> ## Documentation Index
> Fetch the complete documentation index at: https://docs.validate.al/llms.txt
> Use this file to discover all available pages before exploring further.

# Results

> Understanding a scan report.

Scan reports are JSON objects with the following structure:

```json theme={null}
{
  "scan_id": 42,
  "target": "example.com",
  "scan_type": "webapp",
  "status": "completed",
  "scanned_at": "2026-10-04T12:00:00Z",
  "summary": "Nuclei findings (2): CVE-2023-...",
  "raw": {
    "target": "example.com",
    "scan_type": "webapp",
    "nuclei": "... raw tool output ...",
    "nikto": "...",
    "whatweb": "...",
    "dirsearch": "...",
    "sqlmap": "..."
  }
}
```

## Fields

| Field | Description |
| - | - |
| `scan_id` | Unique scan identifier |
| `target` | The hostname or URL scanned |
| `scan_type` | Type of scan performed (`webapp`, `dns-auth`, `ip`) |
| `status` | `pending` (queued), `in_progress` (a scanner is running it), then `completed`, `failed` (every tool failed; doesn't count against your allowance) or `cancelled` |
| `scanned_at` | ISO 8601 timestamp when the scan finished |
| `summary` | Human-readable summary of key findings, one per line. A tool that failed (timeout, missing, error) appears as `nuclei: failed (reason)` and its output is never counted as findings. |
| `raw` | Object containing each tool's raw output |

## Reading tool output

Each tool's output is under the `raw` key. The format varies by tool:

* **nuclei** — lists matched template names on separate lines
* **nikto** — lines starting with `+ ` indicate findings
* **whatweb** — comma-separated list of detected technologies
* **dirsearch** — discovered paths with status codes
* **sqlmap** — structured output with injection details
* **dig** — DNS record lines (A, MX, TXT, SPF, DKIM, DMARC)
* **curl** — HTTP response headers
* **nmap** — open ports with service and version info

## Cancelling a scan

To cancel a pending or running scan, contact [scan@validate.al](mailto:scan@validate.al). Cancelled scans show `cancelled` status, have no report, and don't count against your daily allowance.

## Deleting scans

Delete a finished scan from the [portal](https://portal.validate.al) (**Scans → Delete**) or with `DELETE /scans/{id}`. The scan disappears at once and is removed for good, with its report and target, 10 days later. Until then, [scan@validate.al](mailto:scan@validate.al) can restore it. A deleted scan still counts towards the allowance of the day it ran.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.