Documentation
Scan Methodology
GroundedScan runs 75+ automated tests across 9 security modules:
- M.01 Website Foundation — SSL/TLS, HTTP/HTTPS, mixed content, redirect chains
- M.02 Security Headers — CSP, HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy
- M.03 Cookies & Sessions — Secure, HttpOnly, SameSite attributes
- M.04 Authentication — Login forms, password policies, MFA indicators
- M.05 Input / Output — XSS, injection vectors, CORS configuration
- M.06 Privacy & Compliance — GDPR/CCPA signals, cookie consent, data collection
- M.07 AI & LLM Security — AI endpoint exposure, model metadata, API key leakage
- M.08 AI Agent Exposure — Agent tool access, autonomous action boundaries, prompt injection surfaces
- M.09 WordPress CVE — Known WordPress vulnerabilities, plugin/theme version checks
Findings are mapped to 5 frameworks: PLOT4AI, OWASP LLM Top 10, MITRE ATLAS, STRIDE-LM, and Microsoft AI/ML. Each scan produces a plain-English report with letter grade and prioritized fix list.