Find what's exposed before it's exploited
Leaked API keys. Rogue subdomains. Hijacked CDN scripts. Card skimmers on your checkout. ScanTower finds them first, in under 60 seconds, with nothing to install.
- 30+
- security checks in a single scan
- 0
- plugins or agents to install
- 60s
- from URL to full report
- Free
- plan forever, no card needed
Nobody hacks a site at a convenient hour
This is what one site looks like over one night of monitoring. Every one of these fires an alert on the first scan it appears in, whether or not anyone is awake.
An example account, not live customer data. Your own findings take about a minute to produce. Run it on your site free.
Every finding traces back to a source you can check yourself
No proprietary black-box score you have to take on faith. Vulnerabilities cite the CVE and the advisory that reported it, so you can verify a finding before you act on it, or hand it to a developer who will.
Everything one scan covers
Supply chain through to open ports. Nothing is an add-on, and nothing is held back for a higher tier. The free plan runs the same scan the Agency plan does.
WordPress vulnerabilities
Core, plugin & theme CVEs with severity ratings
Exposed secrets
API keys & credentials leaked in delivered code
Subresource Integrity
SRI hash verification & missing-SRI detection
Card skimmers & malware
Behavioral JavaScript analysis in a real browser
Certificate transparency
New subdomains & unauthorized certificates
Visual defacement
Perceptual screenshot comparison with region mapping
SSL/TLS analysis
Expiry warnings, weak ciphers, A+ to F grading
Security headers
CSP, HSTS, clickjacking & XSS protections
Misconfigurations
Exposed .git, .env, backups & debug endpoints
Port scanning
Top 1,000 ports - exposed services & attack surface
DNS security
DNSSEC, CAA, SPF & DMARC validation
Domain reputation
Blocklist & threat intelligence checks
Change detection
DNS, headers, scripts, ports & hosting drift
Screenshot evidence
Full visual history of every scan
Microsoft IIS scanning
IIS-specific misconfigurations & known CVEs
Plus more in every scan
Visual Defacement - 2 of 16 page regions changed since baseline
Your site changed overnight. Would you notice?
ScanTower builds a baseline on your first scan. Every scan after that gets compared to it, so you know exactly what changed and where.
- Visual defacement detectionScreenshot hashing with adaptive thresholds per site. High-security sites can catch small changes. Busy sites won't get false alarms.
- Configuration drift alertsDNS records, security headers, SSL configuration, WHOIS, hosting provider - any unexpected change triggers an alert.
- New scripts, ports & subdomainsA new third-party script, an unexpected open port, or a fresh subdomain in CT logs - flagged the first scan it appears.
- Full screenshot timelineVisual evidence from every scan, with side-by-side before/after comparison when something changes.
Your first result in under 60 seconds
No plugins, no installation, no configuration, no call with a sales engineer. Paste your URL and read the report.
- 01
Enter your URL
Type your website address. That’s it. We scan from the outside, exactly the way an attacker sees you.
5 seconds - 02
We scan everything
30+ security checks run in parallel: vulnerabilities, secrets, malware, SSL, subdomains, ports and more.
30-60 seconds - 03
Stay protected
Get your security report instantly, then turn on continuous monitoring. We alert you the moment anything changes.
Ongoing
Alerts on your terms
Alerts that reach you in seconds, and reports your clients will actually read.
Instant, multi-channel alerts
Email, Slack, Discord, or webhooks straight into your own tooling. Configurable severity thresholds mean you're woken up for skimmers, not for a missing header.
Client-ready PDF reports
Screenshots, severity breakdowns, plain-English explanations and fix recommendations. Built for agencies proving the value of a monitoring retainer.
Security score & history
Every site gets a 0-100 score and an A+ to F grade, tracked over time. Watch your posture improve, and prove it with historical trend data.
Agencies monitor every client site from one dashboard with team access.
E-commerce gets skimmer and defacement detection customers never have to discover for them.
Developers get pre-launch validation and webhook alerts into an existing stack.
Built around how sites actually get compromised
The story behind most hacked websites is dull and repeatable. A plugin nobody updated. A key left in a JavaScript bundle. A script that quietly appeared one Tuesday. The owner finds out weeks later, usually from a customer or from their payment processor.
So ScanTower is built to catch those specific things, from the outside, with no access to your server. Every detector is here because that class of problem turns up in real compromises, not because it fills out a feature matrix. When a new pattern shows up in the wild, we add detection for it.
Independent and UK-based, funded by the people who use it rather than by an advertising model or an exit plan.
What ScanTower never does
Worth knowing before you point a security scanner at your own site.
- Never asks for server accessNo plugin, no agent, no SSH key, no CMS admin login. Everything comes from the outside of your site.
- Never exploits what it findsScans identify and fingerprint. They do not attempt to break in, change data, or damage anything.
- Never sends your data to ad networksAnalytics are self-hosted and cookieless. No third-party trackers on this site, no profile of you sold on.
- Never holds your account hostageUK GDPR compliant. Export what you need, delete your account and its data from settings whenever you want.
Free is a real plan, not a teaser
One site monitored properly, forever, with the same 30+ check scan every paid plan runs. No card, no trial countdown, no feature that stops working on day 15.
Takes about 30 seconds. Upgrade only if you outgrow it.
- 1 website, monitored continuously
- 15 on-demand scans every month
- Weekly automated scans
- Email alerts when something changes
- 7 days of scan history
- 1 PDF report download per month
- Full API access
Start free, scale when ready
No credit card required. Upgrade anytime for more sites and features.
forever
Perfect for getting started
- 1 website
- 15 adhoc scans per month
- 1 PDF report download per month
- Weekly automated scans
- API access
Need something in between?
Need Extra Scans?
Purchase scan credits that never expire. Works with any plan including free. Perfect for busy months or one-off projects.
30-day money back guarantee • Cancel anytime
All payments securely processed by Stripe
Frequently asked questions
Do I need to install anything to scan my website?
No. ScanTower scans your website from the outside, exactly the way an attacker sees it. There are no plugins, agents, or code changes required - just enter your URL and results arrive in under 60 seconds.
What security issues does ScanTower detect?
Every scan runs 30+ checks: WordPress core, plugin and theme vulnerabilities, exposed API keys and secrets in your JavaScript, Subresource Integrity failures, card skimmers and malware, rogue subdomains via certificate transparency logs, SSL/TLS problems, missing security headers, DNS security issues, open ports, server misconfigurations like exposed .git and .env files, and visual defacement.
How does ScanTower detect that my site has been compromised?
ScanTower takes a snapshot of your site on the first scan: scripts, headers, DNS records, subdomains, open ports, and how it looks. Every scan after gets compared to it. New malicious scripts, integrity failures on CDN resources, unexpected subdomains, and visual changes all trigger alerts.
Does ScanTower work for non-WordPress websites?
Yes, absolutely. WordPress scanning is just one part. SSL, headers, exposed secrets, SRI, malware, DNS, ports, defacement detection all work on any site. We also have dedicated Microsoft IIS scanning.
How often does ScanTower scan my site?
You choose: hourly, daily, or weekly automated scans depending on your plan. Each scan is compared against your site’s history, so you’re alerted only when something actually changes or a new issue appears.
Is there a free plan?
Yes. You can run an instant scan right now without an account, and the free plan includes ongoing monitoring for one site - no credit card required.
Something not answered here? Send it over. We read every one.
You are one minute from knowing
Most first scans turn something up: an expired certificate, a plugin two years behind, a key sitting in a JavaScript file, a script nobody remembers approving. Better you find it than someone else.
Free forever on one site. No credit card. Cancel or delete your account anytime.