Authorized use only
You may use Audit My CMS only for websites you own, manage, maintain, or have explicit permission to assess. Ownership verification is required before scans are queued, but verification does not replace your responsibility to have proper authorization.
Passive audit scope
Audit My CMS performs passive, rate-limited checks using public website responses and public CMS signals. It does not exploit vulnerabilities, brute force credentials, bypass authentication, or access private CMS areas.
Findings are informational and intended for remediation planning. You should verify findings, prioritize based on your environment, and test changes before applying them to production systems.
Results and reports
Scan results can be incomplete if a firewall, CDN, security plugin, hosting provider, network issue, or rate limit blocks scanner traffic. Result pages and report downloads are available only during the retention period shown on the result page.
Reports are generated from passive scan evidence and are intended for review, planning, and remediation. Findings should be verified before making production changes.
Prohibited activity
You must not use Audit My CMS to scan third-party websites without permission, overload targets, evade access controls, test stolen data, perform illegal activity, or interfere with the service or other users.
No guarantee
Audit My CMS is not a penetration test, security certification, legal compliance certification, or guarantee that a website is secure. The service may miss vulnerabilities, misclassify findings, or report items that need manual review.
Contact
For support, scan access, or terms questions, use the Contact page.