Website security scanner
An external scanner that tells you what a stranger can see
An external website security scanner that reads DNS, TLS, headers, cookies and exposed services from outside. Read-only, no install, no credentials used.
What an external scanner actually looks at
DNS and email
The records that decide where visitors land and whether your email can be sent in your name: A and AAAA, MX, NS, CAA, DNSSEC, SPF, DKIM and DMARC, plus the dangling entries that let somebody else claim a subdomain.
Transport security
The certificate and the connection it protects: whether it is valid, whether it matches the hostname, whether it is close to expiry, whether the protocols and cipher suites offered still include ones that are broken, and whether plain HTTP is redirected to HTTPS.
HTTP response headers
What your server tells every browser: HSTS, Content-Security-Policy, X-Content-Type-Options, framing and referrer policy, and the cookie attributes that decide whether a stolen session cookie is useful to anyone.
Exposed surface
What is reachable that should not be: subdomains nobody remembers creating, backup files, version-control directories, source maps, configuration files and API documentation.
What it does not do
An external assessment is one view, not a penetration test
- No credentials are used. Every check runs as an anonymous visitor. Whatever is behind your sign-in page is not assessed, because nothing is signed in to.
- Nothing is installed on your site. There is no agent, no script tag to add and no change to your infrastructure. Your site keeps serving traffic exactly as it does now.
- No source code is read. A flaw in application logic that no request from outside can reach is outside this view.
- No exploitation is attempted. A finding is evidence that a configuration is wrong, not proof that somebody has used it.
- It does not certify a site as secure. It reports what was observable at one moment, on one day, and states how confident it is in each finding.
If you need the other kind of work — authenticated testing, logic review, or an assessment of your internal network — that is a different engagement and a different tool. The methodology is explicit about where the line is.
Two levels of check, and why a report tells you which ran
A basic assessment runs on any public web address, immediately, with no proof of ownership. It covers the checks an outside observer can make unauthenticated — the layers above, all of them.
The full check surface additionally reaches the things that are only worth probing on a system you own: crawling the site to map its endpoints, following paths and parameters, and fetching referenced scripts. Proving control of the domain unlocks it, by publishing a verification record we issue in your domain's authoritative DNS.
Every report states which of the two levels it ran at. That line is at the top of the report rather than buried in a methodology appendix, because a report that does not say what it looked at is not one you can act on.
What the report gives you
A score out of 100, a ranked list of what matters first, and — for each finding — the evidence that produced it, a severity, a confidence level and the specific change that resolves it.
The full example report is a real assessment of a real domain we own, published in full.
How the score is calculated, and why it is not a marketing number
Most scanners compute a headline figure that nobody can reconstruct. This one is arithmetic you can redo from the findings in front of you, because the whole model is printed here — including the term that decides most of the number.
Each finding carries a severity, which says how much the condition would matter if it were exploited, and a confidence, which says how sure the engine is that the condition is really there. Both are Soryvex's own ratings, taken from its catalogue of checks. They are not the output of a penetration test, and a high severity is a statement about the class of issue and about what the evidence showed — not a demonstration that anyone has exploited your site.
1. What one finding is worth. Its severity points, multiplied by its confidence:
| Severity | Points | In the score |
|---|---|---|
| Critical | 9.5 | yes |
| High | 8.0 | yes |
| Medium | 5.0 | yes |
| Low | 2.0 | yes |
| Info | 1.0 | no — dropped first |
| Confidence | Multiplier |
|---|---|
| High | 1.0 |
| Medium | 0.7 |
| Low | 0.4 |
A finding with a missing or unrecognised confidence is scored at
0.4 — the bottom of that table, never the
top. An info finding is removed before any of this arithmetic
happens, so the row it has in the severity table is a catalogue label and
contributes nothing.
2. The anchor. The score does not start at zero. It starts at the value of the worst confirmed severity in the run — that one term is normally the largest part of the figure — and it cannot pass that severity's ceiling however many findings accumulate:
| Worst confirmed severity | Score starts at | Ceiling for this band |
|---|---|---|
| Critical | 82.0 | 100.0 |
| High | 62.0 | 79.0 |
| Medium | 42.0 | 59.0 |
| Low | 20.0 | 39.0 |
3. What is added on top of the anchor. Every confirmed finding then adds its own amount — from a second table, deliberately not the same numbers as the first:
| Severity of the finding | Adds |
|---|---|
| Critical | 2.0 × confidence |
| High | 1.6 × confidence |
| Medium | 1.2 × confidence |
| Low | 0.8 × confidence |
4. What likely findings are allowed to do. A likely finding is discounted to 0.5 of its step-1 value, and the whole group together can add no more than 5.0 to an anchored score. It can raise a number; it can never create the anchor.
5. The verdict. 80 or more is Critical, 60 or more is High, 40 or more is Medium, and anything below that is Low.
When nothing is confirmed. A run with likely issues and no confirmed finding skips steps 2 and 3 and is scored on its own branch: the discounted total, multiplied by 2.5 and never more than 25.0. So a run that finds nothing at all scores 0.0, but a run that finds likely issues and nothing confirmed does not: no confirmed finding means no anchor is ever looked up, and that branch's ceiling of 25.0 is below the 40.0 that earns a Medium rating, so such a run can never be graded above Low.
Worked through, from the illustrative report
| Step | Arithmetic | Running total |
|---|---|---|
| Anchor | worst confirmed severity is High, so the run starts at 62.0 | 62.0 |
| Confirmed findings | 2 confirmed, High severity at high confidence: 2 × (1.6 × 1.0) | 65.2 |
| Likely findings | 1 likely, Medium severity at medium confidence: 0.5 × 5.0 × 0.7 = 1.75, under the 5.0 ceiling on the group | 66.95 |
| Band ceiling | a High-anchored run cannot pass 79.0, and 66.95 is below it | 66.95 |
| Score | rounded to one decimal, which is the figure the report prints — 67.0 falls in the High band | 67.0 / 100 |
That is the figure printed in the illustrative report on the home page — two confirmed High findings, one likely Medium, and nothing else that counts — and the two agree because both come from the same function over the same constants, not because one was copied from the other. The full example report is a real assessment of a real domain and carries whatever score its own findings produce; the arithmetic above is how to check it.
So a report can list five findings and be scored from three, and it says so. That is deliberate: a score that counted every unconfirmed observation would move every time an unrelated header changed, and a score you cannot reconstruct from the findings is a number to argue with rather than act on.
See what the outside view finds on your site
The free plan assesses one domain, four times a month, with no card. Every finding arrives with the evidence behind it.
Read-only. No card. Nothing installed on your site.