Website Vulnerability Scanning
European website vulnerability scanning: recurring authenticated scans, verified by engineers so you get real findings. From EUR120/month. NDA, free retest.
Website vulnerability scanning gives you a regular, systematic check of your site for known weaknesses, so an outdated component or a careless misconfiguration is caught by you rather than by an attacker’s automated tools. SafetyBis runs recurring scans for businesses across Europe and, crucially, has an engineer verify what comes back, so you get a short list of real problems instead of a thousand-line export you have to interpret yourself.
The dirty secret of vulnerability scanning is that the raw output is mostly noise. A scanner flags anything that might be an issue, then leaves you to work out which findings are real, which are duplicates, and which are theoretical. That triage is where the value is, and it is the part cheap scanning services skip entirely.
What website vulnerability scanning covers
A scan is a broad, repeatable sweep for known and detectable weaknesses across your site and its stack. It will not find every subtle logic flaw, and it does not pretend to. What it does well is catch the large category of problems that are already documented, exploitable, and fixable, and catch them regularly enough that new ones do not sit unnoticed.
Website security scanning works best as a habit, not a one-off. Your site changes, new vulnerabilities are published constantly, and last month’s clean bill of health says nothing about this month’s newly disclosed plugin bug.
What a scan actually looks for
Web vulnerability scanning covers several categories of weakness. Understanding them helps you see where a scan is strong and where it needs a human, or a full penetration test, to go further.
Known vulnerable components
The single most productive thing a scan does is compare the software you run against public vulnerability databases. An outdated plugin or library with a published CVE is the entry point in most site compromises, and a scan surfaces it before an attacker’s automated sweep does.
Configuration and exposure
Scans catch the boring mistakes that cause real breaches: a database backup sitting in the web root, directory listing left enabled, an admin login with no protection, debug output printing internal paths and stack traces. None are clever attacks; all are commonly exploited.
Common web vulnerabilities
Automated checks probe inputs for injection and cross-site scripting, test for path traversal, and look for information disclosure. These map to the OWASP Top 10 categories a scanner can reliably detect, which is a useful subset, though not the whole picture.
Where a scan reaches its limit
A scanner cannot reason about your business logic. It will not notice that changing an ID in a URL returns another customer’s order, or that a checkout step can be skipped. Those need a person testing by hand, which is what a penetration test provides. An honest scanning service tells you this rather than implying a scan is the same thing.
How our vulnerability scanning works
The process is built around one principle: a report you can act on beats a report that is technically complete. We do the triage so your team does not have to.
Automated tooling
We run established scanning engines against your site on a schedule you choose. The tools do what tools are good at: broad, tireless, repeatable coverage that would take a person far too long to do by hand every week.
Authenticated scanning
Much of a modern site lives behind a login, and an unauthenticated scan never sees it. We run authenticated scans with test credentials so the members’ area, the dashboard and the account functions are covered, not just the public marketing pages. This routinely finds issues an external-only scan misses entirely.
Manual verification
Every finding the tools raise is reviewed by an engineer before it reaches you. False positives are removed, duplicates merged, and the real issues are rated by their actual impact on your site rather than a generic severity label. This is the step that turns a scan into something worth reading.
Reporting and re-scan
You get a clear report of the verified findings, each with a fix, ranked by priority. After you remediate, we re-scan the affected areas for free to confirm the issue is genuinely closed. Then the cycle repeats on schedule, so your assurance stays current.
Scanning versus penetration testing
These two get sold as if they were interchangeable, and they are not. Knowing the difference stops you overpaying for one or under-protecting with the other.
A vulnerability scan is broad, automated, frequent and relatively cheap. It is excellent at catching known issues across your whole site on a regular cycle, and it is the right tool for ongoing hygiene. A penetration test is deep, manual, periodic and more expensive. An engineer thinks like an attacker, chains flaws together, and finds the business-logic and access-control problems no scanner can see. You want both: scanning for continuous coverage of the known, and testing for periodic depth on the unknown. Buying only scanning and calling it a pentest is a common and costly mistake.
Want this tested on your own systems?
Free 20-minute scoping call, a fixed price with no hourly surprises, and a free retest once you fix what we find.
Authenticated versus unauthenticated scanning
Whether the scan logs in makes a large difference to what it finds, and it is worth being deliberate about.
Unauthenticated scans
These see your site as an anonymous visitor does. They are quick to set up and good for catching exposed files, outdated public-facing components and configuration mistakes. But they are blind to everything behind a login, which on most sites is where the sensitive functionality lives.
Authenticated scans
With valid credentials, the scan reaches the account area, the admin functions and the authenticated APIs. This is where broken access control, insecure account features and post-login injection tend to hide, so for any site with a login, authenticated scanning is where the real coverage comes from.
Scanning and compliance
Regular scanning is not just good hygiene; some frameworks require it on a fixed cadence, and a scanning programme is the cleanest way to evidence that.
PCI DSS scanning requirements
PCI DSS requirement 11.3 expects regular internal and external vulnerability scans, typically quarterly and after significant changes, with external scans by an approved vendor. Our recurring scanning and reporting are built to slot into that cadence and produce the evidence an assessor asks for.
ISO 27001 and GDPR
ISO 27001 Annex A.12.6 covers technical vulnerability management, which a documented scanning programme directly supports. For GDPR, being able to show you actively look for and fix weaknesses is part of demonstrating appropriate technical measures for protecting personal data.
What you get
The deliverable is a report your team can work from and hand to an auditor, not a raw tool dump.
What our scans turn up most often
After running these across a lot of sites, the findings cluster into a predictable set. None are exotic, and that is exactly the point: the routine problems are the ones that get sites breached, and a regular scan keeps them from piling up.
Software that quietly went out of date
The most common serious finding is a plugin, theme or library that was current at install and has since picked up a known vulnerability. On a busy site with several contributors, things fall behind without anyone deciding to let them. A scan makes the gap visible and puts a name and a fix against it.
Files that should never have been public
Database dumps, configuration files with credentials in them, old copies of pages left over from a migration, and log files sitting in a web-accessible folder. Attackers look for these first because they are easy wins, and a scan finds them the same way, just sooner.
Weak transport and missing headers
Outdated TLS settings, weak ciphers, and missing security headers such as content security policy or strict transport security. Individually minor, collectively they widen the surface for attacks like session hijacking and clickjacking, and they are quick to fix once flagged.
How to read the report
We rank findings so you spend your time where it counts. A critical or high finding with a known exploit gets fixed this week; a low-severity informational note can wait for the next maintenance window. Because we have already stripped the noise, the ranking reflects real risk to your site rather than a scanner’s blanket scoring, and your developers are not left guessing which of two hundred lines actually matters.
Pricing
Website vulnerability scanning is billed as a monthly plan, priced by how often you scan, how many sites are in scope, and whether the scans are authenticated. Here is the shape of the plans.
| Plan | What’s covered | Cadence | Price |
|---|---|---|---|
| Essential | One site: monthly unauthenticated scan, engineer-verified report, prioritised fixes | Monthly | from €120/month |
| Business | Up to three sites: authenticated scanning, more frequent scans, trend reporting, re-scan on demand | Weekly or monthly | from €180/month |
| Managed | Business-critical site: authenticated scanning plus manual review of high-risk findings and 24/7 escalation | Weekly | from €250/month |
| Compliance scan | Scheduled scanning and reporting aligned to PCI DSS 11.3 with the evidence an assessor needs | Quarterly + changes | from €180/month |
| Custom / large estate | Many sites or a full platform under one scanning programme, scoped to you | on scoping | custom |
Every plan is fixed-price, quoted after a free 20-minute scoping call, and a re-scan to confirm your fixes is always included. Get a fixed quote
FAQ
How much does website vulnerability scanning cost?
Is a scan the same as a penetration test?
Will the report be full of false positives?
Do you scan behind the login?
How often should I scan my website?
Does this meet PCI DSS scanning requirements?
Will scanning disrupt my live site?
Do you keep the results confidential?
Related services
Businesses across Europe that want continuous, verified visibility of the known weaknesses on their website, whether to stay ahead of attackers, satisfy a PCI DSS or ISO 27001 requirement, or simply stop finding out about outdated software the hard way.
Security you can prove
The same standard on every engagement, big or small.
Evidence, not opinions
Every finding ships with a reproduction and proof of concept — no vague "maybe vulnerable".
Humans over scanners
Certified engineers find the logic flaws and chained attacks automated tools walk straight past.
Fixed price, free retest
You know the cost up front, and verifying the fix is part of the deal — not a second invoice.
Ready to lock this down?
Free scoping call, fixed price, free retest. Tell us what you're running and we'll take it from there — usually within one business day.
Tell us what you're running
Scoping is free. We reply within one business day, and under 30 minutes for active incidents.