Compare
SiteRune vs a penetration test
· Configuration notes, not a newsroom.
We are not a pentest. We do not fuzz, brute-force, or ship exploits. If a vendor scores headers and then attaches a PoC, they are mixing jobs. We refuse the second job.
Public configuration review
SiteRune looks at HTML, headers, cookies, robots, sitemaps, public JSON-LD. Version banners are findings, not payloads. Missing CSP is a header to add, not a script to run against you.
When you still need a pentest
Auth, IDOR, stored XSS in the app, cloud IAM — hire a pentest or a bug bounty. Then use SiteRune so the marketing origin is not the embarrassing part of the report. We will not generate nuclei templates. We will generate nginx snippets and llms.txt.
Run it on a live URL
The brief will name your CMS and attach the files. Three guest scans, no card.