Analytics & Beyond protects every website scan at the server. The crawler accepts only public HTTP or HTTPS addresses on standard ports. It checks resolved IPv4 and IPv6 addresses, rechecks every redirect, blocks credentials and private or reserved networks, requests uncompressed responses, accepts only expected content types, and stops at fixed response and redirect limits.
Brand and account privacy
Every authenticated request checks the signed-in user, WordPress nonce, capability, and brand authorization again on the server. A brand URL or ID does not grant access by itself. Administrators can act across accounts only through administrator-only tools.
Reports and attachments
Private report links use a random hashed token with an expiration date and can be revoked. Expired or revoked token material is removed by retention cleanup. Before a generated report PDF is handed to the mail provider, the platform confirms that it is a real PDF inside the private temporary directory, checks its size and MIME type, and screens it with ClamAV. A missing scanner, scan error, or malware finding blocks the attachment.
Retention
Expired public result tokens and public lead contact details are removed after the configured retention period. Old security events, completed queue jobs, expired report-share tokens, crawler evidence for expired public scans, and known Analytics & Beyond temporary files are also removed by bounded cleanup. Active brand data and authorized retained scan history are not deleted by this public-lead cleanup.
Worker health
Administrators open A&B Platform > Jobs & Workers. Worker Health & Security shows crawler runtime and storage, LanguageTool, malware signatures, queue recovery, the last worker result, oldest queued job, 24-hour completion and failure counts, private crawler storage, free disk space, and the last retention cleanup. Run Retention Cleanup runs the same bounded cleanup immediately.
When a check says Attention
Run the worker once, review failed jobs, confirm the local service or scanner is active, and retry only after the cause is fixed. Do not disable malware screening to force an email through. Contact the platform administrator when a safety check remains unavailable.
