About our scanner
If you found Royals Security in your server logs, this page explains what visited your website, what it asked for, and how to stop it.
What it is
Royals Security is a website security check for small businesses. When someone asks us to check a website, our scanner visits it once and reports common security problems to that person.
It is not a crawler. It doesn't index pages, follow links around your site, or come back on its own schedule.
How to recognise it
Every request the scanner makes to a website carries this exact User-Agent:
RoyalsSecurityScanner/1.0 (authorized security assessment)
Why it visited your site
A scan only runs when a person enters a website address on our site and confirms that they own it or are allowed to test it. If you didn't ask for a scan, someone else entered your address, perhaps a colleague, your web developer or your agency.
What it requests
The scanner is read-only. A scan makes a small number of ordinary requests and then stops:
- Your home page, over HTTP and HTTPS, to read the response headers and cookies and to see where it redirects.
- Your certificate, by opening a normal secure connection.
- Public DNS records for your domain, such as name servers, SPF, DMARC and DKIM, and the public registration record that says when the domain expires. These lookups go to DNS servers and the domain registry, not to your website.
- A short list of well-known sensitive paths, listed below, to see whether a file that should be private is publicly reachable.
- One address that doesn't exist, so we can tell a real file from a site that answers every request the same way.
It never logs in, submits forms, guesses passwords or tries to exploit anything. If one of the sensitive files is reachable, we record that it exists and read only enough of it to confirm what it is. We never store or show its contents.
The paths it checks
/.env/.git/HEAD/.git/config/.aws/credentials/id_rsa/.htpasswd/dump.sql/backup.sql/db.sql/backup.zip/site.zip/wp-config.php.bak/wp-config.php~/phpinfo.php/info.php/server-status/storage/logs/laravel.log/wp-content/debug.log
Extra paths on a Business scan
When the person scanning is on the Business plan, the scanner also requests these addresses once each, with a plain GET. It only looks at whether a login page comes back. It never submits a form, tries a password or follows a login.
/wp-admin//wp-login.php/administrator//admin//cpanel/phpmyadmin//pma//adminer.php/.well-known/security.txt
Outside services it asks about a domain
These lookups never touch your server. Only the domain name is sent.
- Public DNS servers, for DNS and email records.
- The domain registry, through rdap.org, for the expiry date.
- Business scans only: the public Certificate Transparency logs, through crt.sh, for certificates issued for the domain. Subdomains found there are listed and never visited.
- Business scans only: the Google Web Risk blocklist.
On most websites every one of these returns "not found", which is the result you want.
Limits
The number of scans one person can run, and the number of scans against one website, are capped. The scanner refuses private and internal addresses.
Ask us not to scan your domain
If you'd rather your domain is never scanned, contact us from an address at that domain and tell us which domain to exclude. We'll add it to our exclusion list, which also covers its subdomains, and scans of it will be refused.
To report a security problem with Royals Security itself, see our security page.