Home/Services/Website Vulnerability Scanning
security service

Website Vulnerability Scanning

European website vulnerability scanning: recurring authenticated scans, verified by engineers so you get real findings. From EUR120/month. NDA, free retest.

Manual, expert-ledEvidence-based findingsFree remediation retest

Website vulnerability scanning gives you a regular, systematic check of your site for known weaknesses, so an outdated component or a careless misconfiguration is caught by you rather than by an attacker’s automated tools. SafetyBis runs recurring scans for businesses across Europe and, crucially, has an engineer verify what comes back, so you get a short list of real problems instead of a thousand-line export you have to interpret yourself.

The dirty secret of vulnerability scanning is that the raw output is mostly noise. A scanner flags anything that might be an issue, then leaves you to work out which findings are real, which are duplicates, and which are theoretical. That triage is where the value is, and it is the part cheap scanning services skip entirely.

What website vulnerability scanning covers

A scan is a broad, repeatable sweep for known and detectable weaknesses across your site and its stack. It will not find every subtle logic flaw, and it does not pretend to. What it does well is catch the large category of problems that are already documented, exploitable, and fixable, and catch them regularly enough that new ones do not sit unnoticed.

Detection of outdated CMS, plugins, themes and libraries with known CVEs
Misconfigurations: directory listing, exposed backups, debug mode left on
Injection and cross-site scripting checks across inputs and parameters
TLS configuration, weak ciphers and missing security headers
Exposed admin panels, sensitive files and information disclosure
Every finding checked by an engineer before it reaches your report

Website security scanning works best as a habit, not a one-off. Your site changes, new vulnerabilities are published constantly, and last month’s clean bill of health says nothing about this month’s newly disclosed plugin bug.

What a scan actually looks for

Web vulnerability scanning covers several categories of weakness. Understanding them helps you see where a scan is strong and where it needs a human, or a full penetration test, to go further.

Recurring
scheduled scans, weekly or monthly, not once a year
100%
findings verified by hand, no false-positive dumps
Free
retest after you fix a reported issue

Known vulnerable components

The single most productive thing a scan does is compare the software you run against public vulnerability databases. An outdated plugin or library with a published CVE is the entry point in most site compromises, and a scan surfaces it before an attacker’s automated sweep does.

Configuration and exposure

Scans catch the boring mistakes that cause real breaches: a database backup sitting in the web root, directory listing left enabled, an admin login with no protection, debug output printing internal paths and stack traces. None are clever attacks; all are commonly exploited.

Common web vulnerabilities

Automated checks probe inputs for injection and cross-site scripting, test for path traversal, and look for information disclosure. These map to the OWASP Top 10 categories a scanner can reliably detect, which is a useful subset, though not the whole picture.

Where a scan reaches its limit

A scanner cannot reason about your business logic. It will not notice that changing an ID in a URL returns another customer’s order, or that a checkout step can be skipped. Those need a person testing by hand, which is what a penetration test provides. An honest scanning service tells you this rather than implying a scan is the same thing.

How our vulnerability scanning works

The process is built around one principle: a report you can act on beats a report that is technically complete. We do the triage so your team does not have to.

Automated tooling

We run established scanning engines against your site on a schedule you choose. The tools do what tools are good at: broad, tireless, repeatable coverage that would take a person far too long to do by hand every week.

Authenticated scanning

Much of a modern site lives behind a login, and an unauthenticated scan never sees it. We run authenticated scans with test credentials so the members’ area, the dashboard and the account functions are covered, not just the public marketing pages. This routinely finds issues an external-only scan misses entirely.

Manual verification

Every finding the tools raise is reviewed by an engineer before it reaches you. False positives are removed, duplicates merged, and the real issues are rated by their actual impact on your site rather than a generic severity label. This is the step that turns a scan into something worth reading.

Reporting and re-scan

You get a clear report of the verified findings, each with a fix, ranked by priority. After you remediate, we re-scan the affected areas for free to confirm the issue is genuinely closed. Then the cycle repeats on schedule, so your assurance stays current.

Scanning versus penetration testing

These two get sold as if they were interchangeable, and they are not. Knowing the difference stops you overpaying for one or under-protecting with the other.

A vulnerability scan is broad, automated, frequent and relatively cheap. It is excellent at catching known issues across your whole site on a regular cycle, and it is the right tool for ongoing hygiene. A penetration test is deep, manual, periodic and more expensive. An engineer thinks like an attacker, chains flaws together, and finds the business-logic and access-control problems no scanner can see. You want both: scanning for continuous coverage of the known, and testing for periodic depth on the unknown. Buying only scanning and calling it a pentest is a common and costly mistake.

Get a fixed quote

Want this tested on your own systems?

Free 20-minute scoping call, a fixed price with no hourly surprises, and a free retest once you fix what we find.

Get a fixed quote

Authenticated versus unauthenticated scanning

Whether the scan logs in makes a large difference to what it finds, and it is worth being deliberate about.

Unauthenticated scans

These see your site as an anonymous visitor does. They are quick to set up and good for catching exposed files, outdated public-facing components and configuration mistakes. But they are blind to everything behind a login, which on most sites is where the sensitive functionality lives.

Authenticated scans

With valid credentials, the scan reaches the account area, the admin functions and the authenticated APIs. This is where broken access control, insecure account features and post-login injection tend to hide, so for any site with a login, authenticated scanning is where the real coverage comes from.

Scanning and compliance

Regular scanning is not just good hygiene; some frameworks require it on a fixed cadence, and a scanning programme is the cleanest way to evidence that.

PCI DSS scanning requirements

PCI DSS requirement 11.3 expects regular internal and external vulnerability scans, typically quarterly and after significant changes, with external scans by an approved vendor. Our recurring scanning and reporting are built to slot into that cadence and produce the evidence an assessor asks for.

ISO 27001 and GDPR

ISO 27001 Annex A.12.6 covers technical vulnerability management, which a documented scanning programme directly supports. For GDPR, being able to show you actively look for and fix weaknesses is part of demonstrating appropriate technical measures for protecting personal data.

What you get

The deliverable is a report your team can work from and hand to an auditor, not a raw tool dump.

A ranked list of verified findings, false positives already removed
A clear fix and severity for each issue, not just a CVE number
Trend data across scans, so you can see risk falling over time
Reports and evidence formatted for PCI DSS and ISO 27001

What our scans turn up most often

After running these across a lot of sites, the findings cluster into a predictable set. None are exotic, and that is exactly the point: the routine problems are the ones that get sites breached, and a regular scan keeps them from piling up.

Software that quietly went out of date

The most common serious finding is a plugin, theme or library that was current at install and has since picked up a known vulnerability. On a busy site with several contributors, things fall behind without anyone deciding to let them. A scan makes the gap visible and puts a name and a fix against it.

Files that should never have been public

Database dumps, configuration files with credentials in them, old copies of pages left over from a migration, and log files sitting in a web-accessible folder. Attackers look for these first because they are easy wins, and a scan finds them the same way, just sooner.

Weak transport and missing headers

Outdated TLS settings, weak ciphers, and missing security headers such as content security policy or strict transport security. Individually minor, collectively they widen the surface for attacks like session hijacking and clickjacking, and they are quick to fix once flagged.

How to read the report

We rank findings so you spend your time where it counts. A critical or high finding with a known exploit gets fixed this week; a low-severity informational note can wait for the next maintenance window. Because we have already stripped the noise, the ranking reflects real risk to your site rather than a scanner’s blanket scoring, and your developers are not left guessing which of two hundred lines actually matters.

Pricing

Website vulnerability scanning is billed as a monthly plan, priced by how often you scan, how many sites are in scope, and whether the scans are authenticated. Here is the shape of the plans.

Plan What’s covered Cadence Price
Essential One site: monthly unauthenticated scan, engineer-verified report, prioritised fixes Monthly from €120/month
Business Up to three sites: authenticated scanning, more frequent scans, trend reporting, re-scan on demand Weekly or monthly from €180/month
Managed Business-critical site: authenticated scanning plus manual review of high-risk findings and 24/7 escalation Weekly from €250/month
Compliance scan Scheduled scanning and reporting aligned to PCI DSS 11.3 with the evidence an assessor needs Quarterly + changes from €180/month
Custom / large estate Many sites or a full platform under one scanning programme, scoped to you on scoping custom

Every plan is fixed-price, quoted after a free 20-minute scoping call, and a re-scan to confirm your fixes is always included. Get a fixed quote

FAQ

How much does website vulnerability scanning cost?
Plans start from €120 per month for a single site scanned monthly, rising with scan frequency, the number of sites, and whether scans are authenticated. You get a fixed quote after a free scoping call, with the re-scan included.
Is a scan the same as a penetration test?
No. A scan is broad, automated and frequent, catching known issues across your whole site. A penetration test is deep and manual, finding business-logic and access-control flaws a scanner cannot see. Most businesses need both: scanning for hygiene, testing for depth.
Will the report be full of false positives?
No, and that is the point of our service. An engineer verifies every finding, removes false positives and duplicates, and rates real issues by their actual impact, so you get a short, actionable list rather than a raw export.
Do you scan behind the login?
Yes, on authenticated plans. We use test credentials so the account area, dashboard and authenticated APIs are covered. That is where broken access control and post-login flaws usually hide, so authenticated scanning finds far more than an external-only scan.
How often should I scan my website?
Monthly is a sensible minimum for most sites, weekly for anything busy or business-critical, and after every significant change. New vulnerabilities are published constantly, so a recurring cadence matters more than a single deep scan.
Does this meet PCI DSS scanning requirements?
Yes. PCI DSS 11.3 expects regular internal and external scans, typically quarterly and after major changes. Our scanning and reporting are built to that cadence and produce the evidence an assessor asks for.
Will scanning disrupt my live site?
No. We schedule scans sensibly, throttle where needed, and agree any intrusive checks in advance. For very sensitive setups we can scan a staging copy. Availability is never the price of finding a weakness.
Do you keep the results confidential?
Always. Scanning runs under an NDA, and findings, credentials and any data touched are shared only with the people you name. As a European provider we handle your data accordingly.

Related services

Who needs this

Businesses across Europe that want continuous, verified visibility of the known weaknesses on their website, whether to stay ahead of attackers, satisfy a PCI DSS or ISO 27001 requirement, or simply stop finding out about outdated software the hard way.

why safetybis

Security you can prove

The same standard on every engagement, big or small.

Evidence, not opinions

Every finding ships with a reproduction and proof of concept — no vague "maybe vulnerable".

Humans over scanners

Certified engineers find the logic flaws and chained attacks automated tools walk straight past.

Fixed price, free retest

You know the cost up front, and verifying the fix is part of the deal — not a second invoice.

500+
assessments delivered
<30min
incident first response
12k+
infections removed
98%
fixed within one retest
$ safetybis quote --service "Website Vulnerability Scanning"

Ready to lock this down?

Free scoping call, fixed price, free retest. Tell us what you're running and we'll take it from there — usually within one business day.

get in touch

Tell us what you're running

Scoping is free. We reply within one business day, and under 30 minutes for active incidents.