Skip to content
SECQON

What SecQon checks — every external security test, explained

This is the full list of what SecQon sends to a site you have proved you own, grouped the way it appears in your report. Each page says which scan profile runs the tests, which plan includes it, and what we do not test, because a report is only useful if you know where its edges are. Across all profiles, six of the ten OWASP Top 10 (2021) categories — A01, A02, A03, A05, A06 and A08 — have purpose-built tests, A07 is covered in part, and A10 (SSRF) is assessed on Deep scans. A04 (Insecure Design) and A09 (Security Logging and Monitoring Failures) cannot be assessed from outside by anyone, and every report names them.

How this maps to the OWASP Top 10

Together these checks cover 7 of the 10 OWASP Top 10 (2021) categories — A10 where the out-of-band collector is configured, on Deep scans. A07 is partial, and A04 (Insecure Design) and A09 (Security Logging and Monitoring Failures) cannot be assessed from outside by anyone. Read the category-by-category coverage.

See what a scan finds on your own asset

Free for one verified asset, no card needed. Paid plans add the written report, more assets and deeper scans.

Start freeCompare plans