Skip to main content
Scan reports are JSON objects with the following structure:

Fields

Reading tool output

Each tool’s output is under the raw key. The format varies by tool:
  • nuclei — lists matched template names on separate lines
  • nikto — lines starting with + indicate findings
  • whatweb — comma-separated list of detected technologies
  • dirsearch — discovered paths with status codes
  • sqlmap — structured output with injection details
  • dig — DNS record lines (A, MX, TXT, SPF, DKIM, DMARC)
  • curl — HTTP response headers
  • nmap — open ports with service and version info

Cancelling a scan

To cancel a pending or running scan, contact scan@validate.al. Cancelled scans show cancelled status, have no report, and don’t count against your daily allowance.

Deleting scans

Delete a finished scan from the portal (Scans → Delete) or with DELETE /scans/{id}. The scan disappears at once and is removed for good, with its report and target, 10 days later. Until then, scan@validate.al can restore it. A deleted scan still counts towards the allowance of the day it ran.