Compare
SiteRune vs a penetration test
· Configuration notes, not a newsroom.
We are not a pentest. We do not fuzz, brute-force, or ship exploits. If a vendor scores headers and then attaches a PoC, they are mixing jobs. We refuse the second job.
PEPublic configuration review
SiteRune looks at HTML, headers, cookies, robots, sitemaps, public JSON-LD. Version banners are findings, not payloads. Missing CSP is a header to add, not a script to run against you.
When you still need a pentest
Auth, IDOR, stored XSS in the app, cloud IAM — hire a pentest or a bug bounty. Then use SiteRune so the marketing origin is not the embarrassing part of the report. We will not generate nuclei templates. We will generate nginx snippets and llms.txt.
Capability table
| Capability | SiteRune | A penetration test |
|---|---|---|
| Public HTML / header review | Yes | Usually included |
| Auth, IDOR, stored XSS, IAM | No | Yes |
| Fuzzing / exploit proof | No | Yes |
| CMS playbook + ship files | Yes | Rarely |
SiteRune is a configuration review. Hire a pentest for the application.
FAQ
Does SiteRune replace pentest?
No. Use the comparison table. SiteRune is a hosted configuration brief with CMS dialect and ship files. It does not replace rank tracking, backlink graphs, lab Core Web Vitals, or a desktop site-wide crawl.
What does a SiteRune scan actually fetch?
HTML and headers from this vantage point, robots.txt, sitemap, llms.txt, security.txt, and a polite walk of same-origin interiors. No headless Chrome. No exploits.
Run it on a live URL
Same scan engine. Guest scans stay free.