Free vs Paid Website Security Scanner: What Each One Actually Catches

Free scanners and paid ones are not better and worse versions of the same thing. They look at your site from different places. Here is what each one sees, where each one goes blind, and how to decide what you need.

By Nathan Cross, Co-Founder, Network & Security Engineering·

Free vs paid website security scanner: the real difference is the vantage point

When people weigh a free vs paid website security scanner, they usually assume the paid tool is just the free tool with more checks bolted on. That is not the most useful way to think about it. The bigger difference is where the scanner stands when it looks at your site.

A free scanner almost always runs from the outside, as an anonymous visitor with no login and no special access. It sees what any attacker on the public internet sees: your DNS records, your email-authentication setup, your TLS certificate, your HTTP response headers, files you have accidentally left reachable, and version numbers your site happens to broadcast. That is a genuinely valuable view, because it is exactly the view an opportunistic attacker starts from.

A paid or authenticated scan adds the inside view. It logs in, or runs as code on the server itself, and reads things an outsider can never see: the exact version of every plugin and theme, your admin and user configuration, whether two-factor is on, and whether any core files have been tampered with. Neither view is the whole picture on its own. The outside view catches what is exposed; the inside view catches what is lurking. You can run the free external scan to see the outside view for your own site in about a minute.

What a free external scan genuinely catches

A good free scan is not a toy. Done passively and honestly, it surfaces a long list of issues that cause real breaches, and it does so without touching anything it should not. Here is the kind of thing the outside view reliably finds.

  • Email spoofability: missing or misconfigured SPF, DKIM, and DMARC records that let someone send mail as your domain. You can dig into this with our SPF/DMARC checker, and there is a fuller explainer in is your business email spoofable.
  • TLS and certificate problems: expiring certificates, weak configuration, or sites still reachable without HTTPS. Check yours with the SSL/TLS checker.
  • Missing HTTP security headers that leave browsers without basic protections, testable in the security headers checker.
  • Exposed files and paths: backup archives, config files, or directory listings that should never be public, which our exposed files checker looks for.
  • Known CVEs for any software version your site advertises publicly, including WordPress core and anything detectable from the outside.

Where every free external scan goes blind

The honest limitation of any outside-only scan is that it can only judge what the site chooses to reveal. Most well-run sites hide their plugin and theme versions, strip identifying headers, and otherwise give an anonymous visitor very little to go on. That is good security practice, but it means the most important risk on a WordPress site is often invisible from the outside.

That risk is plugins. Plugins account for roughly 96% of WordPress vulnerabilities; only a handful are ever in core (Patchstack). An external scan cannot enumerate the dozens of plugins running behind the scenes, cannot read their exact version numbers, and therefore cannot tell you which of them has a known, patchable vulnerability sitting on your site right now. It also cannot see whether two-factor is enabled on your admin accounts, whether a forgotten administrator account still exists, or whether a core file has been quietly modified by malware.

This is the gap a paid, authenticated, or plugin-based scan exists to close. We wrote about the two halves of the picture in more detail in the inside and outside of a website security scan, and the WordPress security guide covers the underlying hardening steps.

When the paid, inside view is worth paying for

You do not need an authenticated scan for every brochure site. If a site has almost no plugins, no logins, and nothing sensitive, the free external view covers most of what matters. The calculus changes the moment a site has real plugins, real users, or real consequences if it goes down.

WordPress vulnerability volume is the reason. Patchstack recorded nearly 8,000 new WordPress vulnerabilities in 2024, about a 34% rise on the year before (Patchstack, via SecurityWeek). New plugin vulnerabilities are disclosed almost daily, and the only way to know whether one affects you is to compare your exact installed versions against the vulnerability databases, which requires the inside view. You can see a sample of that matching with our WordPress vulnerability scan.

The stakes are also higher for small businesses than many owners assume. In Verizon's 2025 DBIR, ransomware or extortion appeared in 88% of breaches at small and medium businesses, versus 39% at larger organizations (Verizon 2025 DBIR). Attackers go after the sites that are easiest to compromise and slowest to patch, which describes a great many under-maintained small-business WordPress installs.

How BadgerScan splits free and Pro, fairly

BadgerScan is one scanner with two views, and the free vs paid website security scanner question is exactly the line we built it around. The free scan is one passive external scan: DNS, email security, TLS, HTTP headers, exposed files, and known CVEs for publicly detectable versions. It runs from the outside, touches nothing, and gives you a real grade for the attack surface anyone can see. For many sites that is genuinely all the information they need this month.

Pro adds the inside view to the same scanner through a read-only WordPress plugin. The plugin reads your exact plugin, theme, and core versions and matches them against the vulnerability data, checks admin configuration and two-factor, and verifies file integrity. It then fuses the inside and outside findings into one plain-English grade and one deduplicated fix-list, so you are not left reconciling two separate reports. The plugin is read-only by design: BadgerScan never performs penetration testing or active exploitation, and it never claims to remove malware or scan blacklists, because that is not what it does.

Other scanners make different trade-offs, and several are perfectly good at what they do. The questions to ask any tool, free or paid, are simple: does it look from the inside, the outside, or both, and is it honest about what it does not check? A scanner that quietly does only the outside view but talks like it sees everything is the one to be wary of, regardless of price.

See your outside view in about a minute, free

Run the free BadgerScan external scan to see exactly what an anonymous attacker sees: email security, TLS, headers, exposed files, and known CVEs. If your site runs real plugins, add Pro to fuse the inside view into one grade and one fix-list. No penetration testing, no hype, ever.

Run a free security scan

Frequently asked questions

Is a free website security scan good enough on its own?

For a simple site with few or no plugins and nothing sensitive, the free external view covers most of what matters: email spoofability, TLS, headers, and exposed files. But it cannot see the inside of a WordPress install, so it cannot tell you which of your installed plugins has a known vulnerability. Since plugins are about 96% of WordPress vulnerabilities, a plugin-heavy site really does need the inside view too.

What is the difference between an authenticated and unauthenticated scan?

An unauthenticated (external) scan runs as an anonymous visitor and sees only what your site reveals publicly. An authenticated scan logs in, or runs as trusted code on the server, and can read exact software versions, user and admin configuration, and file integrity. The external scan catches what is exposed; the authenticated scan catches what is hidden behind the login.

Does a paid scanner do penetration testing?

Some do, but BadgerScan does not. Our Pro plugin is strictly read-only: it reads versions and configuration and checks file integrity, but it never actively exploits anything. Active penetration testing is a separate, higher-touch engagement, and any tool that runs it should tell you clearly and get your permission first.

Will any scanner remove malware or check blacklists for me?

BadgerScan does not. We scan and report so you know what to fix; we do not claim malware removal or blacklist scanning, because those are different services. Be cautious of any scanner whose marketing blurs the line between detecting a problem and fixing it. If you need hands-on cleanup, that is a separate service from a scan.

Keep reading

Sources

  1. Patchstack, State of WordPress Security
  2. SecurityWeek, 8,000 New WordPress Vulnerabilities Reported in 2024
  3. Verizon, 2025 Data Breach Investigations Report

More from CyberBadger

BadgerScan is the website side of what we do. We're one local Hamilton and Burlington team for your whole setup, on-site nearby and remote across Canada.

Coming soon: BadgerAudit. A full, on-site cybersecurity audit, interviews, hands-on review, and a detailed report, for when a self-serve scan isn't enough. Ask us about it.