Website security checks, with clear limits
A focused first check of the public-facing security basics of a host you control. Evidence and practical fixes—not a replacement for comprehensive vulnerability scanning or penetration testing.
What we check today
We check the host you enter, not every host or page on its domain. Root response headers are a snapshot; different routes, proxies and logged-in responses can behave differently.
Browser security headers
Missing HSTS and Content-Security-Policy headers. Extended checks also look for missing Referrer-Policy and X-Content-Type-Options headers.
Limit: Checks identify a missing policy, not its quality. Extended checks depend on the enabled assessment profile.
Framing protection
Flags an absent framing header when no Content-Security-Policy is observed.
Limit: An existing policy is not fully analysed for frame-ancestors protection.
Observed cookie flags
Looks for Secure and HttpOnly flags on cookies returned by the checked response.
Limit: Does not inspect every cookie or authenticated session. The appropriate flags depend on the cookie’s purpose.
Technology evidence and CVE candidates
Reviews exposed technology headers for potential known-vulnerability matches.
Limit: CVE candidates are not confirmed vulnerabilities. Banners and version hints can be inaccurate; we do not exploit the host.
Evidence and practical fixes
Review findings, severity and remediation guidance, export a PDF and use included rescans.
Limit: Evidence depth varies by finding. Advisory severity alone does not establish whether the host is exploitable.
How an authorised check works
- Choose your host. Only test systems you own or have permission to assess.
- Verify control. Add the DNS TXT ownership record when requested. Authorisation is checked before relevant scan work.
- Review the supported checks. The assessment uses a restricted, non-invasive profile; it does not enable an unrestricted catalogue of tests.
- Choose whether to unlock the report. The £4.99 offer is per host, with two included rescans—not permission to scan other targets.
What a finding does—and does not—mean
A hardening finding describes an observed configuration gap. A CVE candidate suggests a possible known-vulnerability match from limited evidence, not confirmed exploitability. Review the actual software build and vendor advice before treating a candidate as a confirmed vulnerability.
Zero findings does not mean your website is secure. It only means the supported, completed checks did not identify findings. A failed, skipped or unavailable check is not a pass.
Coverage and price comparison
Our low one-off entry price buys a focused host report. Broader commercial products cover different needs; prices below are not a like-for-like comparison or an effectiveness benchmark.
Intruder
Free plan available; Cloud example ≈£182/month
Observed GBP calculator example: £2,182 billed annually for 5 infrastructure targets and 0 web-app licences, excluding VAT. Not a single-host report price or a minimum-price claim. Paid plans depend on configuration; monthly billing differs.
Published scope
Broader external infrastructure checks. Application licences add web-app and API testing, including authenticated options.
How our scope differs
Some public-facing hardening objectives overlap, but our supported checks are substantially narrower.
Sources reviewed
Invicti
Web + API: contact vendor for a quote
Separately, its Agentic Pentest offer advertises a $500 maximum per test in USD. That is a different assessment, not the price of the Web + API subscription or an equivalent host report.
Published scope
Web-application and API testing, including injection checks and proof-based validation where possible.
How our scope differs
Our header observations and CVE candidates are not equivalent to exploit validation or comprehensive application testing.
Sources reviewed
Burp Suite DAST
Contact vendor for subscription pricing
Subscriptions are tailored to scanning needs. Its pay-as-you-scan option has an annual licence plus usage billed by scanning time; it is not a one-off report purchase.
Published scope
Scoped application crawling and testing, application logins, API scanning and scheduled scans.
How our scope differs
We do not currently provide its authenticated crawling, API workflow or broad application testing.
Sources reviewed
CVE Scanner is independent and not affiliated with these products. Vendor capabilities are based on their published documentation; features, licences and prices may change. Check the linked pricing for your configuration. No currency conversions or percentage savings are claimed.
Not included in the current service
Whole-domain discovery, full-site crawling, authenticated application testing, API schema assessment, broad network or internal-device scanning, cloud-account audits and source-code or dependency analysis are not included.
We do not provide a comprehensive injection test, exploit validation, manual penetration test or compliance certification. For deeper assurance, choose an appropriate broader scanner and professional review.
Planned, not promised for today
These improvements are not available to purchase. There are no delivery dates; the current report price does not include future features.
Stronger evidence and check transparency
Clearer applicability, policy evaluation and visibility of completed, skipped or failed checks.
Additional safe external checks
Selected transport-security and configuration checks, with explicit scope and tested evidence.
Optional background host discovery
Keep single-host checks independent. Find additional hosts only when requested, without automatically scanning or charging for them.
Optional repeat monitoring
A separately selected service for recurring checks and meaningful change alerts.
