A Website Security Scan That Sees Inside and Outside
Most free scanners only check what is visible from the street. The real risks usually sit behind the login, so the best website security scan looks at both and combines what it finds.
By Nathan Cross, Co-Founder, Network & Security Engineering·
What a Website Security Scan Actually Checks
When people say website security scan, they usually mean one of two very different things. The first is an external scan: a passive check of what your site shows the public internet. The second is an internal scan: an authenticated look inside the site itself, at the software and settings only an administrator can see.
Think of it like checking on a building. An external scan walks the perimeter, seeing only what anyone on the street can: whether the front-door lock is the current type, whether the nameplate and mailbox are set up so post cannot be forged in your name, and whether any boxes of paperwork have been left out on the step. It never gets past the front door. An internal scan lets itself in with a key and checks what no passer-by can: the wiring behind the walls, whether the fixtures and fittings are a make and model already on a safety-recall list, and whether someone has quietly copied a key or hidden a way back in. Both views are useful, and on their own each one misses what the other would catch.
- External (outside): DNS records, email security (SPF, DKIM, DMARC), the TLS certificate, HTTP security headers, exposed files, and known CVEs for any versions you publish openly.
- Internal (inside): the exact plugin, theme, and WordPress core versions you are running and their known vulnerabilities, admin and login configuration, whether two-factor is on, and file integrity.
Why External-Only Scanners Miss the Biggest Risks
The trouble with most free tools is that they only see the outside. That is not a small gap. On WordPress, the software that powers the largest share of the web, the danger overwhelmingly lives in the parts an outside scanner cannot read. Plugins account for roughly 96% of WordPress vulnerabilities, and only a handful are ever found in WordPress core itself (Patchstack).
Plugins are exactly the layer an external scan struggles with. A modern, well-built site does not announce which plugins it runs or what version they are. So a vulnerable contact form, booking tool, or page builder can sit on your site, fully exploitable, while an outside-only scanner reports a clean bill of health. The lock on the front door looks fine. Nobody checked the cupboard where the spare key is kept.
Concrete Examples: What Each Scan Catches That the Other Cannot
The clearest way to see the value of both views is to look at real findings that only one side can produce. Neither scan is a luxury version of the other. They genuinely look at different things.
- Only an inside scan can tell you that your booking plugin is three versions behind and has a known vulnerability, because that version number is never shown to the public.
- Only an inside scan can confirm whether two-factor authentication is actually switched on for your admin accounts, or whether a core file has been quietly modified.
- Only an outside scan can tell you your domain has no DMARC record, so anyone can send email that looks like it comes from you.
- Only an outside scan can flag an expiring TLS certificate, a missing security header, or a backup file left sitting in a public folder where anyone can download it.
Inside and Outside, Combined Into One Graded Report
Seeing two separate reports is better than one, but it still leaves you doing the hard part: working out which findings overlap, which matter most, and what to fix first. A list from the outside and a list from the inside often describe the same weakness in two different ways, or rank the same plugin twice.
BadgerScan is built to remove that guesswork. The free external scan checks everything visible from the public internet. Pro adds a read-only WordPress plugin that scans the inside: exact versions, their CVEs, admin config, two-factor, and file integrity. BadgerScan then fuses both views into one plain-English letter grade and one deduplicated fix-list, so a problem that shows up inside and outside is counted once and explained once.
The plugin is strictly read-only. BadgerScan never performs penetration testing or active exploitation. It reads what is there and reports it, which is exactly what you want from a tool that runs against a live business site.
How to Read Your Grade and Act on It
A single letter grade is not meant to oversimplify your security. It is meant to give a non-technical owner an honest, at-a-glance answer to one question: how exposed am I right now? The fix-list underneath turns that grade into a short, ordered set of actions, with the highest-impact items first.
Most owners can handle the routine items themselves: update a plugin, turn on two-factor, add the missing email record. For the rest, or if you would simply rather hand it off, the CyberBadger team can do the work for you, and a BadgerScan Analyst Review that writes your fix plan for you is opening soon. The point is that you are never left staring at a wall of jargon, unsure what actually needs doing.
See Your Whole Site, Not Just the Outside
Run the free BadgerScan website security scan now to check your site from the outside in seconds. Add Pro to scan the inside too and get one combined letter grade with a clear, deduplicated fix-list. Want a person to handle it? Our local Hamilton and Burlington team can do the work today, and a BadgerScan Analyst Review that writes your fix plan for you is opening soon. Call (289) 796-8900.
Run a free security scanFrequently asked questions
Is the website security scan safe to run on a live site?
Yes. The external scan is entirely passive and only reads what your site already shows the public. The Pro WordPress plugin is read-only: it inspects versions, settings, and file integrity and reports back. BadgerScan never does penetration testing or active exploitation, so there is no risk to your live site or its data.
Why is an inside scan worth paying for if the outside scan is free?
Because the biggest WordPress risks live where an outside scan cannot see. Plugins account for roughly 96% of WordPress vulnerabilities (Patchstack), and a modern site does not publish its plugin versions. The inside scan reads those exact versions and their known CVEs, confirms two-factor is on, and checks file integrity, then BadgerScan combines that with the external findings into one grade.
What is the difference between BadgerScan and a normal vulnerability scanner?
Most free scanners only see the outside of your site. BadgerScan sees inside and outside and fuses both into one plain-English letter grade and a single deduplicated fix-list, so you are not left reconciling two separate reports. It is also backed by a local Canadian team that can fix what it finds.
Do I need to be technical to use the report?
No. The report is written for a non-technical business owner: one letter grade and a short, prioritised fix-list in plain English. If you would rather not touch it yourself, the CyberBadger team can carry out the work, and a BadgerScan Analyst Review that writes the plan for you is opening soon.