Know what you are checking

Website security checks, with clear limits

A focused first check of the public-facing security basics of a host you control. Evidence and practical fixes—not a replacement for comprehensive vulnerability scanning or penetration testing.

Available scope

What we check today

We check the host you enter, not every host or page on its domain. Root response headers are a snapshot; different routes, proxies and logged-in responses can behave differently.

Limited

Browser security headers

Missing HSTS and Content-Security-Policy headers. Extended checks also look for missing Referrer-Policy and X-Content-Type-Options headers.

Limit: Checks identify a missing policy, not its quality. Extended checks depend on the enabled assessment profile.

Limited

Framing protection

Flags an absent framing header when no Content-Security-Policy is observed.

Limit: An existing policy is not fully analysed for frame-ancestors protection.

Limited

Observed cookie flags

Looks for Secure and HttpOnly flags on cookies returned by the checked response.

Limit: Does not inspect every cookie or authenticated session. The appropriate flags depend on the cookie’s purpose.

Limited

Technology evidence and CVE candidates

Reviews exposed technology headers for potential known-vulnerability matches.

Limit: CVE candidates are not confirmed vulnerabilities. Banners and version hints can be inaccurate; we do not exploit the host.

Report

Evidence and practical fixes

Review findings, severity and remediation guidance, export a PDF and use included rescans.

Limit: Evidence depth varies by finding. Advisory severity alone does not establish whether the host is exploitable.

How an authorised check works

  1. Choose your host. Only test systems you own or have permission to assess.
  2. Verify control. Add the DNS TXT ownership record when requested. Authorisation is checked before relevant scan work.
  3. Review the supported checks. The assessment uses a restricted, non-invasive profile; it does not enable an unrestricted catalogue of tests.
  4. Choose whether to unlock the report. The £4.99 offer is per host, with two included rescans—not permission to scan other targets.

What a finding does—and does not—mean

A hardening finding describes an observed configuration gap. A CVE candidate suggests a possible known-vulnerability match from limited evidence, not confirmed exploitability. Review the actual software build and vendor advice before treating a candidate as a confirmed vulnerability.

Zero findings does not mean your website is secure. It only means the supported, completed checks did not identify findings. A failed, skipped or unavailable check is not a pass.

Choose the right depth

Coverage and price comparison

Our low one-off entry price buys a focused host report. Broader commercial products cover different needs; prices below are not a like-for-like comparison or an effectiveness benchmark.

Intruder

Free plan available; Cloud example ≈£182/month

Observed GBP calculator example: £2,182 billed annually for 5 infrastructure targets and 0 web-app licences, excluding VAT. Not a single-host report price or a minimum-price claim. Paid plans depend on configuration; monthly billing differs.

Published scope

Broader external infrastructure checks. Application licences add web-app and API testing, including authenticated options.

How our scope differs

Some public-facing hardening objectives overlap, but our supported checks are substantially narrower.

Sources reviewed

Invicti

Web + API: contact vendor for a quote

Separately, its Agentic Pentest offer advertises a $500 maximum per test in USD. That is a different assessment, not the price of the Web + API subscription or an equivalent host report.

Published scope

Web-application and API testing, including injection checks and proof-based validation where possible.

How our scope differs

Our header observations and CVE candidates are not equivalent to exploit validation or comprehensive application testing.

Sources reviewed

Burp Suite DAST

Contact vendor for subscription pricing

Subscriptions are tailored to scanning needs. Its pay-as-you-scan option has an annual licence plus usage billed by scanning time; it is not a one-off report purchase.

Published scope

Scoped application crawling and testing, application logins, API scanning and scheduled scans.

How our scope differs

We do not currently provide its authenticated crawling, API workflow or broad application testing.

Sources reviewed

CVE Scanner is independent and not affiliated with these products. Vendor capabilities are based on their published documentation; features, licences and prices may change. Check the linked pricing for your configuration. No currency conversions or percentage savings are claimed.

Not included in the current service

Whole-domain discovery, full-site crawling, authenticated application testing, API schema assessment, broad network or internal-device scanning, cloud-account audits and source-code or dependency analysis are not included.

We do not provide a comprehensive injection test, exploit validation, manual penetration test or compliance certification. For deeper assurance, choose an appropriate broader scanner and professional review.

Product direction

Planned, not promised for today

These improvements are not available to purchase. There are no delivery dates; the current report price does not include future features.

Planned

Stronger evidence and check transparency

Clearer applicability, policy evaluation and visibility of completed, skipped or failed checks.

Planned

Additional safe external checks

Selected transport-security and configuration checks, with explicit scope and tested evidence.

Planned

Optional background host discovery

Keep single-host checks independent. Find additional hosts only when requested, without automatically scanning or charging for them.

Planned

Optional repeat monitoring

A separately selected service for recurring checks and meaningful change alerts.