Only scan a site you own or are authorized to test.
The obvious front-door stuff: HTTPS and certificate health, security headers, cookie safety, files that shouldn't be public, and secrets accidentally left in your site's code.
A deeper sniff that never touches or attacks anything. Outdated software versions, email-spoofing protection (SPF/DMARC), exposed directory listings, WordPress account exposure, and version info your site is leaking.
Speed and build quality: how fast your site loads and how well it's built. Slow sites lose visitors and rank lower on Google.
Active penetration testing that actually probes for exploitable weaknesses. Powerful but aggressive, so it's reserved for authorized, insured engagements and is currently disabled.
Every scan except The Hunt is read-only and safe to run on a live site.