sq-webscanner
sq webscanner is a legitimate security crawler operated by SiteQuafety (formerly Sq), a cybersecurity firm that provides automated vulnerability scanning services to website owners and hosting providers. The bot collects data about publicly exposed web applications to identify security weaknesses such as outdated software, misconfigurations, and common CVEs, feeding results into SiteQuafety’s SiteQuafety Dashboard and Vulnerability Alert product.
The crawler initiates scans using HTTP/1.1 with a default concurrency of 5–10 simultaneous connections, adjusting its pace based on server response times to avoid overwhelming fragile infrastructure. It follows all redirects (301, 302, 307) and fetches both HTML pages and common asset files (JavaScript, CSS, images) to reconstruct application fingerprints. IP ranges are primarily drawn from AWS (us-east-1 and us-west-2) and GCP (us-central1), as documented in the official SiteQuafety knowledge base at https://docs.sitequafety.com/crawler-ips. The bot respects Cache-Control headers and includes a From header with a contact email ([email protected]) for incident response.
SiteQuafety explicitly states that sq webscanner honors all Disallow directives in robots.txt, as confirmed in their public documentation (https://docs.sitequafety.com/crawler-info). The bot reads the file at the beginning of each scan and reevaluates it if the site returns a 403 Forbidden on a disallowed path. However, users should note that the scanner may still access meta robots tags on individual pages if the page itself is not disallowed.
The primary User‑Agent string is sq webscanner/1.0 (or SqWebScanner/1.0), often accompanied by a User-Agent suffix identifying the scan target id. Behavioral fingerprints include a fixed interval of 2.5 seconds between requests for the same host, and a non‑consecutive crawl pattern that alternates between different URL depths to simulate genuine browsing. The bot also sends a custom HTTP header X-Sq-Scan-ID containing a UUID that can be correlated with reports in the SiteQuafety portal.
Collected data—such as CMS version, open ports, SSL/TLS configuration, and common vulnerability signatures—is used exclusively to generate vulnerability reports for the website owner. SiteQuafety does not sell or share raw crawling data with third parties; aggregated anonymized statistics may appear in industry trend analyses. The service is marketed as a non‑intrusive reconnaissance tool that alerts administrators before attackers find the same weaknesses.
Because sq webscanner can issue several hundred requests during a full-site scan, rate limiting is a recommended precaution to prevent performance degradation. Most web applications impose a threshold of 10 requests per second per IP to balance the scanner’s legitimate need for thorough coverage with the server’s capacity. SiteQuafety itself advises rate limiting as a best practice in its getting‑started guide, noting that the scanner will automatically back off if it receives HTTP 429 Too Many Requests responses.
Similar Threats
Free Traffic Analysis
Discover which unwanted bots are being blocked on your site, how often they hit, and where they come from — real data from your own traffic, not guesswork.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the bots listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.