Skip to main content

Vulnerabilities

Free vs paid website security scanners: what you actually get.

Published 2026-07-18 · Last updated 2026-07-18 · Vantyris editorial

Free checkers (SSL Labs, SecurityHeaders.com, MDN HTTP Observatory, Sucuri SiteCheck) are where most small-business owners start. Each is excellent at one slice (TLS grades, header sets, quick malware lookups). None of them gives you a dated audit trail, email authentication depth, subdomain discovery, workflow around findings, or a PDF you can hand to an insurer. Paid scanners (Intruder, Detectify, Vantyris verified scans, and others) charge for breadth and history, and for the operational wrapping around the findings. This comparison shows where the free tools stop, and how to pay for the rest without buying enterprise shelfware.

What this means for your business

How to fix

Use free checkers for quick triage on the dimension each one owns. When you need cross-domain coverage, monitoring, PDFs, or client deliverables, budget for a paid verified scan. Either way, record your sources and dates.

  1. Run the three free checks on your main domain. SSL Labs for TLS, SecurityHeaders.com for defensive headers, and a DMARC lookup tool for email authentication. Screenshot or export the results, and note the dates. Between them they cover transport and browser-side defences, but they skip subdomain sprawl and reputation.
  2. List what your stakeholder actually asks for. Insurer or franchise questionnaire? They want dated evidence and remediation notes, not a letter grade in isolation. Agency client reporting? They want white-label PDFs and trend lines. Match the tool to the deliverable, not the other way around.
  3. Trial a paid verified scan on the same domain. Run one verified Vantyris scan (or an equivalent SMB scanner) and diff the findings against your free-tool notes. Look for email/DNS modules, subdomain discovery, reputation checks, and workflow states (fixed / accepted / assigned).
  4. Decide between monitoring and an annual snapshot. For a stable brochure site, a quarterly verified scan plus free TLS checks may be enough. For a clinic with weekly plugin updates, or an agency managing twelve clients, weekly monitoring with alerts on material change is cheaper than incident response after a certificate expires unnoticed.
  5. Keep a single owner for findings. Free or paid, give one person the job of carrying findings to closure. Tools don't fail SMBs. Untracked spreadsheets do. A paid platform earns its keep when each finding's status and history sit in the same workspace as your exports.

Owner: Owner selects tools. IT implementer closes findings whichever path you pick. · Time: Free triage: 30 minutes. Paid comparison run: 1 hour including read-through.

Common gotchas

How to verify the fix

Re-run the same free tools after your fixes and confirm the grades moved. On paid platforms, open the trend chart or export a PDF and check the date stamp matches your compliance folder. Vantyris includes an attack-surface diff and score trend on verified targets, for before/after proof.

Cyber Essentials alignment

This finding informs the following Cyber Essentials control areas (the UK government's baseline scheme, a sound checklist in any country):

Vantyris is not a CE certifying body. The mapping above is informational.

Common follow-up questions

Is Vantyris replacing SSL Labs?

No. SSL Labs remains the deepest public TLS analyser. Vantyris includes TLS checks plus email, DNS, headers, reputation, subdomain discovery, and workflow in one SMB-oriented report. Use SSL Labs when you need cipher-level detail. Use Vantyris when you need the whole hygiene picture and a client-ready PDF.

What does the free Vantyris teaser include?

Passive teaser modules without verification, no card required. Verified scans, from $10 (or the local price in your region) for a pack of five, add the full module set, workspace history, PDF layouts, share links, trust pages, monitoring enrolment, and API access.

When should I skip free tools entirely?

When you're delivering client reports, need monitoring alerts, or must show dated audit trails to third parties. Free tools still help engineers spot-check one dimension fast.

Are paid scanners legal for any domain?

Only scan domains you own or have written permission to test. Vantyris requires DNS verification before active modules run. Unauthorised scanning can breach the UK Computer Misuse Act, whatever the tool costs.

References

Related explainers

Want Vantyris to check your domain for this and 196 other problems?

The teaser scan is free and needs no card. A verified scan starts at $10€10£10A$15¥1,500AED 40 and comes with the workspace: finding workflow, score trend, three PDF layouts, share links and monitoring.

Written by Vantyris