What your free website scanner misses

Type your domain into any free "website security checker" and you get a green badge in ten seconds. It feels good. It also tells you almost nothing about whether an attacker could get in. This page explains what those free tools actually check, what they skip, and what the scan standard used by the card industry looks at instead.

What your free website scanner misses

What a free checker actually does

Most free scanners run a handful of quick, harmless tests from the outside: is your SSL certificate valid, do you send a few recommended security headers, is your software version visibly out of date, is your site on a malware blacklist. They finish in seconds because they don't probe anything. They read what your site announces about itself and grade it. That's useful for catching an expired certificate. It is not a security assessment.

What it skips

  • Open ports and services. A free checker looks at your website on port 443. An attacker looks at everything else: a database port left open, a remote desktop service, an old FTP server, a management interface. A full scan probes every port on every address you own.
  • Known vulnerabilities in what's running. Free tools might notice you're on an old version. A real scanner tests for the specific weaknesses in that version, thousands of them, and tells you which ones apply to you.
  • Weak encryption in practice. "Certificate valid" is not the same as "encryption strong." Old TLS versions and weak cipher suites pass a certificate check and fail a real scan.
  • Web application flaws. SQL injection, cross-site scripting, broken authentication. These live in your forms, logins, and search boxes. A header check can't see them; a web application scan is built to find them.
  • The things you forgot you had. A staging server, an old subdomain, a test environment still online. Free checkers scan the address you typed. A proper scan starts by finding every address that belongs to you.
  • Anything on the inside. Free checkers only see the outside. Internal scanning and agent-based scanning look at the systems behind your firewall, where most damage actually happens.

What "bank-grade" means

When you accept card payments, the card brands require your internet-facing systems to be scanned every quarter by a PCI Approved Scanning Vendor, an ASV. There are only about 80 ASVs in the world, and each one's scanning engine is tested and re-approved by the PCI Security Standards Council every year. The scan has to find any vulnerability rated medium or higher, and one finding fails the whole scan. It is the strictest routine scanning standard in general use, because money is on the line.

That standard isn't only for merchants. The same engine that decides whether a bank's merchant passes can scan any website, server, or application. Clone Systems has been an ASV since 2007, runs more than 100 million vulnerability checks a day, and sells that scan online to anyone who wants to know what an attacker would find.

Side by side

Free website checkerClone Systems external scan
Time to resultSecondsMinutes to hours, depending on scope
What it looks atThe web page you typed inEvery port and service on every address you own
Certificate checkYesYes, plus protocol and cipher strength
Known vulnerability testingVersion lookup at bestThousands of specific checks, updated daily
Web application flawsNoYes, with authenticated web app scanning
Finds forgotten assetsNoYes, discovery is part of the scan
Rescans after you fix thingsRun it again yourselfFree, unlimited rescans
Explains what to fixA gradeFindings with remediation steps, plus an optional AI assistant that explains each one in plain language
Accepted by banks and auditorsNoYes, from a PCI Approved Scanning Vendor
PriceFreeFrom $595 a year for 10 IPs; PCI ASV scans from $185

When a free checker is enough

If you run a personal blog with no logins, no forms, and no payments, a free checker plus keeping your software updated is a reasonable place to stop.

When it isn't

If your site takes payments, has customer logins, stores anyone's data, or is something your business would suffer without, a free checker is a false sense of security. The next step doesn't need a security team or a sales call: external vulnerability scanning from Clone Systems starts at $595 a year for 10 IPs, you buy it online, and you can run the first scan today.

See scanning packages and buy online · Talk to a specialist

Clone Systems is a PCI Security Standards Council Approved Scanning Vendor, listed since 2007.

Ready when you are

Ready to see what a real scan finds?

External vulnerability scanning from Clone Systems starts at $595 a year for 10 IPs. Buy it online, run your first scan today, and rescan for free whenever you fix something.