WEBSITE TESTING · PASSIVE LIVE
Useful website evidence before active DAST.
Submit an authorised public URL. Cidra observes transport, browser security policy, cookies and limited page signals under a hard request budget—then writes the observations into the same remediation ledger.
THE LIVE EXPERIENCE
A baseline you can run without disguising it as a penetration test.
The result shows exactly which checks passed, failed or need context, together with the final URL, redirect count and finding changes.
Assess a public website
Lead/operator authorization and a workspace interlock are required.
https://shop.example.testAssess websiteWSTGWSTGWSTGSAFETY ARCHITECTURE
Every redirect earns authorization again.
A public hostname that turns into a private address is an SSRF path, not a website target. The target guard is applied before the first request and before every redirect.
A lead or operator attests target authority. A workspace lead releases the passive-only interlock.
Credentials, query strings, alternate ports and private, local or reserved DNS answers are rejected.
Resolved public addresses are pinned to the request socket and every redirect is revalidated.
One submitted page, at most three redirects, a 10-second timeout and 512 KB of inspected response data.
WHAT IT OBSERVES
Browser-facing controls with useful remediation.
HTTPS use, redirect outcome and bounded TLS connection details.
CSP, framing, content-type, referrer and permissions policies.
Secure, HttpOnly and SameSite attributes on returned cookies.
Mixed content and password-form transport in the inspected HTML.
Not executed by this module
- No crawling or path enumeration
- No form submission or JavaScript execution
- No attack payloads, API fuzzing or exploitation
- No network service or port scanning
Those capabilities require verified ownership, vault-backed test identities, isolated runners, cancellation and cyber-range validation.
NEXT ON THE GATED ROADMAP
Passive crawl first. Active techniques one at a time.
The next runtime layer is an isolated browser/API runner with authenticated crawl coverage and immediate cancellation. Active payload classes remain disabled until each technique passes its own authorization and containment gate.