---
title: How to configure the Website Scanner
description: Looking for vulnerabilities in your web application? Let Website Scanner do that for you! In this article, we explain all the features and options available to help you make the finest vulnerability reports.
---

[Skip to content](https://support.pentest-tools.com/website-scanner-settings#main-content)

[![flat ptt\_logo\_RGB\_alpha](https://support.pentest-tools.com/hubfs/flat%20ptt_logo_RGB_alpha.svg)](https://support.pentest-tools.com/)

Open main navigation

Close main navigation

- [Raise a ticket](https://share.hsforms.com/1iXO7OCiAQV67C-9QIn-4Dgbqmk4)

[Raise a ticket](https://share.hsforms.com/1iXO7OCiAQV67C-9QIn-4Dgbqmk4)

 How can we help you?

- There are no suggestions because the search field is empty.

1. [Support Center](https://support.pentest-tools.com/)
2. [Tools and Scans](https://support.pentest-tools.com/tools-and-scans)
3. [Web Application Testing](https://support.pentest-tools.com/tools-and-scans#web-application-testing)

September 8, 2025

# How to configure the Website Scanner

## Looking for vulnerabilities in your web application? Let Website Scanner do that for you! In this article, we explain all the features and options available to help you make the finest vulnerability reports.

The **Website Vulnerability Scanner** is a **custom tool written by our team** that helps you quickly assess the security of a web application. It is a full-blown web application scanner, capable of performing comprehensive security assessments against any type of web application.

![](https://support.pentest-tools.com/hubfs/Knowledge%20Base%20Import/image-Dec-17-2024-03-28-24-8679-PM.png)

#### Light Scan

This option gives a brief overview of the website. The report will contain website technologies that can be found and vulnerabilities that can be found within a few minutes.

#### Deep Scan

This is the default option when trying to start the scan. This type of scan can run up to 24 hours and will search for OWASP Top 10 vulnerabilities.  
This has all the options enabled by default, except for Resource Discovery.

**We recommend you do not change the default settings**. However, if you have any specific requirements, such as a very large application, or you need to exclude several parts of the application from the scan, you can configure these settings as described below, with a **Custom Scan**.

#### Custom Scan

This part of the interface enables you to enforce the scanner to:  
- **run only specific checks**, such as SQL or XSS Injection testing, or scan for only a type of vulnerability  
\- limit the number of requests per second/depth of the scan  
\- exclude critical URLs  
and many, many others.

> ⚠️ When using scheduled scans with custom scan options, newly added detectors will not be enabled by default, you will need to use the Full Scan option to have all the new features of the scanner in scheduled scans.

#### Initial tests

These tests are recommended for all applications. You can skip any of these, depending on the target application typology. The scan duration will vary depending on the number and the complexity of the tests you select to perform.

The **resource discovery** part is the most time-consuming, so we recommend you run this test at a later stage, or when you have time to leave the scan running.

You can **schedule a scan for later** using the scheduling feature. For more details, please check out our support article on [how to schedule a scan](https://support.pentest-tools.com/start-scheduled-scan).

![](https://support.pentest-tools.com/hubfs/Knowledge%20Base%20Import/ddc78b52-cae2-4261-9d89-2d29231d2e5d.png)

> ### [Read more about each test in the dedicated article](https://support-test.pentest-tools.com/website-scanner-tests)

#### Engine Options

You can configure the following options to determine how deep you want the scan to crawl the application or set some paths that you want the scanner to avoid.

### Approach

The **Approach** section notifies the scanner of which type of spidering method to use.

- **Classic Spider** – Used to crawl classic websites.
- **SPA Spider**– Used to crawl single-page application (JavaScript-heavy) websites. We are still working on this feature and it will be released in a later version.

### Limits

By adjusting the **Spidering depth **you are letting the scanner know the number of subpaths (‘/’) it should crawl and scan, meaning to what extent the search engine indexes the website’s content.

![](https://support.pentest-tools.com/hubfs/Knowledge%20Base%20Import/12004dbb-93cc-4767-a988-34db48bca546.png)

A greater crawl depth might get a lot more injection points than a site with a lower crawl depth, but it will also affect your scan duration. We recommend that you keep the default value.

You can also decrease the number of **requests per second** that the scanner sends to the target website.

### Excluded URLs

**Excluded URLs** are a list of URL test names to ignore when scanning. By default, this is an empty list representing no paths that should be excluded. You can enter each URL on a new line. Make sure to **enter the full path of the URL(s)**.

![](https://support.pentest-tools.com/hubfs/Knowledge%20Base%20Import/image-Dec-17-2024-03-28-23-8637-PM.png)

You don't need to exclude each longer path URL specifically, just the main (root) URL path should suffice.

For example, for an online shop: https://example.shop.com/products, if the product pages are all the same, scanning each individual product URL would lead to an  **unnecessary long scan**. You can exclude all of them by just excluding the "root" - https://example.shop.com/products instead of adding to the exclusion list all of them: https://example.shop.com/products/product\_1, https://example.shop.com/products/product\_2, https://example.shop.com/products/product\_3, etc.

> **Tip: **You can resize the input box by dragging the bottom-right corner.

#### Attack Options

**Attack Options** represent tests the scanner engine is performing on every new Injection Point it detects during the scanning process. An Injection Point is a target URL paired with unique parameters. It is considered validated after the scanner sends a request to it and checks if the response is valid.

For example “[https://www.example.com/?parameter=value](https://www.example.com/?parameter=value)” is a unique Injection Point that is checked with all the selected modules.

**There are Active and Passive checks. **Both types of tests use the validated Injection Points from the request engine.

The difference between them is that **active checks send a large number of requests** against an Injection Point with specific payloads that should trigger certain behaviors from the target that indicate whether it is vulnerable or not. 

The latter use the Injection Points detected directly, therefore **passive checks are not sending additional requests**. They analyze the server’s response for specific configurations and behaviors that prove the target is vulnerable to different attacks

> ⚠️ While the  **passive checks** generate a maximum of 20 HTTP requests to the server, the  **active checks **are more aggressive and send up to  **10,000 HTTP requests**. This may trigger alarms from IDS but you should know that it is not a destructive scan.

#### Authentication

If your application requires authentication to access certain parts of the website, it is highly recommended to enable authenticated scanning. Thus, the scanner covers more application functionality and pages than the unauthenticated scan.

> If you wish to learn more about why you should perform an authenticated scan, you can check out  [this dedicated article from our Learning Center](https://pentest-tools.com/blog/authenticated-scanning/).

The “Check authentication” button is **optional for the first three methods** and **disabled** for the **“Headers”** method, so you can start scanning directly.

Our[Website Vulnerability Scanner](https://pentest-tools.com/website-vulnerability-scanning/website-scanner) supports four methods for performing authenticated scans:

1. [Recorded – Recording-based Authentication](https://support.pentest-tools.com/recorded-authentication-chrome)
2. [Automatic – Form-based authentication](https://support.pentest-tools.com/how-to-perform-automatic-authentication-with-website-scanner)
3. [Cookies – Cookie-based authentication](https://support.pentest-tools.com/cookie-authentication-website-scanner)
4. [Headers – Headers authentication](https://support.pentest-tools.com/headers-authentication-website-scanner)

You’ll know that the authentication was successful if you get an additional “Authentication complete” message in the final scan report. Furthermore, the Spider results should contain more crawled URLs than the unauthenticated scan.

#### Notifications

You can configure notifications when your scan matches certain conditions (is Finished, found High Risk, discovered some open port, etc).

*You can find more details about **notifications **in our dedicated [support article](https://support-test.pentest-tools.com/scan-notifications).*

- [Getting started](https://support.pentest-tools.com/getting-started#main-content)

    - [Tips & Tricks](https://support.pentest-tools.com/getting-started#tips-tricks)
    - [First Steps](https://support.pentest-tools.com/getting-started#first-steps)
- [Tools and Scans](https://support.pentest-tools.com/tools-and-scans#main-content)

    - [Network Infrastructure Testing](https://support.pentest-tools.com/tools-and-scans#network-infrastructure-testing)
    - [Authenticated Scanning](https://support.pentest-tools.com/tools-and-scans#authenticated-scanning)
    - [Frequently Asked Questions (FAQ)](https://support.pentest-tools.com/tools-and-scans#frequently-asked-questions-faq)
    - [Offensive Tools](https://support.pentest-tools.com/tools-and-scans#offensive-tools)
    - [Web Application Testing](https://support.pentest-tools.com/tools-and-scans#web-application-testing)
    - [Reconnaissance](https://support.pentest-tools.com/tools-and-scans#reconnaissance)
- [Account and Billing](https://support.pentest-tools.com/account-and-billing#main-content)

    - [Billing and Payment](https://support.pentest-tools.com/account-and-billing#billing-and-payment)
    - [Account Management](https://support.pentest-tools.com/account-and-billing#account-management)
- [Assets, Targets & Workspaces](https://support.pentest-tools.com/assets-targets-workspaces#main-content)

    - [Workspaces](https://support.pentest-tools.com/assets-targets-workspaces#workspaces)
    - [Assets & Targets](https://support.pentest-tools.com/assets-targets-workspaces#assets-targets)
- [Reporting and Vulnerability Management](https://support.pentest-tools.com/reporting-and-vulnerability-management#main-content)

    - [Notifications](https://support.pentest-tools.com/reporting-and-vulnerability-management#notifications)
    - [Attack Surface](https://support.pentest-tools.com/reporting-and-vulnerability-management#attack-surface)
    - [Reporting](https://support.pentest-tools.com/reporting-and-vulnerability-management#reporting)
    - [Findings](https://support.pentest-tools.com/reporting-and-vulnerability-management#findings)
- [VPN Profiles](https://support.pentest-tools.com/vpn-profiles)
- [Integrations](https://support.pentest-tools.com/integrations)
- [Automation](https://support.pentest-tools.com/automation#main-content)

    - [Scheduler](https://support.pentest-tools.com/automation#scheduler)
    - [Scan Groups](https://support.pentest-tools.com/automation#scan-groups)
    - [Pentest Robots](https://support.pentest-tools.com/automation#pentest-robots)
- [Change Log](https://support.pentest-tools.com/change-log)
- [Data Security](https://support.pentest-tools.com/data-security)

[![Chill listening crop-3](https://support.pentest-tools.com/hs-fs/hubfs/Logo%20negru.png?width=109&height=40&name=Logo%20negru.png "Chill listening crop-3")](http://Pentest-Tools.com)

[Go to Pentest-Tools.com ](https://pentest-tools.com/)

<https://www.linkedin.com/company/pentesttools> <https://www.youtube.com/c/PentestToolscom> <https://www.reddit.com/r/pentest_tools_com/>

Copyright © 2026 PentestTools S.A.