Find what's exposed before it's exploited

Leaked API keys. Rogue subdomains. Hijacked CDN scripts. Card skimmers on your checkout. ScanTower finds them first, in under 60 seconds, with nothing to install.

https://
Include
No account needed for your first scanNo credit card
30+
security checks in a single scan
0
plugins or agents to install
60s
from URL to full report
Free
plan forever, no card needed

Nobody hacks a site at a convenient hour

This is what one site looks like over one night of monitoring. Every one of these fires an alert on the first scan it appears in, whether or not anyone is awake.

yourstore.com / detections
Illustrative
02:14critical
Exposed SecretAWS access key found in /static/js/main.8f3a2c.js
02:14critical
SRI Mismatchcdn.thirdparty.com/lib.min.js failed integrity check
03:02high
New Subdomainlogin-secure.yourstore.com appeared in CT logs
04:47high
Plugin Vulnerabilitycontact-form 5.1.6 - known CVE, update available
05:31critical
Skimmer Patternpayment field listener sending data to unknown domain
06:08medium
Configuration DriftContent-Security-Policy header removed since last scan
06:09watching

An example account, not live customer data. Your own findings take about a minute to produce. Run it on your site free.

Every finding traces back to a source you can check yourself

No proprietary black-box score you have to take on faith. Vulnerabilities cite the CVE and the advisory that reported it, so you can verify a finding before you act on it, or hand it to a developer who will.

NVD
NIST vulnerability database
Wordfence Intelligence
WordPress plugin & theme CVEs
OSV.dev
Open source advisories
Certificate Transparency
Public CT logs via crt.sh
endoflife.date
Live software lifecycle data
WordPress.org
Official release & plugin data

Everything one scan covers

Supply chain through to open ports. Nothing is an add-on, and nothing is held back for a higher tier. The free plan runs the same scan the Agency plan does.

baselineMon 02:00
latest scanTue 02:00
region changed

Visual Defacement - 2 of 16 page regions changed since baseline

Your site changed overnight. Would you notice?

ScanTower builds a baseline on your first scan. Every scan after that gets compared to it, so you know exactly what changed and where.

  • Visual defacement detection
    Screenshot hashing with adaptive thresholds per site. High-security sites can catch small changes. Busy sites won't get false alarms.
  • Configuration drift alerts
    DNS records, security headers, SSL configuration, WHOIS, hosting provider - any unexpected change triggers an alert.
  • New scripts, ports & subdomains
    A new third-party script, an unexpected open port, or a fresh subdomain in CT logs - flagged the first scan it appears.
  • Full screenshot timeline
    Visual evidence from every scan, with side-by-side before/after comparison when something changes.

Your first result in under 60 seconds

No plugins, no installation, no configuration, no call with a sales engineer. Paste your URL and read the report.

  1. 01

    Enter your URL

    Type your website address. That’s it. We scan from the outside, exactly the way an attacker sees you.

    5 seconds
  2. 02

    We scan everything

    30+ security checks run in parallel: vulnerabilities, secrets, malware, SSL, subdomains, ports and more.

    30-60 seconds
  3. 03

    Stay protected

    Get your security report instantly, then turn on continuous monitoring. We alert you the moment anything changes.

    Ongoing

Alerts on your terms

Alerts that reach you in seconds, and reports your clients will actually read.

Instant, multi-channel alerts

Email, Slack, Discord, or webhooks straight into your own tooling. Configurable severity thresholds mean you're woken up for skimmers, not for a missing header.

Client-ready PDF reports

Screenshots, severity breakdowns, plain-English explanations and fix recommendations. Built for agencies proving the value of a monitoring retainer.

Security score & history

Every site gets a 0-100 score and an A+ to F grade, tracked over time. Watch your posture improve, and prove it with historical trend data.

Agencies monitor every client site from one dashboard with team access.

E-commerce gets skimmer and defacement detection customers never have to discover for them.

Developers get pre-launch validation and webhook alerts into an existing stack.

Built around how sites actually get compromised

The story behind most hacked websites is dull and repeatable. A plugin nobody updated. A key left in a JavaScript bundle. A script that quietly appeared one Tuesday. The owner finds out weeks later, usually from a customer or from their payment processor.

So ScanTower is built to catch those specific things, from the outside, with no access to your server. Every detector is here because that class of problem turns up in real compromises, not because it fills out a feature matrix. When a new pattern shows up in the wild, we add detection for it.

Independent and UK-based, funded by the people who use it rather than by an advertising model or an exit plan.

What ScanTower never does

Worth knowing before you point a security scanner at your own site.

  • Never asks for server access
    No plugin, no agent, no SSH key, no CMS admin login. Everything comes from the outside of your site.
  • Never exploits what it finds
    Scans identify and fingerprint. They do not attempt to break in, change data, or damage anything.
  • Never sends your data to ad networks
    Analytics are self-hosted and cookieless. No third-party trackers on this site, no profile of you sold on.
  • Never holds your account hostage
    UK GDPR compliant. Export what you need, delete your account and its data from settings whenever you want.
The free plan, in full

Free is a real plan, not a teaser

One site monitored properly, forever, with the same 30+ check scan every paid plan runs. No card, no trial countdown, no feature that stops working on day 15.

Takes about 30 seconds. Upgrade only if you outgrow it.

  • 1 website, monitored continuously
  • 15 on-demand scans every month
  • Weekly automated scans
  • Email alerts when something changes
  • 7 days of scan history
  • 1 PDF report download per month
  • Full API access

Start free, scale when ready

No credit card required. Upgrade anytime for more sites and features.

MonthlyYearly
Free
$0

forever

Perfect for getting started

  • 1 website
  • 15 adhoc scans per month
  • 1 PDF report download per month
  • Weekly automated scans
  • API access
MOST POPULAR
Pro
$12.99

per month

  • 20 websites
  • 500 adhoc scans per month
  • Unlimited PDF report downloads
  • Hourly automated scans
  • Custom request headers
  • Unlimited webhook endpoints
Agency
$99.99

per month

  • Everything in Pro, plus:
  • 200 websites
  • 2000 adhoc scans per month
  • Unlimited team members
  • Unlimited white-label PDF reports (your logo & branding)
  • Unlimited scan history

Need something in between?

Solo
$19.99/ year

Perfect for freelancers

  • 3 websites
  • 50 adhoc scans per month
  • Unlimited PDF report downloads
  • Daily automated scans
  • Custom request headers
Solo, lifetimeLimited

Pay once, use Solo features forever. No renewals.

$32.99
one-time
One-Time Purchases

Need Extra Scans?

Purchase scan credits that never expire. Works with any plan including free. Perfect for busy months or one-off projects.

One-time payment
Credits never expire
Use on any website
Stacks with subscription
POPULAR

100 Scans

Perfect for getting started

$4.99
$0.05 per scan

500 Scans

Great for growing websites

$21.99
$0.04 per scan
BEST VALUE

1,000 Scans

Maximum value and savings

$37.99
$0.04 per scan

30-day money back guarantee • Cancel anytime

All payments securely processed by Stripe

Frequently asked questions

Do I need to install anything to scan my website?

No. ScanTower scans your website from the outside, exactly the way an attacker sees it. There are no plugins, agents, or code changes required - just enter your URL and results arrive in under 60 seconds.

What security issues does ScanTower detect?

Every scan runs 30+ checks: WordPress core, plugin and theme vulnerabilities, exposed API keys and secrets in your JavaScript, Subresource Integrity failures, card skimmers and malware, rogue subdomains via certificate transparency logs, SSL/TLS problems, missing security headers, DNS security issues, open ports, server misconfigurations like exposed .git and .env files, and visual defacement.

How does ScanTower detect that my site has been compromised?

ScanTower takes a snapshot of your site on the first scan: scripts, headers, DNS records, subdomains, open ports, and how it looks. Every scan after gets compared to it. New malicious scripts, integrity failures on CDN resources, unexpected subdomains, and visual changes all trigger alerts.

Does ScanTower work for non-WordPress websites?

Yes, absolutely. WordPress scanning is just one part. SSL, headers, exposed secrets, SRI, malware, DNS, ports, defacement detection all work on any site. We also have dedicated Microsoft IIS scanning.

How often does ScanTower scan my site?

You choose: hourly, daily, or weekly automated scans depending on your plan. Each scan is compared against your site’s history, so you’re alerted only when something actually changes or a new issue appears.

Is there a free plan?

Yes. You can run an instant scan right now without an account, and the free plan includes ongoing monitoring for one site - no credit card required.

Something not answered here? Send it over. We read every one.

You are one minute from knowing

Most first scans turn something up: an expired certificate, a plugin two years behind, a key sitting in a JavaScript file, a script nobody remembers approving. Better you find it than someone else.

Free forever on one site. No credit card. Cancel or delete your account anytime.