CHANGELOG
What’s new.
Everything we’ve shipped, newest first.
- API
Safe retries for new scans
- POST /v1/scan now accepts an Idempotency-Key header, so a retried request within 24 hours never starts a second scan or uses another scan from your quota.
- Polling a scan’s status no longer shares its rate limit with starting scans — a CI job can poll for as long as a scan takes.
- Every API response now carries rate-limit and request-ID headers, for easier debugging and support requests.
- Security
Logged-in scans stop if the session expires
- If a saved login expires mid-scan, the scan now stops cleanly instead of scanning logged-out pages as if they were logged in.
- A stored login session can now be revoked directly through the API.
- Scan requests are protected against DNS-rebinding, and a saved session is pinned to the site it was captured on.
- Product
Before-and-after code in fix guidance
Fix guidance now shows step-by-step instructions and the failing code next to the fixed code for more than 12 common issue types, generated from your own code where possible.
- Performance
Four pages at a time
Multi-page scans now test up to four pages in parallel.
- Product
Scheduled scans and email alerts
- Scheduled scans — daily, weekly or monthly — in your own timezone.
- Email alerts when a scan completes, finds critical issues or fails, each one switchable on its own.
- Storage
No size limit on large scans
Large multi-page scans are stored without a practical size limit, and the dashboard lists them from their summaries.