How Passive Scanning Works
Understanding Barrion's passive, production-safe scanning approach.
Barrion uses passive scanning to evaluate the security posture of your web applications without modifying data, submitting forms, or exploiting vulnerabilities. Every scan is read-only and production-safe. You can run it against live sites with minimal load on the site.
What Is Passive Scanning?
Passive scanning analyzes the observable behavior and configuration of a web application by inspecting HTTP responses, headers, TLS certificates, and page content. Unlike active scanning (penetration testing), passive scanning never:
- Submits forms or modifies data
- Attempts SQL injection, XSS, or other exploit payloads
- Brute-forces authentication endpoints
- Creates, updates, or deletes resources on your server
This makes it safe to run against production environments at any time, including during peak traffic.
The Scan Pipeline
When you initiate a scan, Barrion executes a multi-stage pipeline:
- URL validation: The target URL is validated and normalized. Barrion confirms the domain is reachable before proceeding.
- Puppeteer crawl: A headless Chromium browser crawls your site, following links to discover pages up to the configured crawl depth. This captures the full rendered DOM, including content loaded by JavaScript frameworks.
- ZAP passive analysis: Crawled pages are passed through ZAP (Zed Attack Proxy). ZAP passively inspects HTTP traffic for common misconfigurations and vulnerabilities.
- Custom security checks: Barrion runs 35+ proprietary checks across 10 security categories, evaluating everything from TLS configuration to Content Security Policy to email authentication records.
- Scoring and reporting: Results from all checks are aggregated into a security score (0--100), letter grade, and detailed findings with remediation guidance.
Security Check Categories
Barrion organizes its 35+ passive checks (on paid plans; 18 on the Free plan) into 10 categories:
- TLS/SSL: Certificate validity, protocol versions, cipher strength
- Security Headers: HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy
- Content Security Policy: CSP presence, configuration, bypass risks
- CORS: Cross-origin resource sharing configuration
- Cookie Security: Secure, HttpOnly, SameSite attributes
- Email Security: SPF, DKIM, DMARC records
- Network Security: DNS configuration, open ports
- XSS Protection: Cross-site scripting mitigations
- Clickjacking: Frame embedding protections
- Miscellaneous: Server information disclosure, mixed content, and other checks
Real-Time Progress
Scans report progress in real time via Server-Sent Events (SSE). As each check completes, results stream to your browser immediately, so there is no need to refresh the page or wait for the entire scan to finish before viewing partial results.
Scan Contexts
Every scan runs in one of three contexts, which determines rate limits and available features:
| Context | Description | Trigger |
|---|---|---|
| User Request | Authenticated user initiates a scan from the dashboard | Manual |
| Guest Request | Unauthenticated visitor runs a scan from the landing page | Manual |
| Schedule | Automated scan triggered by a monitoring schedule | Automatic |
Scan Lifecycle
Each scan progresses through a defined set of statuses:
- SCHEDULED: The scan has been queued and is waiting to execute.
- STARTED: The scan is actively running checks against the target.
- COMPLETED: All checks finished successfully and results are available.
- FAILED: The scan encountered an error (e.g., the target is unreachable or timed out).
Crawl Depth by Plan
The number of pages Barrion crawls during a scan depends on your subscription tier:
| Plan | Max Pages Crawled |
|---|---|
| Free | 3 |
| Essential | 20 |
| Business | 200 |
A deeper crawl means more pages are analyzed, increasing the likelihood of discovering misconfigurations on specific routes or subpages that differ from the homepage.