Website Security Scanner
We open a real TLS connection to your site, read the certificate, and check the security headers it sends back. You get a graded report of what is there and what is missing.
Issues Found in Your Scan?
This scanner checks surface-level issues. A CREST-certified penetration test goes deeper, testing authentication, business logic, and application-layer vulnerabilities.
About the Security Scanner
The scanner opens a TLS connection to the address you give it, reads the certificate the server presents, and records the security headers that come back with the page. You get the issuer, the expiry date, the protocol and cipher that were negotiated, whether the server still accepts TLS 1.0 or 1.1, and which of the standard security headers are set.
It is a surface check, and a useful one before a Cyber Essentials assessment, before a customer audit, or after a deploy. A certificate expiring next week or a missing Content-Security-Policy is cheap to fix now and awkward to explain later.
It does not enumerate network ports, match services against CVE feeds, log in to anything, or test application logic. That work needs a scope and written authorisation. Our CREST-certified penetration testing and the credentialed CE Plus pre-assessment cover that ground.
Common questions
Is the security scanner free?
Yes. We rate-limit by source address and by target so the service stays available, and each email address can unlock the full report for two domains.
Does this scan network ports?
No. It reads the TLS certificate and the HTTP security headers, nothing else. Port enumeration and CVE matching are a different job, and one that needs written authorisation from whoever owns the address.
Should I run this against a site I do not own?
No. Unauthorised scanning can be a Computer Misuse Act 1990 offence. Run it against domains you own or have explicit written authorisation to test.
What do I do with the report when it is done?
Start with the certificate. If it is expired, close to expiry, or does not cover the hostname, fix that first, because browsers will warn your visitors before anyone reads a header. Then add the missing headers, worst first. If there is more than you can act on internally, the next step is a scoping call with us.
Beyond the free check
CREST-Certified Penetration Testing
Manual exploitation, application-logic testing, and a chained-attack write-up beyond what an automated scan can find.
Learn moreCE Plus Pre-Assessment
Authenticated scan with the same class of enterprise scanner the assessor runs on CE Plus day.
Learn more24/7 Threat Monitoring (MDR)
Continuous detection across your estate, with analysts who investigate and respond rather than forward an alert.
Learn more