Vulnerabilities
Free vs paid website security scanners: what you actually get.
Published 2026-07-18 · Last updated 2026-07-18 · Vantyris editorial
Free checkers (SSL Labs, SecurityHeaders.com, MDN HTTP Observatory, Sucuri SiteCheck) are where most small-business owners start. They are excellent at one slice each: TLS grades, header sets, quick malware lookups. None of them gives you a dated audit trail, email authentication depth, subdomain discovery, workflow around findings, or a PDF you can hand to an insurer. Paid scanners (Intruder, Detectify, Vantyris verified scans, and others) trade money for breadth, history, and operational wrapping. This comparison maps what free tools actually deliver, where gaps show up in real SMB workflows, and how to spend without buying enterprise shelfware.
What this means for your business
- Free tools are point solutions. SSL Labs is the gold standard for certificate chains and cipher suites; it will not tell you DMARC is still on p=none. SecurityHeaders.com grades response headers; it will not map your CT-log subdomains or check Spamhaus listings.
- Free scans are usually manual and stateless. You paste a URL, read the grade, close the tab. There is no score trend, no 'who marked this accepted risk', no evidence pack an accountant can attach to a PI renewal questionnaire.
- Paid SMB scanners cluster into two buckets: continuous SaaS platforms with subscriptions (Intruder, Detectify) and pay-as-you-go hygiene scans (Vantyris from €10 per verified run). The right choice depends on whether you need always-on scheduling baked into a contract or occasional verified snapshots you file away.
- Neither free nor paid passive scanning replaces a penetration test. Both sit on the hygiene side of NCSC's scanning-versus-pentest line. Paid value is breadth + workflow + proof, not magic exploit discovery on every click.
How to fix
Use free checkers for quick triage on the dimension they own. When you need cross-domain coverage, monitoring, PDFs, or client deliverables, budget for a paid verified scan. Document sources and dates either way.
- Run the free trio on your primary domain. SSL Labs for TLS, SecurityHeaders.com for defensive headers, and a DMARC lookup tool for email auth. Screenshot or export results. Note dates. These three cover transport and browser-side defences but skip subdomain sprawl and reputation.
- List what your stakeholder actually asks for. Insurer or franchise questionnaire? They want dated evidence and remediation notes, not a letter grade in isolation. Agency client reporting? They want white-label PDFs and trend lines. Match the tool to the deliverable, not the other way around.
- Trial a paid verified scan on the same domain. Run one verified Vantyris scan (or equivalent SMB scanner) and diff the finding set against your free-tool notes. Look for email/DNS modules, subdomain discovery, reputation checks, and workflow states (fixed / accepted / assigned).
- Decide monitoring vs annual snapshot. Stable brochure site: quarterly verified scan plus free TLS checks may suffice. Clinic with weekly plugin updates or agency managing twelve clients: weekly monitoring with alerts on material change is cheaper than incident response after a certificate expires unnoticed.
- Keep a single owner for findings. Whether free or paid, assign one person to carry findings to closure. Tools do not fail SMBs; untracked spreadsheets do. Paid platforms earn their keep when status, history, and exports live in one workspace.
Owner: Owner selects tools; IT implementer closes findings whichever path you pick. · Time: Free triage: 30 minutes. Paid comparison run: 1 hour including read-through.
Common gotchas
- Do not treat a green SSL Labs grade as 'secure website'. TLS can be perfect while DMARC is absent and RDP is open on your office IP.
- Do not pay for enterprise VMDR if you have one WordPress site and no GRC team to consume 400 findings a week.
- Free SiteCheck malware lookups lag real compromise. A clean result is not proof; it is a point-in-time lookup.
- Subscriptions that autorenew without credit visibility frustrate SMB owners. Prefer packs with explicit per-scan cost if your cadence is irregular.
How to verify the fix
Re-run the same free tools after fixes and confirm grades moved. On paid platforms, open the trend chart or export PDF and verify the date stamp matches your compliance folder. Vantyris includes attack-surface diff and score trend on verified targets for before/after proof.
Cyber Essentials alignment
This finding informs the following UK NCSC Cyber Essentials control areas:
- A2. Secure configuration — devices and services hardened against the inherent default vulnerabilities.
- A3. Security update management — software supported, updated, and patched within 14 days for high-/critical-risk vulnerabilities.
Vantyris is not a CE certifying body. The mapping above is informational.
Common follow-up questions
Is Vantyris replacing SSL Labs?
No. SSL Labs remains the deepest public TLS analyser. Vantyris includes TLS checks plus email, DNS, headers, reputation, subdomain discovery, and workflow in one SMB-oriented report. Use SSL Labs when you need cipher-level detail; use Vantyris when you need the whole hygiene picture and a client-ready PDF.
What does the free Vantyris teaser include?
Passive teaser modules without verification, no card required. Verified scans from €10 unlock the full module set, workspace history, PDF layouts, share links, trust pages, monitoring enrolment, and API access.
When should I skip free tools entirely?
When you are delivering client reports, need monitoring alerts, or must show dated audit trails to third parties. Free tools still help engineers spot-check one dimension fast.
Are paid scanners legal for any domain?
Only scan domains you own or have written permission to test. Vantyris requires DNS verification before active modules run. Unauthorised scanning can violate the UK Computer Misuse Act regardless of tool price.
References
- Qualys SSL Labs Vendor
- SecurityHeaders.com Vendor
- NCSC: vulnerability scanning vs penetration testing NCSC
- Mozilla HTTP Observatory Vendor
Related explainers
- What a passive security scan can and cannot prove about your site.
- What is a WAF, and when is it worth paying for one?
- How Vantyris continuous monitoring works (without daily noise).
Want Vantyris to scan your domain for this and 80 other findings?
Free teaser scan, no card. Verified scan from €10 with the full workspace around it: workflow, score trend, three PDF layouts, share links, monitoring.
Vantyris editorial team · methodology v1.0.0