Scanner transparency
How CyberLens AI evaluates security evidence
A scan is a bounded observation, not a guarantee that an application is secure. CyberLens separates confirmed exposure, confirmed not exposed, and inconclusive results so missing evidence does not become a passing check.
Three possible outcomes
Confirmed exposure means the check found evidence supporting the finding. Confirmed not exposed means the check completed and its evidence did not show the tested condition. Inconclusive means the available evidence was insufficient. A negative result applies only to the condition and scope tested.
Website integrity methodology
Website integrity checks compare raw and rendered pages, examine hidden content and links, correlate topic or brand mismatch, and use WordPress-specific origin evidence only when applicable. Historical comparisons can help identify when a change appeared; they do not prove who caused it.
Coverage and limitations
Website, repository, agent-skill and database checks have different access and coverage. Passive website checks cannot establish every authorization or business-logic flaw. Review the evidence, affected resource, remediation and limitations in each finding, and validate fixes by repeating the relevant check.
Live scanner inventory
The interactive inventory on this page loads current scanner versions, test counts and release changes from the transparency service. Counts describe implemented checks, not a probability of safety or a certification.
Security references
CyberLens AI guidance is informed by established security standards and public vulnerability intelligence.
- OWASP Top 10: Common web application security risks used as a baseline reference.
- OWASP Application Security Verification Standard: Application security verification guidance for web application controls.
- NIST Cybersecurity Framework: Cybersecurity risk management guidance from NIST.
- CISA Known Exploited Vulnerabilities Catalog: Known exploited vulnerability intelligence for prioritization context.