The ShieldWave scanner and domain exclusion

Version of 29 September 2026

1. What the scanner is and who runs it

ShieldWave (https://shieldwave.io) checks the security of websites from the outside. It is run by Radosław Fedorczuk, trading as ENSOMEDIA Radosław Fedorczuk, ul. Chorwacka 33/42, 51-107 Wrocław, Poland, tax number (NIP) 8952195742, EU VAT number PL8952195742, business register number (REGON) 381626230, entered in the Polish Central Register and Information on Economic Activity (CEIDG), "ENSOMEDIA" or "we" below.

2. How the scanner identifies itself

The scanner uses the User-Agent ShieldWave-Scanner/1.0 (+https://shieldwave.io/bot).

Not every request carries it: parts of a check that load a page like a browser identify themselves as an ordinary browser. On domains whose control the customer has not confirmed, the scanner stops when the site refuses it. On domains confirmed by their owner it may repeat the request as a browser. Blocking the identification therefore does not stop all requests. To stop checks of your site, ask for exclusion (section 5).

Anyone can copy it; if in doubt, send us the time, IP address and log line and we will say whether the request was ours.

3. What a check does to a site

A check reads what the server returns (pages, security headers, certificate, cookies, caching) and asks for typical addresses of forgotten files. Depending on the platform it also checks the WordPress configuration. Forms, redirects and known vulnerabilities are checked only by the full set, described below.

A check ordered from an account sends test inputs to forms and addresses only when the customer has confirmed control over the domain (a DNS record, a file, a meta tag or a connected WordPress plugin). That is more than reading. Without that confirmation it runs the shorter set and stops when the site refuses it. The demonstration check and the four free tools, open to anyone without an account, run a shorter set: they read what the server returns and send no test inputs to forms; the demonstration check also asks for a short list of addresses of forgotten files.

A check does not log in, unless the customer gave login details for the part behind the login, and does not change content, though a test input sent to a form can reach you, for example as a contact-form message. We limit the pace of requests and the number of checks one account and one IP address can order. Checks run only when a customer orders them, on a customer's schedule, or when someone uses the demonstration check.

4. Who may order a check

From an account, a customer may check only a site that is theirs or whose owner allowed it. The customer states this when adding a site or ordering a check; we record the statement with the account, the domain, the time, where it was given, the IP address and the browser identification, and keep it for 3 years from the statement. The full set runs only after a technical confirmation of control over the domain (DNS record, file, meta tag or connected plugin); we may also ask for proof of the owner's permission.

Checking a site without permission breaks our Terms of Service and can be an offence, such as unauthorised access to a computer system or disrupting its work, under Polish criminal law (Articles 267 to 269c of the Penal Code) and the corresponding laws of other countries.

5. How to exclude your domain

A site's owner can have the domain excluded from all ShieldWave checks, free and without giving reasons. Write to support@shieldwave.io from an address at that domain, subject "Domain exclusion", saying whether subdomains are included. From another address, add other proof of control, such as a DNS record or a file with a text we give you.

We exclude the domain within 2 working days of a complete request, confirm it by e-mail and keep it on our exclusion list, which covers all customers' checks, the demonstration check and the free tools. To lift the exclusion, write from the same domain.

6. How to report misuse

If you believe someone checked your site through ShieldWave without permission, write to support@shieldwave.io with the domain, the date and time (with time zone) and, if you have them, the IP address and log line. We will check who ordered the check, may ask them for proof of permission, block checks of your domain and suspend their account, and will tell you what we did. We disclose a customer's data only where the law allows. Report weaknesses in ShieldWave itself under Vulnerability Disclosure.

7. What happens to the results

The results go to the person who ordered the check, in their account or browser. We do not publish results ourselves.

8. Change history