Scanner scope

Free Website Security Scanner: What External Scans Can and Cannot Find

A free external scan is the fastest way to see what a public website exposes to the internet. It is not a penetration test, internal audit or full PQC assessment. This guide explains what the scan can prove, what it cannot see and what to do next.

Updated: 19 June 2026|13 min read

What It Can Find

  • -TLS versions and visible protocol posture
  • -Certificate issuer, expiry and basic certificate hygiene
  • -Observed key exchange and active hybrid PQC indicators where visible
  • -Security headers such as HSTS, CSP and clickjacking protections
  • -Public redirect and HTTPS enforcement behaviour
  • -Visible CDN, hosting or platform signals
  • -Basic externally observable AI-resilience signals

What It Cannot Find

  • -Internal APIs, private mTLS paths, VPNs or service mesh configuration
  • -Source code vulnerabilities and business-logic flaws
  • -Authentication, authorisation and session-management defects that require login context
  • -Supplier cryptography, HSM configuration and key-management policy
  • -Encrypted databases, backups and stored-data crypto
  • -Code signing, document signing or firmware signing workflows
  • -Full compliance with GDPR, NIS2, DORA, Cyber Essentials or other frameworks

Why External Scans Are Still Useful

The limits are real, but so is the value. Public endpoints are easy for attackers, customers and auditors to inspect. If TLS, certificates, headers or redirects are weak on the outside, those issues are visible before anyone logs in.

NCSC guidance describes automated vulnerability scanning as a cost-effective way to find common issues inside a wider vulnerability management programme. That is the right model: use the scan to find visible issues quickly, then feed the result into ownership, remediation and deeper assessment.

For post-quantum migration, an external scan is a starting signal. It can show whether the endpoint has the TLS 1.3 foundation and whether active hybrid key exchange is visible. It cannot map every cryptographic dependency behind the service.

What to Do After the Scan

  1. 1. Fix visible public issues. Use the free result to correct TLS, certificate, redirect and security-header issues on the assessed hostname.
  2. 2. Scan all public endpoints. Repeat the scan across customer websites, APIs, admin portals, partner callbacks and non-standard HTTPS ports.
  3. 3. Build a cryptographic inventory. Record internal systems, suppliers, signing workflows, key stores, data lifetime, owners and migration status.
  4. 4. Add authenticated and manual testing. Use authenticated scanning, manual application security testing and penetration testing where business logic or access control matters.
  5. 5. Track evidence over time. Rescan after changes, store evidence, assign owners and use the findings to drive a migration backlog.

When You Need More Than a Free Scan

Move beyond a free external scan when the system handles regulated data, payment data, patient data, financial data, authentication, partner APIs, admin functions or long-lived confidential information.

At that point, you need authenticated testing, internal endpoint discovery, supplier questions, key-management review, signing-workflow review and a cryptographic inventory. OWASP's Web Security Testing Guide is a useful reference for the breadth of manual and application-level testing that automated public scans cannot replace.

Primary References

FAQ

Can a free website scanner prove my organisation is secure?

No. A free external scanner can check visible public signals for one endpoint. It cannot prove internal security, source code quality, supplier risk, compliance or full post-quantum readiness.

Why run a scan if it is limited?

External scans are fast, repeatable and useful for finding visible misconfigurations. NCSC guidance positions automated scanning as a cost-effective way to find common issues within a wider vulnerability management programme.

Does the scan test post-quantum cryptography?

It can identify externally visible readiness signals such as TLS posture and observed hybrid key exchange where available. It cannot inspect internal cryptography, signing systems or stored-data encryption.

What should I do after a clean scan?

Treat a clean scan as one evidence item. Continue with a full endpoint inventory, supplier review, internal cryptography discovery and periodic rescans.

Start With the Free External Scan

Use the free scan to capture visible evidence, then turn the result into remediation, inventory and periodic monitoring.

Free readiness account

Keep This Guide Connected to a Real Website Scan

A PQC guide is more useful when it is attached to current evidence. Create a free account, add a public domain now or later, and keep a repeatable baseline for TLS, security headers and visible post-quantum readiness.

No cardStart the free evidence path without a paid plan.
Saved scanKeep the public endpoint result after the browser session.
Rescan laterRerun after TLS, header or provider changes.

Prefer to scan first? Open the free quantum security scanner.

Create Your Free Account

Start with Google, Microsoft or a one-time email code. You can add a domain now if you want the scanner to run after signup, but it is not required.

No cardNo passwordFree saved scan
Add a domain to scan after signup (optional)

Leave this blank to create the account first and scan later.

or use email code

No card or password is needed. The free account can keep scan evidence for rescans and badge qualification when you add a public domain.