Stop scanning. Start reading changelogs.
Unpopular opinion after a year of this: my best findings have not come from a scanner. They have come from reading the product's own release notes and asking what had to change underneath to ship that feature.
A new export format means a new parser. A new SSO option means new session handling. A new mobile release means the API grew endpoints the web client never calls.
The scanner tells you what everyone else already found. The changelog tells you what shipped last Tuesday and has been in front of maybe nine people.