Project Pages review
Review discovered public pages and keep the scan boundary clear before running scans.
Customers reviewing project pages and technical reviewers
Feature availability
Product, package, provider and deployment boundaries for this page.
- Available from
- Current documentation
- Deployment modes
- cloud
Product screenshots
Current customer-safe screenshots are generated from the application so examples do not drift from the product.
Before reviewing pages
Project Pages is the customer-facing boundary for scans. It shows the public pages WebRiskOps discovered for the project and keeps later scan evidence, reports, skipped-page explanations and monitoring aligned with the same public website. Use this page after the project exists and discovery has run. Do not scan private pages, admin areas, login-only screens, third-party tools or unrelated domains from this project.
Review the project page boundary
Follow the path `Projects → Project detail → Project Pages → Actions`.
- Open /projects and choose the project. Result: the project detail page shows Project Pages, Scans and Actions for that domain.
- Review the discovery summary and listed page groups. Result: you can see which public URLs are ready before spending credits.
- Confirm the intended public journey is represented, such as homepage, pricing, checkout, cart or contact pages. Result: the scan starts from pages that matter to the customer.
- If key pages are missing, use Discover pages before starting the scan. Result: WebRiskOps refreshes discovery from the same domain instead of asking for another setup flow.
- Leave private, admin, login-only, third-party and unrelated-domain pages out. Result: the scan stays inside the self-service public-page boundary.
- Continue to Actions only when the page list looks right. Result: Run whole scan uses the current project pages and account credit state.
Check what the project stores
The project page state should be concrete enough that a later scan cannot widen the target silently.
- Discovered public page URLs and grouped page patterns.
- Excluded unsafe areas such as admin, login, account and completion paths.
- Plan limits such as credits, page budget, crawl depth, rate limit and timeout.
- Domain ownership and account context used for the scan.
- Scan history that shows when those pages were last checked.
Blocked states
Do not use acceptance to approve an unsafe or unclear boundary.
- Project pages empty means discovery did not find usable public pages. Refresh discovery or confirm the domain is reachable.
- Package page cap reached means return to [Public-page-only limits](/docs/projects/public-page-only-limits) and reduce the scan request or upgrade.
- Ownership proof required means finish [Ownership proof](/docs/projects/ownership-proof) before running a private scan.
- Unsupported target means remove it; payment must not convert it into an eligible project.
Continue to scan setup
When Project Pages looks correct, continue to [Run scans from Project Pages](/docs/projects/scan-scope-and-live-audits). That page explains how scan start, skipped pages and scanner input stay inside the project boundary.
Related documentation
Was this page helpful?
Feedback goes into the product documentation review queue.

