The QAuncle scanner
If QAuncle visited your website, this page explains who we are and exactly what we did. Last updated 4 October 2026.
Why it visited
Someone typed your website's address into QAuncle and asked for an audit. QAuncle does not crawl the web and does not find sites on its own. It scans only an address a person gave it.
How to recognise it
Its User-Agent contains QAuncle/0.1 (+https://www.qauncle.com/bot). It runs from Google Cloud, so there is no fixed range of IP addresses to list.
What one scan requests
- The page that was entered, opened in a real browser twice - once at a desktop size, once at a phone size - so it can measure layout, colour and speed. It scrolls the page and takes screenshots.
- Up to 12 JavaScript files from your own site, which it reads to check that no secret key was shipped inside them.
- Your
/robots.txtand/sitemap.xml, to see whether they exist. - A short fixed list of addresses where sites often expose files by mistake, such as
/.env,/.git/config,/.vscode/settings.json,/adminand/server-status. Each is a plain GET request, made only to learn whether the file is publicly readable. We do not try passwords, we do not send input, and we do not try to get past anything.
That is all: besides the files your page loads for itself, a scan makes at most about 35 requests. It does not follow links to other pages, does not log in, and does not submit forms.
How often
A visitor who is not signed in can start one scan an hour, and a signed-in account is limited too, so a site is not hit repeatedly.
What we keep
The measurements and findings, and screenshots for 24 hours. See the Privacy Policy.
If you do not want to be scanned
Email lsc.aisolutions@gmail.com with your domain and we will add it to a list our scanner refuses to scan. We do not decide whether to scan a page by reading your robots.txt, because a person asked for that scan; the list is how you opt out.
If something looks wrong
Write to the same address and tell us what you saw in your logs and when.