Skip to main content

Website security scanner for small business

Know what's broken on your website. Before they do.

Vantyris checks your business website the way an attacker would, then writes the report in plain English: a one-page summary, a Fix Roadmap grouped by who does each fix, and the exact snippet to paste for each one.

A first answer in seconds. A verified report from $10€10£10A$15¥1,500AED 40. No contracts.

67Security score,
grade C
2Fixes for
today

Each panel mirrors a screen in your workspace, shown with our demo clinic. After your first scan, it's your sites and your findings.

Checked against

  • OWASP
  • NCSC Cyber Essentials
  • CISA KEV
  • GDPR
  • ePrivacy
  • Google Safe Browsing
  • Spamhaus
  • Certificate Transparency

The reality

Small businesses don't have a security team. Attackers know it.

You have no security person.

Maybe you run a dental practice or an accountancy firm. Someone built the website four years ago, and you have no idea what's running on it now.

Every other tool talks past you.

CVE this, CVSS that. SAST, DAST, EASM. You don't care what it's called. You want to know if the door is open.

Or it costs $1,750 a month.

That's the published price of UpGuard's Standard plan, billed annually (upguard.com/pricing, checked 2 October 2026). Other tools want a quote call and a twelve-month contract before you see anything. For a website check, that's too much.

The method

From a domain name to a fix list in about 90 seconds.

Read the full methodology

What you get

A workspace around the report.

The report is what you forward. The workspace is where you track what happens next: mark fixes, schedule re-scans, share a link, show an insurer your grade. It's built so a business owner can run a security baseline without hiring a security person.

Fix Roadmap

A Fix Roadmap that turns the report into a worklist

Vantyris sorts findings into Today, This Week and Later, then groups each bucket by owner. Your DNS admin gets one list, your developer another, and you get the short 'fix it in your hosting panel today' list.

Learn more

Share and trust page

Three ways to share a finished scan

A time-limited share link with an optional watermark, in full, executive or evidence-redacted mode. A public trust page on a slug you choose, showing the nine-category grid and the controls in place: the link you give an insurer or a customer's procurement team.

Learn more

Portfolio

A portfolio view for more than one site

Running an agency, several brands or a handful of clinics? The portfolio dashboard ranks every target worst first, shows the average score across the workspace, and re-scans the lot in one click within your credit balance.

Learn more

Monitoring

Continuous monitoring with alerts only when it matters

Enrol a target in daily, weekly, biweekly or monthly re-scans. We email you about three things only: a new high or critical finding, a security score drop of 10 points or more, or a TLS certificate within 14 days of expiry.

Learn more

The artefact

Forwardable to your developer or your accountant.

Every finding says what it means in plain English and how to fix it. The raw technical evidence sits one tap below.

Finding 02 / 11 · ExposureHigh severity

WordPress REST API exposes public user slugs

/wp-json/wp/v2/users returns the public WordPress user slugs for any account that has authored content. These slugs are commonly fed into automated tools before credential-stuffing or password-spray attempts against /wp-login.php.

Business impact: easier brute-force and credential stuffing.


Exact fix: drop into your theme's functions.php

add_filter('rest_endpoints', function ($endpoints) {
  if (isset($endpoints['/wp/v2/users'])) {
    unset($endpoints['/wp/v2/users']);
  }
  return $endpoints;
});

Time-to-fix: ~30 min · Owner: web developer · Confidence: high

What we check

Nine questions about your website, in plain English.

The report scores your site across nine axes (TLS, web hygiene, DNS, email, exposure, technology, reputation, supply chain, privacy) and explains each one the way you'd brief your web host. The acronym in small grey type at the end is for the engineer if you have one.

Is your padlock real, and is it telling the browser to stay locked?

highYour server still allows TLS 1.0 or TLS 1.1

How we check it

The padlock in the address bar is supposed to mean the connection is private. We check whether yours actually is, whether the certificate is healthy and won't expire next week, and whether the HSTS header tells browsers to stay on HTTPS for the next two years. A short HSTS on its own is a hardening gap. It doesn't mean a downgrade is in progress.

Is your visitor's browser being told what to do?

mediumNo Content-Security-Policy

How we check it

Modern browsers will defend a website against common attacks, but only if the site asks them to. We read your response headers (Content-Security-Policy, X-Frame-Options, Permissions-Policy, Referrer-Policy and cookie flags) and look for the gotchas: unsafe-eval in the CSP, wildcard camera permissions, cookies without the Secure flag. If none of these are set on your site, it's usually because nobody knew to turn them on.

Can someone hijack your domain name?

mediumNo registrar transfer lock

How we check it

Beyond the records that protect your email, your domain has a few other settings that decide who is allowed to issue certificates for it, whether old forgotten subdomains are still reachable, whether DNSSEC validates, and whether your transfer lock is on. We check those. The transfer lock is easy to overlook, and it's what stops your domain being moved to another registrar without your say-so.

Can a stranger send email pretending to be you?

highNo DMARC policy

How we check it

If your domain doesn't have the right DNS records, anyone can send an invoice from "accounts@yourbusiness.co.uk" and it will land in your customer's inbox looking real. We check whether your domain blocks this: SPF (and whether you're over the 10-lookup RFC limit), DKIM signing, DMARC policy and subdomain policy, BIMI logo + VMC, MTA-STS, TLS-RPT. If you fix one thing on this page, fix this.

Anything on your server that shouldn't be reachable from the internet?

critical.env file is publicly accessible

How we check it

A database, an admin login page, a forgotten /readme.html, an .env file, a /backup.zip in the docroot, a WordPress REST API handing out user slugs, an XML-RPC endpoint waiting for a brute-force amplifier. We probe about 70 known paths and report each hit with its HTTP status, its severity, why it matters and the exact fix to paste. If you read one section of the report closely, make it this one.

What does your stack reveal about itself?

mediumOutdated jQuery loaded

How we check it

Every site tells attackers something about what's running on it. Sometimes that's just a CMS name. Sometimes it's the exact WordPress version, the outdated jQuery 1.12.4 still being loaded, or a Server header bragging about Apache 2.2.15. We fingerprint the public surface so you know what you're advertising, and flag the version banners worth removing.

Is your domain flagged by anyone's safety list?

criticalDomain on Google Safe Browsing list

How we check it

Even if your site is clean today, an old subdomain that got compromised once can sit on Google Safe Browsing, Spamhaus, or SURBL for months. We check the major reputation lists. When the only hit is a shared CDN edge (Cloudflare, Fastly, Akamai), we mark it Acknowledged rather than urgent. You can't act on a listing you share with every other site on that address, and you probably don't need to.

Could a third-party script betray your visitors?

mediumExternal scripts loaded without Subresource Integrity

How we check it

Your site probably loads scripts from other companies: analytics, ads, fonts, A/B testing tools, payment SDKs. Each one is a supply-chain risk. If their CDN is compromised, your site runs whatever they ship next. We list every outside script, check each one for a Subresource Integrity hash, and put the riskiest at the top.

Does your site meet the baseline privacy expectations?

highTracking scripts load without a consent banner

How we check it

Trackers that fire before consent. A cookie banner with no Reject button on the first layer, the kind of thing EDPB enforcement notices cite. Google Analytics without Consent Mode v2 defaulting to denied. No privacy notice at all. Under UK-GDPR and PECR these are real liabilities, and they're what a regulator or a sharp-eyed visitor spots first.

The rates

Pay only for what you scan.

No contracts. No quote call. One credit = one verified scan. Credits valid 60 days.

No subscriptions at all. Nothing renews.

Built to be checked

Proof you can hand to an insurer.

A public trust page shows your current grade and the controls in place. Send the link to a customer's procurement team or your insurer, and they can check it themselves.

Cyber Essentials A1-A5

A Cyber Essentials block maps each finding to the five NCSC controls.

CISA KEV priority

Severity is weighed against the Known Exploited Vulnerabilities list.

Append-only audit trail

Every status change is kept, so you can show an auditor what changed when.

EU data residency

Scans and reports are stored on servers in the EU, under GDPR.

Delivery

How you receive your report.

Common questions

8 questions to ask before you scan.

What does Vantyris check on my website?
Nine axes of cyber hygiene: TLS / HTTPS, web hygiene headers, DNS and domain plumbing, email authentication (SPF / DKIM / DMARC / MTA-STS / BIMI), exposure (sensitive files, WordPress hardening, subdomain enumeration), technology fingerprint, reputation lists, supply chain (third-party scripts + SRI), and privacy posture (consent, trackers, EDPB reject-parity, Consent Mode v2). Each axis is scored independently with its own grade.
Is a Vantyris scan legal? Can I scan my own website?
Yes. You can scan domains you own or have written authorisation to scan. Every Vantyris scan requires verified ownership (a DNS TXT record, a file on the server, or an HTML meta tag) before any active probe runs. The gate is there because computer-misuse laws in most countries, such as the US Computer Fraud and Abuse Act and the UK Computer Misuse Act, treat unauthorised scanning as an offence.
How much does it cost?
The starter pack of 5 verified scans is $10, or €10 in the EEA, £10 in the UK, A$15 in Australia, ¥1,500 in Japan or AED 40 in the UAE, and credits last 60 days. There's no subscription and no annual contract. Create a free account, add a domain, and run the free passive teaser as often as you like for a partial grade in seconds.
What does the report actually contain?
A cover page, a one-page executive summary for non-technical readers, the top urgent actions, a score for each of the nine categories, and an attack surface map with a severity and an exact fix for every exposed file. Then the Fix Roadmap (Today, This Week, Later, Acknowledged), every finding with a one-line business impact and a fix to paste, and an appendix on methodology and the audit trail. It comes as three PDFs: the full report, a single-issue work order and a compliance pack.
Why is HSTS not flagged as a High urgent item in your report?
HSTS controls how long browsers remember to stay on HTTPS for your site. Provided HTTPS is working, there's no mixed content, and the certificate is valid, a short HSTS max-age is a hardening gap, not an emergency on its own. We treat a very short HSTS (under one day) as Medium severity, anything else as Low. It's scored under TLS rather than Web Hygiene so the grades agree with each other.
Will a Vantyris scan slow my website down?
No. The teaser is a single page-load. The verified scan reads what's already publicly visible about your domain (DNS records, response headers, CT-log entries) and checks a short list of common sensitive paths, with time-limited, spaced-out requests. We don't fuzz, brute-force or run exploit frameworks.
How is Vantyris different from SSL Labs or Security Headers?
Those are excellent free single-purpose tools. They answer one question well. Vantyris answers nine in one report, plus adds an attack-surface map, a Fix Roadmap grouped by who does the work, a one-page executive summary, Cyber Essentials A1-A5 alignment, CISA KEV priority scoring, share links, a public trust page, a portfolio dashboard, continuous monitoring, and a workspace API. Free tools answer 'is my config right?'. Vantyris answers 'how do I run a security baseline as a business owner, and how do I prove it?'
What's the Acknowledged bucket?
A bucket in the Fix Roadmap for findings that need a check rather than a fix. Example: your resolved IP is on a shared Cloudflare edge that Spamhaus has listed. The listing is real, but it's shared-tenancy noise from another tenant on that IP, not something you can or should fix. Acknowledged sits below Today / This Week / Later so it doesn't make the report feel like an emergency over informational items.
All 45 answers on the FAQ page

Get a first check in seconds.

Free account, free passive teaser, no card. A verified scan from $10€10£10A$15¥1,500AED 40. No contracts.