Disclaimer
VulnerabilityTools is an automated scanning tool. This page explains — honestly — what its reports can and cannot tell you. Please read it before acting on a report.
1. Automated scans have limits
- Our scanner checks for common, known issues using automated tests. It cannot examine your server's internals, your source code, your business logic, or how your site behaves for logged-in users.
- A high score or a "clean" report does not mean your website is secure. It means the automated checks didn't find the issues they look for — nothing more.
- Conversely, findings can be false positives: a flagged item may turn out to be harmless in your specific setup. Each finding explains what it means so you can judge.
2. Not professional advice
Reports are general information, not professional security, legal, or compliance advice. They don't certify compliance with any standard (such as PCI DSS, ISO 27001, or SOC 2), and they aren't a substitute for a manual security review or penetration test by a qualified professional. For anything critical — customer data, payments, health or legal obligations — get a proper assessment.
3. Scores are estimates
Grades and section scores are our automated estimate of website health based on the checks that ran. If a check can't run (for example a service is temporarily unreachable), the report says so instead of guessing. Scores can also change between scans as sites, tools, and threat intelligence update.
4. Third-party data
Parts of the report rely on third-party sources (threat-intelligence feeds, reputation databases, page-speed services). We present their signals as faithfully as we can, but we can't guarantee their accuracy or availability.
5. Use at your own risk
You use the scanner and rely on its reports at your own risk. We're not responsible for decisions you make based on a report, or for security incidents on scanned websites. See the Terms & Conditions for the full legal position.