Running Your First Scan
Step-by-step guide to running a security scan.
This guide walks you through running your first security scan on Barrion, from entering your URL to interpreting the results.
Start a Scan
- Log in to your Barrion dashboard.
- Navigate to Dashboard > Scans.
- Enter the full URL of the site you want to scan (e.g.,
https://example.com). - Click Scan to begin.
Barrion validates that the target URL is reachable before starting the scan. If the domain cannot be resolved or the server does not respond, the scan will fail with a descriptive error.
Monitor Progress
Once the scan starts, you will see real-time progress on the scan page. Results stream in via Server-Sent Events as each security check completes, so you can begin reviewing findings before the full scan finishes.
The progress indicator shows:
- The current scan status (STARTED, COMPLETED, or FAILED)
- Individual checks completing in real time
- The emerging security score as checks report results
View Your Results
When the scan completes, you will see an overview including:
- Security score -- A numeric score from 0 to 100
- Letter grade -- A grade from A to F based on your score
- Check summary -- Total checks run, passed, and failed
Understanding Check Statuses
Each individual check reports one of the following statuses:
| Status | Meaning |
|---|---|
| Passed | Your site meets the security requirement for this check. |
| Failed | A vulnerability or misconfiguration was detected. |
| Requires Upgrade | This check is available on a higher plan tier. Upgrade to unlock it. |
Reviewing Individual Findings
Click on any check to expand its details. Each finding includes:
- Check name -- What was tested
- Status and severity -- Whether it passed or failed, and the severity level (Critical, High, Medium, or Low)
- CVSS score -- The Common Vulnerability Scoring System rating
- Description -- A detailed explanation of what this check evaluates and why it matters
- Finding -- The specific result observed on your site
- Recommendation -- Actionable steps to fix the issue
Descriptions and recommendations are rendered in rich markdown with code examples where applicable.
Affected URLs
For checks that evaluate individual pages (rather than domain-wide configuration), the results include a list of affected URLs showing exactly which pages triggered the finding. This helps you pinpoint where fixes need to be applied, especially on larger sites with many routes.
Next Steps
After reviewing your first scan results:
- Fix critical and high severity findings first -- These have the greatest impact on your security posture and score.
- Re-scan to verify fixes -- Run another scan after making changes to confirm the issues are resolved.
- Set up continuous monitoring -- Configure scheduled scans to automatically track your security posture over time.
- Review the scoring methodology to understand how your grade is calculated.