Sources and credits
Everything Ward tells you comes from public sources. These are the ones in use today: what each one adds, under what license, and the credit its terms ask us to give.
Besides these sources, Ward reads three public standard files of your own website (robots.txt, sitemap.xml and /.well-known/security.txt), one request each, and asks search engines what they already have indexed from your domain. We never probe paths: we don't try lists of addresses on your server and we never open the paths those files mention.
Who processes your data for us is listed in the Privacy Policy.
Domain and DNS
RDAP (IANA and registries)
Registration data of your domain: expiry date, transfer lock and name servers.
Free to useTerms(opens in a new tab)Public DNS resolvers
The DNS lookups any computer makes: addresses, mail servers, SPF, DMARC, DKIM and CAA records.
Free to useTerms(opens in a new tab)
Website and certificates
hstspreload.org
Whether your domain is on the HSTS preload list that browsers ship with.
Free to useTerms(opens in a new tab)crt.sh
Public certificate transparency logs, as a fallback to list your subdomains and the certificates issued for them.
Free to useTerms(opens in a new tab)Cert Spotter
Certificate transparency: your subdomains, the certificates issued for your domain and new certificates as they appear.
Free to useTerms(opens in a new tab)Credit: Certificate data: Cert Spotter by SSLMate(opens in a new tab)
Common Crawl
The public index of web crawls, to see whether sensitive files of your site were ever indexed.
Free to useTerms(opens in a new tab)
PSBL
Passive Spam Block List: mail server IPs seen sending spam.
Free to useTerms(opens in a new tab)UCEPROTECT level 1
Mail server IPs seen sending spam (level 1 only).
Free to useTerms(opens in a new tab)JustSpam
Mail server IPs reported for spam.
Free to useTerms(opens in a new tab)s5h.net
Mail server IPs reported for spam.
Free to useTerms(opens in a new tab)NordSpam (IPs)
Mail server IPs seen sending spam.
Free to useTerms(opens in a new tab)NordSpam (domains)
Domains seen in spam.
Free to useTerms(opens in a new tab)Hostkarma
Mail server IPs on its blacklist (its other codes are ignored).
Free to useTerms(opens in a new tab)Microsoft SNDS
Your sending reputation in Outlook, from the access link you provide.
Free to useTerms(opens in a new tab)
Reputation and impersonation
WhoisDS
The daily list of newly registered domains, to spot new lookalikes of your name.
Free to useTerms(opens in a new tab)Google Web Risk
Whether Google has flagged your website as possibly dangerous (malware, phishing, unwanted software).
Free to useTerms(opens in a new tab)Phishing.Database
A community list of active phishing domains, copied to our servers every day.
Free to use, MITTerms(opens in a new tab)Credit: Phishing.Database by Mitchell Krog, MIT license(opens in a new tab)
DROP list
Networks flagged as hijacked or used for crime (DROP list), copied to our servers every day.
Free to useTerms(opens in a new tab)Credit: DROP list data © The Spamhaus Project SLU(opens in a new tab)
Tor exit node list
Addresses of Tor exit nodes, copied to our servers every day.
Free to use, CC0Terms(opens in a new tab)CINS Army
Addresses that have attacked other systems, copied to our servers every day.
Free to useTerms(opens in a new tab)RansomLook
Companies named on ransomware leak sites. We download recent data and match it on our servers.
Free to use, CC BY 4.0Terms(opens in a new tab)RansomFeed
A second feed of ransomware victims, matched on our servers the same way.
Free to use, CC BY 4.0Terms(opens in a new tab)GitHub
Public code search, to see whether your domain or secrets appear in public repositories.
Free to useTerms(opens in a new tab)
Vulnerabilities
NVD
The national vulnerability database: severity scores and affected products of every CVE, copied to our servers.
Free to useTerms(opens in a new tab)Credit: This product uses the NVD API but is not endorsed or certified by the NVD.(opens in a new tab)
CISA KEV
CISA's catalog of vulnerabilities known to be exploited by attackers.
Free to use, CC0Terms(opens in a new tab)EPSS
The probability that each vulnerability is exploited in the next 30 days.
Free to useTerms(opens in a new tab)Credit: See EPSS at https://www.first.org/epss(opens in a new tab)
CISA Vulnrichment
CISA's enrichment of CVE records, to fill the gaps NVD leaves.
Free to use, CC0Terms(opens in a new tab)
Team accounts
Have I Been Pwned (breach catalog)
The public catalog of data breaches: description and date of each one.
Free to use, CC BY 4.0Terms(opens in a new tab)
Ward AI
OpenRouter
Runs Ward AI, the assistant that helps you fix a finding step by step.
Paid planTerms(opens in a new tab)