Help Center

Frequently Asked
Questions

Everything you need to know about EzyAudit AI, security scanning, and how to protect your website.

01 How does EzyAudit AI work?

EzyAudit AI connects to your domain and runs 95+ automated security checks covering SSL/TLS certificates, HTTP security headers, DNS and email security (SPF, DMARC, DKIM, DNSSEC, MTA-STS, TLS-RPT, CAA), cookie security, information disclosure, malware and Google Safe Browsing blocklist reputation, firewall detection (both edge WAFs and application-layer plugins like Wordfence), exposed ports and services, and known plugin and theme vulnerabilities. For WordPress sites it also fingerprints your installed plugins and themes and cross-references them against a live vulnerability database. Results are scored, graded, and explained in plain English with AI-generated remediation guidance.

02 Is domain verification required before scanning?

Yes, domain verification is required to run full scans. This ensures that only domain owners can access detailed security reports. Verification takes under 2 minutes and can be done via a DNS TXT record, a file upload to your server, or a simple email link sent to an address on your domain.

03 How long does a scan take?

Most scans complete in 60 to 90 seconds. The deeper vulnerability and WordPress component checks add a little time, but you’ll typically have full results within a minute or two of starting the scan.

04 How often can I scan my domain?

The Single Scan plan gives you one comprehensive scan per purchase. Starter, Professional, and Agency subscription plans all include unlimited scans per domain. All subscription plans also include continuous automated monitoring with instant alerts.

05 What is included in the security reports?

Reports include an executive summary, a security score (0–100), a letter grade (A–F), a risk level assessment, a prioritised remediation roadmap, a full technical breakdown (SSL, headers, DNS, cookies), a software inventory of detected plugins and themes, any matched CVE vulnerabilities, business impact explanations, and step-by-step fix instructions for every issue. Downloadable PDF reports are available on all plans, with white-label branding on the Agency plan.

06 What does the security score mean?

The security score is a weighted 0–100 rating that reflects the severity and number of security issues found. Scores translate to letter grades: A (90–100), B (80–89), C (70–79), D (60–69), and F (below 60). A higher score means fewer and less severe security issues.

07 Do you scan for plugin and theme vulnerabilities?

Yes. This is one of the things that sets EzyAudit AI apart from basic header checkers. For WordPress sites, we automatically detect which plugins and themes you have installed, identify their versions, and cross-reference them against our vulnerability database of known CVEs. If a component has a known security flaw — especially one that is being actively exploited — we flag it as a priority finding and tell you exactly which version to upgrade to.

08 How does EzyAudit stay up to date with the latest vulnerabilities?

Our vulnerability database updates itself automatically every single day. It pulls the newest data from trusted sources including the CISA Known Exploited Vulnerabilities catalog (the authoritative list of flaws being exploited in the wild) and the U.S. National Vulnerability Database. This means every scan you run reflects the very latest known threats — not a stale snapshot from months ago.

09 What makes EzyAudit more thorough than other scanners?

Many free scanners only check a handful of HTTP security headers. EzyAudit AI runs 95+ checks in every scan: full SSL/TLS analysis (including TLS versions, ciphers and forward secrecy), all security headers, DNS and email authentication, cookie security, WAF detection, information-disclosure checks (exposed .env files, phpinfo pages, Git repositories, backups), deep WordPress inspection, and live plugin/theme vulnerability matching against known CVEs. Every finding comes with a plain-English explanation and exact fix steps.

10 Which issues does the scanner detect?

Among many others: missing or expiring SSL certificates, weak TLS versions and ciphers, missing security headers (HSTS, CSP and more), missing SPF/DMARC/DKIM/CAA records, insecure cookies, exposed admin areas and debug logs, username enumeration, directory browsing, exposed database backups, .env and phpinfo() exposure, open GraphQL endpoints, XML-RPC abuse, outdated WordPress core, and vulnerable or outdated plugins and themes with known CVEs.

11 How does continuous monitoring work?

Once you enable monitoring on a domain, EzyAudit AI will automatically scan it on a regular schedule. You’ll receive alerts when your SSL certificate is approaching expiry, when DNS records change unexpectedly, when your security score drops, or when new security issues are detected.

12 Do I need technical knowledge to use EzyAudit AI?

No technical background is needed. EzyAudit AI is specifically designed for business owners, marketers, and non-technical users. Every finding is explained in plain English with specific, actionable steps to fix each issue — no coding required.

13 Can I use EzyAudit AI for client websites?

Absolutely. The Professional plan lets you manage up to 10 domains. The Agency plan gives you unlimited domains plus white-label PDF reports, client management, and team access — ideal for web agencies and IT service providers.

14 Is EzyAudit AI GDPR compliant?

Yes. We only collect the minimum data needed to operate the service (your name, email, and domains you add). We do not sell your data to third parties. Your scan results are stored securely and accessible only to you. See our Privacy Policy for full details.

Still have questions?

Our team is here to help. Reach out and we’ll get back to you within one business day.

Scroll to Top