
What's New in Pipsqueak: AI Reports, CLI, Localhost Scanner & More
New Features
Localhost Scanner – Extension Audit
Added Extension Audit support to the Localhost Scanner, enabling detection and auditing of installed browser extensions during localhost scans.
Pipsqueak CLI
Introduced the Pipsqueak CLI, allowing command-line execution, automation, and easier integration into scripts and CI/CD workflows.
Windows Security Data Collection
Enhanced the Localhost Scanner to collect and report Windows Security information, including:
Current security threats
Virus & Threat Protection settings
Virus & Threat Protection updates
Ransomware Protection status
Website Improvements
Lead Magnet Report
Enhanced the Lead Magnet Report by providing clear explanations for every finding. Each issue now includes:
What was tested
What condition failed
Why the finding was flagged
The security or compliance impact of the issue
Improved scan reliability by routing Lead Magnet scans through a proxy when required. This helps:
Bypass regional access restrictions that may prevent websites from being reached.
Eliminate false-positive HTTPS/security findings caused by regional IP restrictions or geo-blocking.
Produce more accurate and consistent scan results across different geographic locations.
Organization Management
Added the ability for administrators to create new organizations directly from the main dashboard, streamlining organization onboarding and management.
Organization Scan Links
Added a new feature that allows administrators to generate secure scan links and share them with users within an organization.
Users can scan their local environment without requiring direct administrator involvement.
Scan results are automatically aggregated into a centralized organizational report, providing a unified view of the organization's security posture.
URL Processing Improvements
Enhanced URL processing to correctly handle a wide range of domain input formats, including:
Root domains
Subdomains
URLs with query parameters
URLs containing paths and fragments
HTTP and HTTPS variations
Improved URL normalization and validation to ensure all supported URL formats are processed consistently, reducing scan errors and improving scan accuracy.
AI-Generated Custom Reports
Redesigned the AI Report Builder experience — instead of typing a prompt from scratch, users now select from a curated list of Recommended Prompts tailored to their chosen Report Scope (Executive/Technical) and Page Orientation (Portrait/Landscape). Selecting a prompt builds the report immediately, with no extra steps.
Recommended prompts now adapt to the data actually present in the scan (Active Directory, Network, Localhost, Microsoft 365, PII, External Risk), so users only see report options their data can actually support.
Added a "Create your own prompt" option for teams that want full control over the AI's focus.
Improved consistency of AI-generated content — scorecards, charts, and supporting figures are now computed directly from the real scan data using a repeatable method, so regenerating the same report produces the same findings and scores every time.
Landscape reports now present one finding (issue, evidence, and remediation) per page, matching the clean, slide-style format used in competitor reports.
Added AI-driven topology diagrams for Active Directory computers, in addition to network topology — with device labels intelligently sized so long names never overflow.
General report polish: automatic page numbering, sharper and larger charts, capped table pagination to prevent runaway multi-page reports, and cleaner placeholders for unconfigured images.
Multi-Factor Authentication (MFA)
Added support for authenticator-app MFA (Google Authenticator, Microsoft Authenticator, Duo) as a faster, more reliable alternative to emailed sign-in codes.
Authenticator app is now the default sign-in method for new accounts; users can alternatively opt in to email-based codes during setup.
Users can download their one-time recovery codes with a single click, ensuring they always have a backup if they lose access to their device.
Platform/Global Administrators can now reset a user's MFA configuration, giving support teams a safety net for users who lose both their device and recovery codes.
Added a dismissible, high-visibility banner that encourages existing users to upgrade from emailed codes to authenticator-app MFA.
Tenant Brand Colors
Tenant administrators can now configure their organization's brand color palette (Primary, Secondary, Accent, and additional colors) directly from the Admin Panel.
Once configured, brand colors automatically become the default color palette in the AI Report Builder — every generated report matches the tenant's branding with zero manual setup.
Administrators can start from one of Pipsqueak's built-in presets and customize further, or build a fully custom palette from scratch.