Supported public pages
Confirm whether public same-domain pages fit the self-service scan boundary before spending credits or starting scans.
Customers reviewing project pages and technical reviewers
Feature availability
Product, package, provider and deployment boundaries for this page.
- Available from
- Current documentation
- Deployment modes
- cloud
Product screenshots
Current customer-safe screenshots are generated from the application so examples do not drift from the product.
Before reviewing pages
Supported public pages are customer-owned or explicitly authorized web pages that belong to the project domain and can be opened safely by an automated browser. Use this page before spending credits or starting a scan. This boundary matters because WebRiskOps is a self-service public-page workflow. The scanner should not guess that private dashboards, admin paths, login-only pages, unrelated third-party domains or destructive actions are allowed.
Confirm supported public pages
Follow the path `Projects → Project detail → Project Pages → Actions`.
- Open /projects and choose the project for the authorized domain. Result: the project detail page shows the project domain, plan state and Project Pages for that site.
- Compare the project Domain with the public site you want scanned. Result: you know whether the pages belong to the same accepted host instead of another customer, admin or third-party domain.
- In Project Pages, review discovered URL groups before starting the scan. Result: WebRiskOps shows candidate public pages and the page count inside the plan limit.
- Keep only public pages that a browser can open without credentials, such as home, pricing, product, cart, checkout information, contact or support pages. Result: private account areas and destructive actions stay out of scanner input.
- Use Discover pages when expected public pages are missing. Result: discovery refreshes from the same project domain without another setup flow.
- When the public page set is correct, continue to Actions. Result: Run whole scan uses the reviewed project boundary.
Decide what belongs in the scan
Supported pages are pages the customer can authorize and the scanner can safely render without credentials or side effects.
- Include same-domain public pages that represent the user journey you need checked: homepage, pricing, product detail, cart, public checkout information, contact, support and public policy pages.
- Include a subdomain only when the project and authorization clearly cover that host.
- Exclude account dashboards, admin panels, private network hosts, staging environments, password-protected pages and pages that submit destructive actions.
- Keep third-party payment, analytics, identity, SaaS admin and vendor dashboards out of scope unless a later dedicated integration flow documents them.
- If the selected set exceeds the plan page limit, reduce the scan request or upgrade instead of assuming the scanner will choose safely.
Resolve unsupported or blocked state
The product should stop unsupported targets before a scan starts.
- Unsupported target means remove the URL or read [Unsupported targets](/docs/projects/unsupported-targets) before continuing.
- Private network means stop the workflow; private/internal hosts are outside the standard self-service scan.
- Ownership proof required means finish project authorization before running a private scan.
- Plan limit reached means reduce selected groups or use [Public-page-only limits](/docs/projects/public-page-only-limits) to understand the cap.
- Project page rejected means check [Project page boundaries](/docs/projects/manual-urls-and-path-rules) and keep the URL on the project host.
Continue to Project Pages
When every selected page is public, same-domain and authorized, continue to [Project Pages review](/docs/projects/accepted-scan-scope). That page explains how supported public pages become the scan boundary.
Related documentation
Was this page helpful?
Feedback goes into the product documentation review queue.

