Re-runs SQL Injection, XSS, Input Validation, CSRF, Open Redirect, and IDOR across every crawled page (not just the homepage) — a form or query param elsewhere on the site is real, previously-unscanned attack surface.