The limits are real, but so is the value. Public endpoints are easy for attackers, customers and auditors to inspect. If TLS, certificates, headers or redirects are weak on the outside, those issues are visible before anyone logs in.
NCSC guidance describes automated vulnerability scanning as a cost-effective way to find common issues inside a wider vulnerability management programme. That is the right model: use the scan to find visible issues quickly, then feed the result into ownership, remediation and deeper assessment.
For post-quantum migration, an external scan is a starting signal. It can show whether the endpoint has the TLS 1.3 foundation and whether active hybrid key exchange is visible. It cannot map every cryptographic dependency behind the service.