Appearance
Settings
Settings control how scans behave — the proxies they route through, how hard they hit a target, and what headers they send. There are two places to manage them, and global settings can be enforced so projects and individual scans cannot work around them.
Global vs. project settings
The same Settings screen appears in two scopes:
| Scope | Where to find it | Applies to |
|---|---|---|
| Global Settings | Bottom of the left sidebar, always available. | The whole platform / all projects. |
| Project Settings | The Settings item inside an open project. | Only that project. |
What you can configure depends on the scope:
| Setting | Global Settings | Project Settings |
|---|---|---|
| Proxies | ✅ (global proxies) | ✅ (global + project proxies) |
| Throttle | ✅ (platform-wide) | ✅ (project) |
| Host limits / retry / error limits | ✅ (platform-wide) | ✅ (project) |
| Scan Defaults | — | ✅ |
| Headers | — | ✅ |
| User-Agent | — | ✅ |
| Bustah skip directories | ✅ | ✅ |
| Bustah wordlist library | ✅ | — |
| LFIC fileset library | ✅ | — |
| Appearance: Theme (light / dark / retro), Motion | ✅ (this browser) | — |
| Appearance: Date format | ✅ (platform-wide) | — |
| License install / status | ✅ | — |
| Security (sign-in status, change password) | ✅ | — |
Headers, User-Agent, and Scan Defaults are project-scoped only.
Settings tabs
Both Global Settings and Project Settings use the same tabbed layout. A tab that has nothing to configure in the current scope is hidden automatically.
| Tab | Global Settings | Project Settings |
|---|---|---|
| Connection & Limits | Proxies, throttle, host limits (concurrency cap, host timeout, request timeout, retries) | Same (project can override where not globally enforced) |
| Scan Defaults | — (hidden) | Scan Defaults, Headers, User-Agent |
| Bustah | Skip directories + wordlist library | Skip directories only |
| LFIC | Fileset library | — (hidden) |
| Appearance | Theme and Motion (this browser), Date format (platform-wide) | — (hidden) |
| License | License status, install/replace/delete | — (hidden) |
| Security | Sign-in status, session expiry, change password | — (hidden) |
Open Global Settings from the bottom of the sidebar, or Settings inside a project for project-scoped values. See License for installing and replacing licenses.
Connection & Limits
Proxies, throttle, and host limits live on this tab at both global and project scope.
Proxies
Named proxies let you route scan traffic through tools like Burp Suite or Caido, or through a SOCKS5 tunnel. HTTP, HTTPS, and SOCKS5 are supported.
Add a proxy with Add Proxy, then set:
- Label — a friendly name (for example
Burp Suite). Required. - Scheme —
http,https, orsocks5. - Host and Port — required; port must be 1–65535.
- Username / Password — optional, for authenticated proxies. When editing, leave the password blank to keep the existing one.
A Quick Fill shortcut populates 127.0.0.1:8080 for the common local-proxy case.
Proxy scope
When you add a proxy from Project Settings, you choose a Scope:
- Global (all projects) — available to every project.
- This project only — visible only within the current project.
Global proxies are also created from Global Settings. In a project's proxy list, each row is tagged Global or Project so you can tell them apart.
Enforcing a proxy
Inside Project Settings, each proxy row has an Enforce toggle. Turning it on makes that proxy mandatory for the project:
When a project has an enforced proxy, all requests made by all tools for scans in that project are routed through it. There is no per-scan or per-tool override.
Only one proxy can be enforced per project. Toggle it off to remove enforcement. This is a project-level compliance control — for example, forcing every scan through an auditing proxy.
You cannot delete a proxy that is still enforced by one or more projects. Turn off enforcement (or reassign it to another proxy) in each project's Settings first; otherwise delete returns an error naming the projects still using it.
Throttle
Throttle limits how aggressively scans send requests. Fields:
- Concurrency — max simultaneous requests per scan (
0= use default). - RPS — max requests per second (
0= unlimited). - Delay — time between requests: a fixed value in milliseconds (for example
100) or a range for jitter (for example50-200). Empty = no delay.
Set these under Global Settings to establish platform-wide defaults, or under Project Settings to tune a single project.
The "Enforce" checkbox
Both the global and project throttle panels have:
Enforce these limits on all scans (cannot be overridden)
When enforce is on, the fields in that panel become the hard limit for everything beneath it, and lower levels cannot raise them.
HTTP 429 (rate limiting)
When a target returns HTTP 429, the platform applies adaptive backoff (honors Retry-After when present), requeues affected work, and slows further requests for that scan. This is separate from the Throttle RPS/concurrency knobs — it reacts to the target telling you to slow down.
If backoff is exhausted while 429s continue, the scan can still finish completed but is marked degraded, a medium finding is written, and a rate_limited note appears in Logs → Scan Activity. Lower scan rate/concurrency or use project throttle defaults to reduce recurrence.
Bustah has additional per-scan Rate limiting (429) options (Ignore 429, Never stop on errors) — see Bustah.
Host limits, retry, and error limits
These settings live under Connection & Limits → Host Limits. They control how many scans may run at once, how long a scan may spend actually scanning, how long one request may take, how many times a failing request is retried, and when a scan should give up on an unreachable host.
Max concurrent hosts
How many scans may run at the same time. Extra scans wait in the queue. The cap applies to Nikto, Crawl, LFIC, and Bustah. Range 1–100 (placeholder default 5). Check Enforce max concurrent hosts on all scans to lock the cap for every project and scan beneath this scope.
Host timeout (min)
Minutes of scanning time before a scan is stopped. 0 = no limit (max 20160, or 14 days). Time spent paused does not count; resume does not immediately time out a scan that was idle for a long wall-clock stretch. The scan list still shows the original start time. Check Enforce host timeout on all scans to lock the value.
A scan that hits the budget is marked timeout (not failed) with a finding titled Scan timed out after … (host timeout limit N min) and an activity line Scan stopped - host timeout exceeded (ran …, limit N min). Those durations are scanning time.
Request timeout (seconds)
How long one request may take before it counts as a failure. Default 15 seconds (range 1–600). Raise it for slow or distant targets.
A request that exceeds this is a transport error: it consumes a retry and counts toward Scan failure threshold, the same as a refused connection. It is not a host-timeout — that budget is for the whole scan.
A Nikto scan can override this on the Nikto tab (Request timeout, seconds). Crawl, LFIC, and Bustah use the value stored here.
Max retry attempts
Max retry attempts is the per-task retry budget: how many times a single HTTP request is attempted before it is permanently marked failed.
- Default: 5. A task that fails five consecutive times is retired; the scan continues with its remaining tasks.
- Applies to transport errors only (DNS failures, timeouts, connection refused). A real HTTP response — even a 4xx or 5xx — is a success and does not consume a retry.
- Increasing this is useful against hosts that occasionally drop connections.
- Valid range: 1–100.
Scan failure threshold (circuit breaker)
Scan failure threshold is a circuit breaker for a host that has stopped answering. It does not abort a live scan just because some requests timed out.
How it works:
- Every request that gets a transport error (no HTTP response at all — DNS failure, connection refused, timeout, network unreachable, TLS error) increments a per-scan failure counter.
- Any request that gets any HTTP response (200, 302, 404, 500 — anything) resets the counter to zero.
- When the count reaches the threshold and the host answered recently, the scan is not failed. The platform narrows this scan's concurrency (the same adaptive slowdown as HTTP 429) and writes a line in Logs → Scan Activity. Scan detail Speed limit shows narrowed after requests timing out against a target that is still answering.
- The scan is marked failed only when the host then stays silent after that narrowing has run its course. Remaining work is cleaned up, and one finding explains the abort (for example that the target was unreachable after many consecutive failures).
The counter is consecutive, not total. A burst of failures followed by a successful response starts the count fresh. The breaker only trips when the host goes quiet.
Notes:
0= disabled. The scan runs to completion regardless of how many transport errors occur.- Default: 75 consecutive failures.
- Malformed requests (a test URL the scanner cannot even build into a valid request) are excluded from the count — a bad test URL is not evidence the host is down.
- Valid range: 0–10000.
Precedence
Max retry attempts, Scan failure threshold, and Request timeout cascade platform → project → scan (most-specific wins). Unlike throttle, those three have no Enforce checkbox — a scan-level override always wins.
Max concurrent hosts and Host timeout do have Enforce checkboxes; when enforced at a higher scope, lower levels cannot raise them.
| Level | How to set | Wins over |
|---|---|---|
| Scan | Values on the scan form | Project, platform |
| Project | Project Settings | Platform |
| Platform | Global Settings | — (floor) |
Set platform-level values as your organization-wide defaults. Override at project or scan level when a specific target needs a looser or stricter policy.
TIP
A very low Scan failure threshold (for example 5) is useful when you want a host that goes fully silent to fail the scan sooner. A value of 0 (disabled) makes sense for intentionally unreliable lab targets where you want to collect whatever results are available. A target that is merely slow is narrowed, not aborted — raise Request timeout if legitimate requests are timing out.
Scan Defaults (project only)
Under Project Settings → Scan Defaults tab, set starting values for new scans created in this project. This is the broadest stored default tier:
scan launch options > host Scan Defaults > project Scan DefaultsAnything you pick on the New Scan wizard (or a host tool tab) always wins. Host defaults and project defaults only fill in keys the scan left unset. Existing scans are unaffected.
See also Host Scan Defaults for per-host overrides and Scan options for the launch-time fields.
Tri-state booleans
For Follow Redirects, Send Browser Headers, Secret Detection, and Force IPv6, each dropdown offers:
| Value | Meaning |
|---|---|
| No project default | Each tool uses its own built-in default when the scan does not specify the option |
| On | Force the option on for new scans |
| Off | Force the option off for new scans |
On the host Scan Defaults tab the unset option reads Use tool default (…) with the same per-tool summary.
Other fields
- User-Agent, Virtual Host, Root Path — blank means no project default.
- Proxy — default proxy for new scans. An enforced proxy still overrides at runtime.
- HTTP Version — optional Force HTTP/3 default for Nikto, LFIC, and Bustah (not crawl). The proxy-bypass acknowledgment stays per-scan only and cannot be stored here. See HTTP/3 scanning.
- Additional Headers — one per line (
Name: value). Separate from enforced headers, which are always applied.
Click Save when the panel shows unsaved changes. These are defaults, not policy — they remain overridable at the host and scan tiers unless a separate enforced control applies (proxy, headers, throttle).
Headers (project only)
Under Project Settings → Scan Defaults → Headers, add HTTP headers that get attached to scan requests for the project — one per line in Name: value form, for example:
X-Vercel-Protection-Bypass: your-key
Authorization: Bearer tokenCheck Enforce these headers on all scans (cannot be overridden or removed) to guarantee they are always sent, then Save Headers.
User-Agent (project only)
Under Project Settings → Scan Defaults → User-Agent, set the default User-Agent sent on the project's scan requests. Notes:
- Leave it empty to send no
User-Agentheader. - Use Reset to Default to restore the platform default.
- A test that sets its own
User-Agentoverrides this default.
How enforcement resolves
For any given scan, the platform decides the effective settings top-down. Enforcement at a higher level always wins:
- Global (platform) throttle enforced? → the platform's concurrency / RPS / delay are used, overriding project and scan values. This is the strongest control.
- Project throttle enforced? → the project's values are used, overriding the individual scan's values.
- Otherwise, values inherit down — the scan's value is used; if it's unset (
0or empty), the project value is used; if that's unset, the platform value is used; and finally a built-in default.
The enforced proxy and enforced headers work the same way in spirit: once set at the project level, scans cannot opt out of them.
| Control | Set at | When enforced, overrides |
|---|---|---|
| Throttle | Global and project | Global beats project beats scan |
| Proxy | Project (choose any global or project proxy) | All tools, all scans in the project |
| Headers | Project | All scans in the project |
TIP
Enforcement is about guaranteeing a control is applied. If you want a default that scans may adjust, set the value but leave Enforce unchecked.
Bustah skip directories
Under Settings → Bustah tab (global or project), set default directory names Bustah sweeps should skip (one per line, for example /admin/). Each entry matches case-insensitively at any depth — a directory name, not a rooted path.
Precedence at scan launch:
scan skip directories > project skip directories > global skip directoriesAn empty saved list means “skip nothing” and overrides inherited defaults. Clearing the field removes the override. See Bustah.
Bustah wordlist library (global only)
On Global Settings → Bustah, the Wordlists table lists every Bustah wordlist (name, entry count, Built-in tag for seeded defaults). Upload adds a custom list (name, optional description, one word per line or a file). Built-in lists cannot be deleted; custom lists have a trash action with confirmation.
A list file may be up to 128 MiB. If the upload is cut off, nothing is stored — try again. Uploaded wordlists are available in the New Scan wizard and host Bustah tabs alongside built-in lists. See Bustah → Wordlists.
LFIC fileset library (global only)
On Global Settings → LFIC, the Filesets table lists LFIC filesets (entry count, Built-in tag, Upload for custom sets, delete for non-default rows). Same 128 MiB cap as wordlists; a cut-off upload stores nothing. Custom filesets appear when launching LFIC scans. See LFIC → Filesets.
Appearance (global only)
Global Settings → Appearance holds Theme and Motion (per browser) and Date format (platform-wide).
Date format
How every date in the console is written. This one is stored on the platform, so it applies to every operator and every browser.
| Choice | Example |
|---|---|
| ISO (YYYY-MM-DD) | 2026-09-07 — sorts visually, unambiguous. The default. |
| US (MM/DD/YYYY) | 09/07/2026 — month first. |
| EU (DD/MM/YYYY) | 07/09/2026 — day first. |
The change applies across the app as soon as you pick it; the card reports Saving… then Saved., or Could not save — try again. if the write failed. Times of day, byte counts, and request totals are unaffected — this setting is the date part only.
Theme
| Choice | Effect |
|---|---|
| Match system | Follow this device's light/dark setting. The default. |
| Light | Always light, whatever the system says. |
| Dark | Always dark, whatever the system says. |
| Retro terminal | Green phosphor on black, monospaced, square-cornered. |
The sun/moon toggle in the topbar is the quick control and has two positions, so it always sets an explicit Light or Dark. Match system and Retro terminal are only available here — use Match system to go back to following the device after using the toggle, and note that the toggle leaves Retro terminal for Light.
Retro keeps severity colours distinguishable (amber, red, cyan) rather than going fully monochrome, so findings stay scannable. No animation is added. /nikto-diag has no retro palette and follows the dark one.
Both controls read and write the same preference and stay in step, including across browser tabs. The /nikto-diag Status page follows the resolved theme as well.
Motion
Whether the console animates spinner rotation and colour transitions.
| Choice | Effect |
|---|---|
| Match system | Follow this device's reduce-motion setting. The default. |
| Full motion | Animate even when the system asks to reduce motion. |
| Reduced | No spinner rotation or colour fades. |
Both overrides are useful: a locked-down or shared machine may not let you change the OS setting, and someone who reduced motion OS-wide for one bad application may still want animation here.
Each card reports the result below the choices — Currently: dark., Currently: motion is reduced. — so Match system shows which way the device answered.
Where these are stored
Theme and Motion are saved in this browser, not in the platform database. They are not project-scoped, they cannot be enforced, and they do not follow you to another machine or change what other operators see. An existing theme choice carries over from earlier versions.
Date format is the exception: it is a platform setting, so it is shared by every operator and every browser. See Accessibility.
Security (global only)
Global Settings → Security shows who is signed in and when the session expires, and has a Change password form. When login is disabled (AUTH=off), this tab says so instead of showing a form that cannot work. See Operator Login for first login, password rules, and what to do if you are locked out or have forgotten the username.