PikoSystem IT engineering services
Free Audits

Free website and server security scan

Plenty of break-ins start with an outdated plugin or a port someone forgot to close. Our free website security test looks at your site and your server's public addresses from the outside, read-only. You get a short report that tells you what to fix first.

Tools & technology security-scan
  • Nmap
  • WPScan
  • Nuclei
  • testssl.sh
  • OWASP ZAP
  • Google Safe Browsing
  • CVE
5work areas
4deliverables
4steps

What is Free Security Scan?

A free website security test is an external, read-only scan that looks for weak spots in your site and your server's public addresses before an attacker finds them. It is useful when a site has not been updated in years, when Google or antivirus software has flagged it as unsafe, or before a new site goes live. After confirming you own the domain, PikoSystem finds open ports and service versions with Nmap, matches web server, PHP, CMS and plugin versions against CVE data and WPScan, checks TLS settings and headers such as HSTS, and looks for exposed files like .env and signs of compromise. Nobody tries to break in and nothing is changed. You receive a findings report with severity levels and a recommended fix for each item, in priority order.

When you need Free Security Scan

  • Our website was built years ago and nobody has updated it since.
  • Google or our antivirus flagged the site as possibly unsafe.
  • I don't know which ports on our server are open to the internet.
  • We're about to launch a new site and want to rule out obvious security holes.

What Free Security Scan includes

01

Port and service scan

We use Nmap to find open ports on your public IP and identify service versions. Admin panels, databases or RDP exposed to the internet for no good reason are flagged.

02

Known vulnerabilities

We match the versions of your web server, PHP, CMS and plugins against CVE data. WordPress sites are checked with WPScan.

03

SSL and security headers

We look for old TLS versions, weak ciphers and missing headers such as HSTS and Content-Security-Policy.

04

Exposed files and paths

We check for files that should never be public: .env files, .git folders, zip backups in the web root and phpinfo pages.

05

Signs of compromise

We inspect page source for injected scripts, suspicious redirects and spam links, and check your domain against Google Safe Browsing.

What you get from Free Security Scan

  • A findings report with severity levels (critical, high, medium, low)
  • A list of ports and services reachable from the internet
  • A recommended fix for each finding, in priority order
  • Answers to your questions about the report

Free Security Scan: a practical guide

Online website malware scan or a proper security test?

Online scanners such as VirusTotal or Sucuri SiteCheck only see the page a visitor would see. A backdoor hidden in a PHP file, or malicious code that fires only for mobile visitors or for Googlebot, usually slips past them. A clean result means nothing was found at that moment, from that angle.

Automated tools like Nuclei and OWASP ZAP produce false positives too. Distributions such as Ubuntu and AlmaLinux backport security fixes without changing the advertised Apache or OpenSSH version, so matching version numbers against CVE lists can flag a hole that is already patched. That is why tool output needs a human review before anyone acts on it.

What to fix first after a website vulnerability scan

Priority follows exposure more than the CVSS score alone. Management ports open to the whole internet, such as 3306, 3389 or Winbox on 8291, come first, and restricting them to known IPs or a VPN is usually a same-day job.

If a .env file or .git folder was readable from outside, deleting it is not enough. Assume the database password, API keys and SMTP settings inside were already copied, and rotate all of them. After that come plugins and themes with public exploit code, then TLS settings and security headers.

What drives the scope of a website penetration test?

The number of applications and subdomains, whether there is an API or a mobile app, how many user roles exist (customer, seller, admin) and whether testing happens logged in or anonymous all change the workload. So does the approach: black box with no inside knowledge, or grey and white box with documentation or source code.

The target environment (staging or production), the reporting baseline such as OWASP Top 10 or ASVS, and whether a retest after fixes is included should all be agreed before work starts.

Before you request a server security check

Collect every domain and subdomain you own, your public server IPs, and whether the site sits behind a CDN or web application firewall. Forgotten subdomains like test or old are often where an outdated copy of the site is still running.

If the server is with a hosting company or data center, tell them when the scan will run. Some providers treat port scans as attacks and block the source IP. Pick a time when traffic is low.

How Free Security Scan works

  1. 01

    Request and ownership check

    You enter your domain and IP. Before scanning, we confirm you own them or have permission, using a DNS record or a verification file.

  2. 02

    External scan

    The scan runs from outside at a controlled rate so it does not noticeably slow your site.

  3. 03

    Manual review

    An engineer reviews the tool output and drops false positives before anything goes into the report.

  4. 04

    Report delivery

    We send the report. Nothing is fixed at this stage. If you want help with the fixes, we send a separate proposal.

Free Security Scan: frequently asked questions

What does the free scan not cover?

The scan is external and non-destructive. We do not try to break in, guess passwords or exploit anything, and we have no access inside your server. For a deeper look, we recommend a penetration test or server hardening.

How is this different from a website penetration test?

A security scan finds and lists known weaknesses. In a website penetration test, an engineer with your written permission tries to actually get in through those weaknesses and documents the path. Penetration testing is a paid service with an agreed scope.

Can the scan slow down or crash my site?

The scan is rate-limited and sends no destructive requests. If your site sits behind a firewall or CDN, our IP may get blocked, and we will sort that out with you.

What if the scan shows the site is already hacked?

We tell you straight away so you can lock down access. Cleaning up a hacked site is a separate service with its own page.

Related searches

  • free website security scan
  • website vulnerability scan
  • server security check
  • website penetration test
  • check if website is hacked
  • online website malware scan
  • website security test tool

Free

Request a free audit

Give us your site address or server IP. The check makes no changes to your systems and you get the results as a written report.

  1. 01We agree on access. Most checks only need read-only access.
  2. 02We run the check without changing anything on your systems.
  3. 03You receive a report with issues ranked and fixes suggested.

Your details are only used to answer this request.