curl <url> | bash is arbitrary local code execution with no checkpoint. curl qsa.sh is not that pattern: it streams a report, runs nothing on your machine, and scans only your own public IP from the outside.
A small bash script that runs a qsa.sh scan on a schedule, remembers the last result, and notifies you only when your externally visible exposure actually changes. Works with free and paid tokens.
nmap 7.99 and nuclei 3.11.1 are now live for every scan, scan time budgets have been rebuilt so long scans finish instead of being cut off, and every scan now opens with origin intelligence from worldip.io.
qsa.sh runs a real external security and port scan of your own server, from outside your network, in about thirty seconds with nothing to install — and it only ever scans the IP you connect from.