Vulnerability Scan vs Penetration Test
Both find security weaknesses — but they work very differently. Here's what each one actually does, what each one finds, and how to use them together without wasting money.
Start with the free option. Run a vulnerability scan now — it's the sensible first step before you ever pay for a penetration test.
No signup · 7-section report · Plain language
Plain-language definitions
A vulnerability scan is an automated check. Software systematically probes your site for known flaw patterns — outdated components, common misconfigurations, missing headers, exposed files — and reports what it finds. It's fast, repeatable, and cheap (ours is free). Think of it as a thorough health checkup with a checklist.
A penetration test ("pentest") is a human-led attack simulation. A security professional actively tries to break into your site the way a real attacker would: chaining small weaknesses together, abusing business logic, testing logged-in areas. It's slower, creative, and expensive — and it finds things no checklist can. Think of it as hiring a professional burglar to test your locks.
Side-by-side comparison
Vulnerability scan
Who: automated software
Cost: free to low
Time: minutes
Depth: known issues & misconfigurations
Skills needed: none — paste a URL
Best for: continuous monitoring, catching the common stuff early
Penetration test
Who: human security expert
Cost: professional service fees
Time: days to weeks
Depth: chained attacks, logic flaws, authenticated areas
Skills needed: hire a specialist
Best for: high-stakes launches, compliance, deep assurance
What a free online vulnerability scanner covers well
Don't underestimate the automated scan — it covers the ground where most real-world compromises begin:
- Known vulnerability patterns like SQL injection and cross-site scripting, tested actively against your forms and URLs.
- Misconfigurations — missing security headers, weak TLS settings, exposed files and backups.
- Malware indicators and blocklist status on your public pages.
- Technology disclosures that help attackers, like version numbers in public files.
Because it's automated, you can run it monthly — or after every update — at no cost. That frequency is its superpower: most sites are compromised through flaws that a regular scan would have flagged.
What a scan can't find — honest limits
Automation has blind spots, and you should know them:
- Business-logic flaws. A scanner can't tell that your discount code system can be abused, or that one user can see another's invoices — those need human understanding of what your site is supposed to do.
- Chained attacks. Three "low severity" issues that combine into one serious exploit — a human tester connects those dots; a scanner lists them separately.
- Authenticated areas. External scanners test what the public sees. Member dashboards, admin panels and checkout flows need credentialed testing.
- Server-side backdoors. Malicious code hidden in server files that never appears on public pages needs an internal, file-level review.
A clean scan report is genuinely good news — it means the common, automated attacks will likely fail. It is not a certificate of invulnerability, and no honest provider will sell it as one.
The sensible workflow: scan often, pentest at milestones
For most small and medium sites, this is the right balance:
- Continuously: run the free vulnerability scan monthly and after every change — updates, new plugins, redesigns.
- Fix what it finds: updates, headers, exposed files, passwords. The scan report prioritizes these in plain language.
- Pentest at milestones: before launching anything that handles payments or sensitive data, after a major rebuild, or when a client or regulation requires it.
This way the expensive human expertise is spent on deep, creative testing — not on discovering the missing security headers a free scan would have caught.
How to use a scan report as the starting brief for a pentester
If you do hire a penetration tester, hand them your latest scan report first. It gives them a head start on your stack, your known issues, and what's already fixed — which means less billable time spent on discovery and more on the deep testing only a human can do. Every report from our scanner includes a shareable link and a branded PDF for exactly this purpose. Tell the tester what the scan couldn't cover (authenticated areas, business logic) so they focus there.
Run your free vulnerability scan now. Seven sections, plain language, no signup — the right first step whatever you decide next.
Frequently asked questions
Is it legal to scan a website for vulnerabilities?
Only scan websites you own or have written permission to test. Scanning someone else's site without permission can be illegal in many jurisdictions. Our scanner requires you to confirm authorization before every scan.
How often should I run a vulnerability scan?
Monthly at minimum for most small sites, plus after every significant change — updates, new plugins, redesigns, or new features. Automated scanning is cheap; the expensive part is an undiscovered flaw.
Can a free vulnerability scan replace a penetration test?
No. A free scan is excellent for catching known issues and misconfigurations continuously, but it can't replicate a human tester's creativity — chained attacks, business-logic flaws, and authenticated testing need a professional.
How much does a penetration test cost?
Costs vary widely depending on your site's size, complexity, and the depth of testing. Get quotes from two or three reputable providers and ask exactly what's in scope before you commit.
Do I need a penetration test for a small business website?
Not necessarily as a first step. Regular free scanning plus good hygiene (updates, headers, backups) covers the common risks. Consider a pentest before handling payments or sensitive data, or after a major rebuild.
Will a vulnerability scan damage my website?
A well-built scanner uses harmless, read-only test requests — ours never sends destructive payloads. That's one reason to only use scanners you trust, and only on sites you're authorized to test.