What a Website Security Scan Actually Checks – A Practical Guide for UK Small Businesses
A website security scan checks for known vulnerabilities, misconfigurations and malicious code on your site. It examines the web server, application code, third‑party components and the surrounding infrastructure for weaknesses that could be exploited. The scan also verifies that security headers, SSL/TLS settings and authentication mechanisms are correctly configured.
Server‑level checks
At the foundation of any website is the server that hosts it. A thorough scan will interrogate the server for:
- Open ports – Unnecessary services listening on the internet increase the attack surface. The scanner probes common ports (80, 443, 22, 21, etc.) and flags any that should be closed.
- Out‑of‑date software – The operating system, web server (Apache, Nginx, IIS) and associated modules are compared against public vulnerability databases. If a known CVE exists for the version in use, the scan highlights it.
- File permissions – Incorrect permissions on configuration files or directories can allow attackers to read or modify sensitive data.
- Server banners – Revealing the exact version of software in HTTP headers gives attackers a roadmap. The scanner checks whether these banners are hidden or generic.
For UK small businesses, many hosts offer managed patches, but it is still vital to confirm that the latest security updates have been applied.
Application‑level checks
Modern websites are rarely static HTML; they run code written in PHP, JavaScript, Python, Ruby or other languages. Application‑level scanning focuses on:
- Injection flaws – SQL, NoSQL and command injection vulnerabilities allow attackers to run arbitrary queries or system commands. The scanner injects test strings into form fields and URL parameters to see if the backend reacts unexpectedly.
- Cross‑site scripting (XSS) – By inserting malicious scripts into input fields, the scanner determines whether the output is properly escaped.
- Authentication and session management – Weak password policies, missing multi‑factor authentication (MFA) and insecure session cookies are flagged.
- Directory traversal and insecure file inclusion – Attempts are made to access files outside the web root or include remote code.
These checks are automated, but they complement manual code reviews and secure development practices.
Third‑party components and libraries
Most websites rely on content management systems (CMS) such as WordPress, Joomla or Drupal, plus plugins, themes and JavaScript libraries. Each component can introduce its own vulnerabilities. The scan will:
- Identify installed plugins and themes – By reading the site’s file structure or analysing HTTP responses, the scanner creates an inventory.
- Cross‑reference known vulnerabilities – Using public advisories (e.g., WPVulnDB, NVD), the scanner checks whether any component version is known to be vulnerable.
- Detect outdated libraries – Front‑end libraries like jQuery, Bootstrap or Font Awesome are examined for versions that have security patches.
- Spot insecure defaults – Some plugins ship with default admin accounts or sample data that should be removed.
Keeping plugins up to date is a core recommendation in the UK Government's Cyber Security Breaches Survey guidance for small businesses.
Security headers, SSL/TLS and encryption
Even if the underlying code is clean, a site can be vulnerable if it does not enforce secure communication. The scanner validates:
- HTTPS enforcement – Whether all pages redirect from HTTP to HTTPS, preventing downgrade attacks.
- TLS version and cipher suite – Older protocols (TLS 1.0/1.1) and weak ciphers are flagged. The scanner may suggest using
TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384as a modern, secure choice. - HTTP security headers –
Content‑Security‑Policy,Strict‑Transport‑Security,X‑Content‑Type‑Options,X‑Frame‑OptionsandReferrer-Policyare checked for presence and correct values. - Certificate validity – Expiry dates, correct hostname matching and the use of a trusted Certificate Authority are verified.
For UK businesses handling personal data, these controls help meet the technical standards required for Cyber Essentials, which is issued via an accredited body.
Malware, phishing and black‑list checks
A scan also looks for signs that the site has already been compromised:
- Hidden malicious files – The scanner searches for known web‑shell signatures, base64‑encoded payloads and suspicious file names.
- External links to phishing or scam domains – Any outbound link that points to a URL listed on public phishing black‑lists triggers an alert.
- Search engine de‑indexing warnings – Google Safe Browsing and Bing’s SmartScreen APIs are queried to see if the site is flagged as unsafe.
If any of these indicators are found, the report will advise immediate isolation of the site and a forensic review.
Reporting, remediation guidance and next steps
After the technical checks, the scanner compiles a clear, prioritised report. Each finding includes:
- A description of the issue and why it matters for UK data protection law.
- The risk rating (low, medium, high) based on exploitability and potential impact.
- Concrete remediation steps – for example, "Update WordPress to 6.5.2 or later" or "Add
Strict-Transport-Security: max-age=31536000; includeSubDomainsto the server config". - References to official guidance, such as the National Cyber Security Centre (NCSC) hardening checklists.
For small businesses, the most valuable part of the report is the actionable checklist that can be tackled in-house or handed to a trusted developer. Regular re‑scanning (at least quarterly) ensures that new vulnerabilities are caught early.
Understanding exactly what a website security scan checks empowers you to protect your online presence, comply with UK cyber‑security standards and avoid the costly fallout of a breach. If you’re ready to see your site’s current security posture, let Solvbeat give you a clear, no‑obligation picture.