Skip to main content

Boteraser | Website and Server Security Solutions

sq webscanner

Scanner User-Agent: sq-webscanner

🤖 Overview

sq webscanner is a legitimate security crawler operated by SiteQuafety (formerly Sq), a cybersecurity firm that provides automated vulnerability scanning services to website owners and hosting providers. The bot collects data about publicly exposed web applications to identify security weaknesses such as outdated software, misconfigurations, and common CVEs, feeding results into SiteQuafety’s SiteQuafety Dashboard and Vulnerability Alert product.

🌐 Technical Behavior

The crawler initiates scans using HTTP/1.1 with a default concurrency of 5–10 simultaneous connections, adjusting its pace based on server response times to avoid overwhelming fragile infrastructure. It follows all redirects (301, 302, 307) and fetches both HTML pages and common asset files (JavaScript, CSS, images) to reconstruct application fingerprints. IP ranges are primarily drawn from AWS (us-east-1 and us-west-2) and GCP (us-central1), as documented in the official SiteQuafety knowledge base at https://docs.sitequafety.com/crawler-ips. The bot respects Cache-Control headers and includes a From header with a contact email ([email protected]) for incident response.

📋 robots.txt Compliance

SiteQuafety explicitly states that sq webscanner honors all Disallow directives in robots.txt, as confirmed in their public documentation (https://docs.sitequafety.com/crawler-info). The bot reads the file at the beginning of each scan and reevaluates it if the site returns a 403 Forbidden on a disallowed path. However, users should note that the scanner may still access meta robots tags on individual pages if the page itself is not disallowed.

🔍 Detection Indicators

The primary User‑Agent string is sq webscanner/1.0 (or SqWebScanner/1.0), often accompanied by a User-Agent suffix identifying the scan target id. Behavioral fingerprints include a fixed interval of 2.5 seconds between requests for the same host, and a non‑consecutive crawl pattern that alternates between different URL depths to simulate genuine browsing. The bot also sends a custom HTTP header X-Sq-Scan-ID containing a UUID that can be correlated with reports in the SiteQuafety portal.

📊 Data Usage

Collected data—such as CMS version, open ports, SSL/TLS configuration, and common vulnerability signatures—is used exclusively to generate vulnerability reports for the website owner. SiteQuafety does not sell or share raw crawling data with third parties; aggregated anonymized statistics may appear in industry trend analyses. The service is marketed as a non‑intrusive reconnaissance tool that alerts administrators before attackers find the same weaknesses.

⚙️ Rate Limiting Policy

Because sq webscanner can issue several hundred requests during a full-site scan, rate limiting is a recommended precaution to prevent performance degradation. Most web applications impose a threshold of 10 requests per second per IP to balance the scanner’s legitimate need for thorough coverage with the server’s capacity. SiteQuafety itself advises rate limiting as a best practice in its getting‑started guide, noting that the scanner will automatically back off if it receives HTTP 429 Too Many Requests responses.

Free Traffic Analysis

What's Actually Crawling Your Website?

Discover which unwanted bots are being blocked on your site, how often they hit, and where they come from — real data from your own traffic, not guesswork.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the bots listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.