CHANGELOG

What’s new.

Everything we’ve shipped, newest first.

  1. API

    Safe retries for new scans

    • POST /v1/scan now accepts an Idempotency-Key header, so a retried request within 24 hours never starts a second scan or uses another scan from your quota.
    • Polling a scan’s status no longer shares its rate limit with starting scans — a CI job can poll for as long as a scan takes.
    • Every API response now carries rate-limit and request-ID headers, for easier debugging and support requests.
  2. Security

    Logged-in scans stop if the session expires

    • If a saved login expires mid-scan, the scan now stops cleanly instead of scanning logged-out pages as if they were logged in.
    • A stored login session can now be revoked directly through the API.
    • Scan requests are protected against DNS-rebinding, and a saved session is pinned to the site it was captured on.
  3. Product

    Before-and-after code in fix guidance

    Fix guidance now shows step-by-step instructions and the failing code next to the fixed code for more than 12 common issue types, generated from your own code where possible.

  4. Performance

    Four pages at a time

    Multi-page scans now test up to four pages in parallel.

  5. Product

    Scheduled scans and email alerts

    • Scheduled scans — daily, weekly or monthly — in your own timezone.
    • Email alerts when a scan completes, finds critical issues or fails, each one switchable on its own.
  6. Storage

    No size limit on large scans

    Large multi-page scans are stored without a practical size limit, and the dashboard lists them from their summaries.