Scan Options

1 extra check (SQL-injection probe) : adds a little time per form on your site, no separate timing budget
An extra, heavier check layered on top of the base scan: a harmless test character sent to every form on your site, to check it's handled safely (an SQL-injection probe). Slower than the base scan, but catches an extra class of vulnerability. It only runs together with Functional Scan Checks: on its own it has nothing to hook into, since it needs the exact same page visits.
Documentation last updated: 2026-09-04