Vulnerabilities
Free vs paid website security scanners: what you actually get.
Published 2026-07-18 · Last updated 2026-07-18 · Vantyris editorial
Free checkers (SSL Labs, SecurityHeaders.com, MDN HTTP Observatory, Sucuri SiteCheck) are where most small-business owners start. Each is excellent at one slice (TLS grades, header sets, quick malware lookups). None of them gives you a dated audit trail, email authentication depth, subdomain discovery, workflow around findings, or a PDF you can hand to an insurer. Paid scanners (Intruder, Detectify, Vantyris verified scans, and others) charge for breadth and history, and for the operational wrapping around the findings. This comparison shows where the free tools stop, and how to pay for the rest without buying enterprise shelfware.
What this means for your business
- Free tools are point solutions. SSL Labs is the gold standard for certificate chains and cipher suites, but it won't tell you DMARC is still on
p=none. SecurityHeaders.com grades response headers. It won't map your CT-log subdomains or check Spamhaus listings. - Free scans are usually manual and stateless. You paste a URL, read the grade, close the tab. Nothing records a score trend or who marked a finding as accepted risk, and there's no evidence pack an accountant can attach to a PI renewal questionnaire.
- Paid SMB scanners fall into two buckets: continuous SaaS platforms with subscriptions (Intruder, Detectify) and pay-as-you-go hygiene scans (Vantyris, where five verified scans cost $10, or the local price in your region). The right choice depends on whether you need always-on scheduling baked into a contract, or occasional verified snapshots you file away.
- Neither free nor paid passive scanning replaces a penetration test. Both sit on the hygiene side of NCSC's scanning-versus-pentest line. Paid value is breadth + workflow + proof, not magic exploit discovery on every click.
How to fix
Use free checkers for quick triage on the dimension each one owns. When you need cross-domain coverage, monitoring, PDFs, or client deliverables, budget for a paid verified scan. Either way, record your sources and dates.
- Run the three free checks on your main domain. SSL Labs for TLS, SecurityHeaders.com for defensive headers, and a DMARC lookup tool for email authentication. Screenshot or export the results, and note the dates. Between them they cover transport and browser-side defences, but they skip subdomain sprawl and reputation.
- List what your stakeholder actually asks for. Insurer or franchise questionnaire? They want dated evidence and remediation notes, not a letter grade in isolation. Agency client reporting? They want white-label PDFs and trend lines. Match the tool to the deliverable, not the other way around.
- Trial a paid verified scan on the same domain. Run one verified Vantyris scan (or an equivalent SMB scanner) and diff the findings against your free-tool notes. Look for email/DNS modules, subdomain discovery, reputation checks, and workflow states (fixed / accepted / assigned).
- Decide between monitoring and an annual snapshot. For a stable brochure site, a quarterly verified scan plus free TLS checks may be enough. For a clinic with weekly plugin updates, or an agency managing twelve clients, weekly monitoring with alerts on material change is cheaper than incident response after a certificate expires unnoticed.
- Keep a single owner for findings. Free or paid, give one person the job of carrying findings to closure. Tools don't fail SMBs. Untracked spreadsheets do. A paid platform earns its keep when each finding's status and history sit in the same workspace as your exports.
Owner: Owner selects tools. IT implementer closes findings whichever path you pick. · Time: Free triage: 30 minutes. Paid comparison run: 1 hour including read-through.
Common gotchas
- Don't treat a green SSL Labs grade as 'secure website'. TLS can be perfect while DMARC is absent and RDP is open on your office IP.
- Don't pay for enterprise VMDR if you have one WordPress site and no GRC team to work through 400 findings a week.
- Free SiteCheck malware lookups lag behind real compromise. A clean result isn't proof. It's a point-in-time lookup.
- Subscriptions that auto-renew without showing your credit balance frustrate SMB owners. If your cadence is irregular, prefer packs with an explicit per-scan cost.
How to verify the fix
Re-run the same free tools after your fixes and confirm the grades moved. On paid platforms, open the trend chart or export a PDF and check the date stamp matches your compliance folder. Vantyris includes an attack-surface diff and score trend on verified targets, for before/after proof.
Cyber Essentials alignment
This finding informs the following Cyber Essentials control areas (the UK government's baseline scheme, a sound checklist in any country):
- A2. Secure configuration: devices and services hardened against the weaknesses they ship with by default.
- A3. Security update management: software stays in vendor support, and high or critical patches go on within 14 days.
Vantyris is not a CE certifying body. The mapping above is informational.
Common follow-up questions
Is Vantyris replacing SSL Labs?
No. SSL Labs remains the deepest public TLS analyser. Vantyris includes TLS checks plus email, DNS, headers, reputation, subdomain discovery, and workflow in one SMB-oriented report. Use SSL Labs when you need cipher-level detail. Use Vantyris when you need the whole hygiene picture and a client-ready PDF.
What does the free Vantyris teaser include?
Passive teaser modules without verification, no card required. Verified scans, from $10 (or the local price in your region) for a pack of five, add the full module set, workspace history, PDF layouts, share links, trust pages, monitoring enrolment, and API access.
When should I skip free tools entirely?
When you're delivering client reports, need monitoring alerts, or must show dated audit trails to third parties. Free tools still help engineers spot-check one dimension fast.
Are paid scanners legal for any domain?
Only scan domains you own or have written permission to test. Vantyris requires DNS verification before active modules run. Unauthorised scanning can breach the UK Computer Misuse Act, whatever the tool costs.
References
- Qualys SSL Labs Vendor
- SecurityHeaders.com Vendor
- NCSC: vulnerability scanning vs penetration testing NCSC
- Mozilla HTTP Observatory Vendor
Related explainers
- What a passive security scan can and cannot prove about your site.
- What is a WAF, and when is it worth paying for one?
- How Vantyris continuous monitoring works (without daily noise).
Want Vantyris to check your domain for this and 196 other problems?
The teaser scan is free and needs no card. A verified scan starts at $10€10£10A$15¥1,500AED 40 and comes with the workspace: finding workflow, score trend, three PDF layouts, share links and monitoring.
Written by Vantyris