Barrion Docs
Passive Scanning

Running Your First Scan

Step-by-step guide to running a security scan.

This guide walks you through running your first security scan on Barrion, from entering your URL to interpreting the results.

Start a Scan

  1. Log in to your Barrion dashboard.
  2. Navigate to Dashboard > Scans.
  3. Enter the full URL of the site you want to scan (e.g., https://example.com).
  4. Click Scan to begin.

Barrion validates that the target URL is reachable before starting the scan. If the domain cannot be resolved or the server does not respond, the scan will fail with a descriptive error.

Monitor Progress

Once the scan starts, you will see real-time progress on the scan page. Results stream in via Server-Sent Events as each security check completes, so you can begin reviewing findings before the full scan finishes.

The progress indicator shows:

  • The current scan status (STARTED, COMPLETED, or FAILED)
  • Individual checks completing in real time
  • The emerging security score as checks report results

View Your Results

When the scan completes, you will see an overview including:

  • Security score -- A numeric score from 0 to 100
  • Letter grade -- A grade from A to F based on your score
  • Check summary -- Total checks run, passed, and failed

Understanding Check Statuses

Each individual check reports one of the following statuses:

StatusMeaning
PassedYour site meets the security requirement for this check.
FailedA vulnerability or misconfiguration was detected.
Requires UpgradeThis check is available on a higher plan tier. Upgrade to unlock it.

Reviewing Individual Findings

Click on any check to expand its details. Each finding includes:

  • Check name -- What was tested
  • Status and severity -- Whether it passed or failed, and the severity level (Critical, High, Medium, or Low)
  • CVSS score -- The Common Vulnerability Scoring System rating
  • Description -- A detailed explanation of what this check evaluates and why it matters
  • Finding -- The specific result observed on your site
  • Recommendation -- Actionable steps to fix the issue

Descriptions and recommendations are rendered in rich markdown with code examples where applicable.

Affected URLs

For checks that evaluate individual pages (rather than domain-wide configuration), the results include a list of affected URLs showing exactly which pages triggered the finding. This helps you pinpoint where fixes need to be applied, especially on larger sites with many routes.

Next Steps

After reviewing your first scan results:

  • Fix critical and high severity findings first -- These have the greatest impact on your security posture and score.
  • Re-scan to verify fixes -- Run another scan after making changes to confirm the issues are resolved.
  • Set up continuous monitoring -- Configure scheduled scans to automatically track your security posture over time.
  • Review the scoring methodology to understand how your grade is calculated.