About the WideAisle scanner
If you found this page from your server logs, the WideAisle scanner may have visited during an authorized client preflight, an internal canary, or a controlled shadow test of an official Shopify demo or explicitly authorized storefront. Here is exactly what it does.
Scanner identifier: every production browser profile includes WideAisleScanner/0.1 (+https://wideaisle.com/scanner.html) in its User-Agent string.
What it does
- Attempts one discoverable public home, collection, product, cart, search, and information template.
- Runs a locked automated ruleset in desktop, Pixel 5 touch, and 320 CSS-pixel reflow profiles. Browser profiles can load the same public resource more than once.
- To load the public cart template, the scanner adds one available public product variant to an isolated, per-device cart session. That temporary cart state is discarded after the run and is not shared with unrelated page templates.
- Uses stop thresholds of 30 top-level document navigations, 2,000 origin requests, 50 MiB of recorded response content (discovery bodies plus origin response bodies admitted to browser capture), and 15 minutes. The response-content ceiling is shared across capture pages and enforced before each bounded stream read; reaching it cancels in-flight responses and records incomplete coverage. Request and response headers, encrypted transport overhead, bytes buffered below Chromium's response-stream boundary, and scan-local cached replays are outside this ceiling. Chromium-exposed browser-delivered requests and bytes are recorded separately. Cross-origin frame documents are blocked and not assessed because their isolated browser targets cannot share this response boundary.
What it never does
- No unbounded crawling, speculative inventory collection, or attempt to submit a purchase.
- WideAisle does not bypass bot protection, CAPTCHAs, passwords, or logins. A blocked or failed page attempt is recorded as incomplete; an HTTP 429 response stops the entire run.
- No bypass of an HTTP 429 response. The run stops and records incomplete coverage.
- No screenshots, account creation, contact or newsletter submission, checkout submission, or changes to storefront code.
Why
When an authorized preflight is run, the scanner records observations supported by automated accessibility checks for a developer worklist and sanitized evidence appendix. Private pilot requests are reviewed before payment; submitting a request does not start a scan.
Opt out
Email hello@wideaisle.com with your
domain and we will suppress future WideAisle outreach to that store. A later client preflight requires a separate explicit authority attestation.
Home · Privacy · Terms