Port and service scan
We use Nmap to find open ports on your public IP and identify service versions. Admin panels, databases or RDP exposed to the internet for no good reason are flagged.
Start here
Free Audits 5Urgent help
Emergency 4Ongoing support
Managed IT 5Projects
Servers & Hosting 6 Network & Virtualization 9 DevOps 5 Security & Recovery 5 Hardware & Licensing 2Find out where your servers, security, backups and performance stand, at no cost.
Server down, network out, site hacked or data lost? Call us now.
Monthly network and server support with response times written into the contract.
Setup, configuration, management and migration of Linux and Windows servers, panels and mail.
Network design and cabling, MikroTik, VoIP, branch links, virtualization and private cloud.
Networking & communications
Virtualization & cloud
Containers, Kubernetes, automated delivery, infrastructure as code and observability.
Server hardening, firewalls, backup and DR, ransomware recovery and incident forensics.
Advice, supply and installation of servers and network gear, plus genuine enterprise licenses.
Start here
Urgent help
Ongoing support
Projects
Plenty of break-ins start with an outdated plugin or a port someone forgot to close. Our free website security test looks at your site and your server's public addresses from the outside, read-only. You get a short report that tells you what to fix first.
A free website security test is an external, read-only scan that looks for weak spots in your site and your server's public addresses before an attacker finds them. It is useful when a site has not been updated in years, when Google or antivirus software has flagged it as unsafe, or before a new site goes live. After confirming you own the domain, PikoSystem finds open ports and service versions with Nmap, matches web server, PHP, CMS and plugin versions against CVE data and WPScan, checks TLS settings and headers such as HSTS, and looks for exposed files like .env and signs of compromise. Nobody tries to break in and nothing is changed. You receive a findings report with severity levels and a recommended fix for each item, in priority order.
We use Nmap to find open ports on your public IP and identify service versions. Admin panels, databases or RDP exposed to the internet for no good reason are flagged.
We match the versions of your web server, PHP, CMS and plugins against CVE data. WordPress sites are checked with WPScan.
We look for old TLS versions, weak ciphers and missing headers such as HSTS and Content-Security-Policy.
We check for files that should never be public: .env files, .git folders, zip backups in the web root and phpinfo pages.
We inspect page source for injected scripts, suspicious redirects and spam links, and check your domain against Google Safe Browsing.
Online scanners such as VirusTotal or Sucuri SiteCheck only see the page a visitor would see. A backdoor hidden in a PHP file, or malicious code that fires only for mobile visitors or for Googlebot, usually slips past them. A clean result means nothing was found at that moment, from that angle.
Automated tools like Nuclei and OWASP ZAP produce false positives too. Distributions such as Ubuntu and AlmaLinux backport security fixes without changing the advertised Apache or OpenSSH version, so matching version numbers against CVE lists can flag a hole that is already patched. That is why tool output needs a human review before anyone acts on it.
Priority follows exposure more than the CVSS score alone. Management ports open to the whole internet, such as 3306, 3389 or Winbox on 8291, come first, and restricting them to known IPs or a VPN is usually a same-day job.
If a .env file or .git folder was readable from outside, deleting it is not enough. Assume the database password, API keys and SMTP settings inside were already copied, and rotate all of them. After that come plugins and themes with public exploit code, then TLS settings and security headers.
The number of applications and subdomains, whether there is an API or a mobile app, how many user roles exist (customer, seller, admin) and whether testing happens logged in or anonymous all change the workload. So does the approach: black box with no inside knowledge, or grey and white box with documentation or source code.
The target environment (staging or production), the reporting baseline such as OWASP Top 10 or ASVS, and whether a retest after fixes is included should all be agreed before work starts.
Collect every domain and subdomain you own, your public server IPs, and whether the site sits behind a CDN or web application firewall. Forgotten subdomains like test or old are often where an outdated copy of the site is still running.
If the server is with a hosting company or data center, tell them when the scan will run. Some providers treat port scans as attacks and block the source IP. Pick a time when traffic is low.
You enter your domain and IP. Before scanning, we confirm you own them or have permission, using a DNS record or a verification file.
The scan runs from outside at a controlled rate so it does not noticeably slow your site.
An engineer reviews the tool output and drops false positives before anything goes into the report.
We send the report. Nothing is fixed at this stage. If you want help with the fixes, we send a separate proposal.
The scan is external and non-destructive. We do not try to break in, guess passwords or exploit anything, and we have no access inside your server. For a deeper look, we recommend a penetration test or server hardening.
A security scan finds and lists known weaknesses. In a website penetration test, an engineer with your written permission tries to actually get in through those weaknesses and documents the path. Penetration testing is a paid service with an agreed scope.
The scan is rate-limited and sends no destructive requests. If your site sits behind a firewall or CDN, our IP may get blocked, and we will sort that out with you.
We tell you straight away so you can lock down access. Cleaning up a hacked site is a separate service with its own page.
Related searches
Free
Give us your site address or server IP. The check makes no changes to your systems and you get the results as a written report.