Website security scanners: what free scanners check and what they miss
Free website security scanners compared by what each checks: headers, TLS, DNS, exposed files, malware or active attacks, and what none can see.
LLaunchScaler·Published ·8 min read
The free website security scanners worth using are LaunchScaler, Mozilla's HTTP Observatory, Qualys SSL Labs, Internet.nl, Sucuri SiteCheck and ZAP, and each checks a different slice: headers, TLS, DNS and email records, exposed files, malware, or active attacks. None of them can see your login logic, your database permissions or your business rules, because a scanner outside your app only sees what your server sends back.
What each tool covers below was read on its own site in September 2026. Coverage changes, so confirm the current scope on the tool's site before you rely on a clean result.
What does each website security scanner check?
The main split is passive versus active. Passive scanners make ordinary requests and grade the responses, so they are safe to run on any site. Active scanners send attack payloads to find exploitable bugs, which is why they are only for apps you own. The table compares the six by what they read.
Scanner
Headers
TLS and certificate
DNS and email records
Exposed files
Malware and blocklists
Active attacks
Needs
1. LaunchScaler free scan
Yes
Yes
SPF, DKIM, DMARC, CAA, DNSSEC
.env, , source maps, dumps
Questions, answered
What people ask about this
01
What is the best free website security scanner?
It depends on what you need checked. LaunchScaler's free scan covers headers, TLS, email DNS records and exposed files in one pass with no account; Mozilla's HTTP Observatory scores headers; Qualys SSL Labs grades TLS; Sucuri SiteCheck looks for malware and blocklisting; ZAP runs active attacks against apps you own.
Start with a passive scanner that covers the most ground from one URL, then add a specialist for the area it flags. The list is ranked for a founder who wants the widest check of a live site in one pass, with no account and no setup, and then moves to the single-purpose tools.
1. LaunchScaler: headers, TLS, DNS and exposed files in one free scan
LaunchScaler leads this list because it is the only one of the six that covers response headers, TLS, email DNS records and exposed files together in one pass, from a URL, with no account. Its free scan runs 29 security checks, and all 29 are included in the free run.
What those 29 read: HSTS and preload eligibility, the Content-Security-Policy and any 'unsafe-inline' or 'unsafe-eval', clickjacking protection, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, session cookie flags, wildcard CORS, Subresource Integrity on third-party scripts, the HTTP to HTTPS redirect, TLS versions and the certificate chain, version-leaking server headers, SPF, DKIM, DMARC, CAA and DNSSEC, security.txt, exposed /.env and /.git, published source maps, database dumps, open directory listings, reachable admin or debug endpoints, dangling subdomain records and passive mixed content. The security checks run beside the scan's other categories: 156 checks across search, AI visibility, security, compliance, speed and visual, and whether the site works.
The free scan gives a verdict per check. The full audit, $19 once for the domain, opens every check to its evidence and exact fix. Like every tool here except ZAP, it is passive: it reads what your site serves and does not attack it.
2. Mozilla HTTP Observatory: the scored header grade
The HTTP Observatory, run by MDN, grades a site's HTTP response headers from a baseline of 100, with penalties such as 25 for a missing CSP and 20 for missing HSTS, and bonuses once the score reaches 90. It is free, scans the entry URL and follows its redirects, and allows one new scan per site every 60 seconds.
It checks headers only. Its FAQ says the previous Observatory's TLS and certificate tabs are gone, with no plans to bring them back, and points to SSL Labs for TLS. The old Observatory, including the TLS and SSH Observatory, was retired in October 2024. The security headers checklist lists every header it scores and the value to send.
3. Qualys SSL Labs: the TLS configuration in depth
SSL Labs' Server Test "performs a deep analysis of the configuration of any SSL web server on the public Internet," and it is free. Use it when you need the detail behind a TLS problem, such as which protocol versions the server accepts or whether the certificate chain is complete.
Results can appear on its public boards unless you tick "Do not show the results on the boards" before the test. It does not look at page content or DNS mail records.
4. Internet.nl: web and email standards
Internet.nl, an initiative of the internet community and the Dutch government, tests a website for IPv6, DNSSEC, HTTPS, security headers and security.txt, and route authorisation (RPKI), and a mail domain for DMARC, DKIM, SPF, STARTTLS and DANE. It publishes no price on its site. It goes deeper on the email side than the other tools here, adding STARTTLS and DANE, which makes it a useful second opinion after you set up the records in the SPF, DKIM and DMARC guide.
5. Sucuri SiteCheck: malware and blocklisting
SiteCheck is Sucuri's free scanner for "known malware, viruses, blacklisting status, website errors, out-of-date software, and malicious code." It is the one to run when you suspect a compromise, for example spam links you did not add or a browser warning on your domain.
Sucuri states its limits plainly: remote scanners have limited access, results are not guaranteed, and it "will not detect anything on the server-side," such as backdoors hidden in your files.
6. ZAP: active scanning for apps you own
ZAP, now branded ZAP by Checkmarx, is a free, open-source web app scanner. Unlike the others, it can run an active scan, which "attempts to find potential vulnerabilities by using known attacks against the selected targets." Its docs are explicit that active scanning is an attack and that you should not use it on web applications you do not own.
It takes setup: you install it, point it at your app (ideally a staging copy), and configure authentication if you want it to test signed-in pages. Its alert list includes passive header alerts (CSP header not set, missing anti-clickjacking header, HSTS not set) and active alerts such as ".env Information Leak" and "Hidden File Found". It finds classes of bug the passive scanners cannot, such as injection flaws, and its own docs say it still will not find logical flaws like broken access control.
What is the difference between a header checker and a vulnerability scanner?
A header checker makes one normal request and grades what comes back: which security headers are present and whether their values are safe. A vulnerability scanner sends crafted requests designed to break things, such as injection payloads in form fields, and watches the responses for signs that an attack worked.
The difference decides when you can run each. A passive check reads the same responses any browser gets, so you can point it at any site, including a competitor's. An active scan sends attacks, so run it only against your own app, preferably a staging copy with test data, because it submits forms and can create records.
Use both at different times: a passive scan on every deploy, because it is quick and catches configuration regressions, and an active scan before a launch or a major release.
What can't passive security scanners see?
Anything that depends on who is asking. A passive scanner sees your site as an anonymous visitor, so it cannot tell whether one signed-in user can read another user's data, whether your database enforces permissions, or whether your checkout can be tricked into a zero price. Those need tests written for your app.
The gaps that matter most for a small SaaS:
Access control between users. Sign in as user A, copy a request that loads A's record, change the ID to one belonging to user B, and send it. If B's data comes back, you have a broken access control bug no scanner above will flag.
Database permissions. With Supabase, a table in an exposed schema without row-level security is readable and writable by any role with a grant on it, according to Supabase's docs. Scanners do not log in to your database; check that RLS is enabled on every table and that each policy limits rows to their owner.
Business rules. Coupons that stack, trials that restart, prices set by the client, rate limits on password reset. Test each rule by trying to break it.
Secrets in your code. A scanner finds a public .env file; it does not find an API key committed to a private repository or pasted into a client component. Search your repository and your built bundle.
As "nothing found in what this tool checks," not "secure." Each scanner above covers one slice, and each says so. Confirm on the tool's own site what it checks today, then combine a broad passive scan with the specialist tool for anything it flags.
A practical routine for a small team:
Run a broad passive scan on every production deploy, or at least weekly.
When it flags TLS, run SSL Labs for the detail; when it flags email records, run Internet.nl.
When something looks compromised, run Sucuri SiteCheck and check your server files directly.
Before launch and before major releases, run an active ZAP scan against staging.
Test access control and database permissions by hand, because no scanner here can.
To run the broad pass now, run the free scan on LaunchScaler with your URL. It needs no account and runs its 29 security checks alongside 127 checks in its other categories, so the headers, TLS, DNS records and exposed files come back in one report.
02
Can a free online scanner find every vulnerability?
No. Passive scanners read what your server sends to any visitor, so they cannot test login logic, access control between users or database permissions. ZAP's own docs say automated scanning will not detect logical flaws such as broken access control.
03
What is the difference between a security headers checker and a vulnerability scanner?
A headers checker makes one normal request and grades the response headers. A vulnerability scanner sends crafted requests that attack the app to see what breaks, which is why tools like ZAP warn you to run active scans only on apps you own.
04
Is it legal to scan any website for security issues?
Passive checks read the same public responses any browser gets. Active scanning is different: ZAP describes it as an attack and says not to use it on web applications you do not own.