Search for a website security scanner and you will find dozens of options, from free online checkers to paid platforms with monthly subscriptions. They all promise to find problems on your site, but they do very different jobs. Before you pay for anything, or rely on a free tool, it helps to know what each type can actually tell you.
What Is a Website Security Scanner?
A website security scanner is a tool that checks a website for known weaknesses and misconfigurations, then reports what it found. Some look at your site from the outside, the way a visitor or an attacker would. Others run inside your server or connect to your account to see more. The difference matters, because it decides what the tool is able to find.
The Main Types of Tools
- Free external scanners: check what is visible from the internet, such as your SSL setup, security headers, exposed files and DNS records. Some cover one area only, and some cover several.
- Paid vulnerability scanners: usually run on a schedule, can scan more deeply, and may check pages that need a login.
- Malware scanners and monitoring services: look for infected files and suspicious changes, and may alert you or help clean up.
- WordPress security plugins: run inside your site, so they can check files and add a firewall and login protection.
- Professional audits and penetration tests: a person reviews your setup and code and tests it with your permission.
What a Free External Scan Can Find
- An expired or misconfigured SSL certificate, and a missing HTTPS redirect.
- Missing or weak security headers.
- Weak cookie settings.
- Sensitive files or folders that are publicly reachable, such as
.envfiles and backups. - Missing SPF and DMARC email records.
- Platform-specific exposure, such as an enabled XML-RPC endpoint on WordPress.
What a Free External Scan Cannot Find
- Malware inside your files. An outside scan cannot confirm that your site is clean.
- Problems in your code. It does not read your source code or review how your application works.
- Anything behind a login. Customer accounts and admin areas are out of reach.
- Server-level issues. Weak passwords, wrong file permissions and outdated server software are mostly invisible from outside.
What Paid Tools Usually Add
Paid products vary a lot, so check what a specific tool does before you pay. Common extras include scheduled scans with alerts, scanning of logged-in areas, deeper matching of your software against known vulnerabilities, malware detection and cleanup, a firewall, support, and reports for compliance. These are valuable for some sites, and unnecessary for others.
What Actually Matters When Choosing
- Permission and method. Only scan sites you own or have permission to test. Running tests on systems that are not yours can break the law in many places. Stick to passive tools, which only request what a normal browser can see, and be wary of any tool that sends attack payloads.
- Plain-English results. A list of technical codes is not much help. Look for explanations of why each issue matters and how to fix it.
- Honesty about false alarms. A missing header is not always a vulnerability, and a good tool shows how sure it is about each finding.
- What it asks from you. Check what details you must give, and what the provider does with them.
- Fit for your site. A brochure site, an online store and a custom web app need different things.
- One-off or ongoing. A single scan is a snapshot. Sites change, so regular checks matter more than one perfect result.
Which Option Fits Your Site?
This is a sensible starting point, not a rule.
- Small brochure or business site: a free external scan every few months and after any update, plus working backups, updated plugins and strong logins, is a good base.
- WooCommerce store or a site that collects customer details: add continuous protection and monitoring, and consider a professional review of your setup once or twice a year.
- Custom web app or a site holding sensitive data: a professional code audit or penetration test is worth the cost, with paid scanning alongside it.
Where Our Free Scanner Fits
Our free website security scanner is a free external scan. It checks your SSL setup, security headers, cookies, exposed files, SPF and DMARC records, and WordPress-specific exposure if WordPress is detected. Every check is passive and read-only. You see your score on the page straight away, and the full PDF report is emailed to you, so the form asks for your name, email and phone. It is a good first check, but it is not a replacement for a code review or malware scan.
To learn more about what it looks at, read our guides on how to check if your website is secure, SPF, DKIM and DMARC, exposed .env and backup files, and security headers. If your scan shows serious issues, or you need a deeper review than any scanner can give, talk to our team.