Site quality · Site security

Vulnerability scanning

We run automated vulnerability scanning with third-party tools: we check the site and infrastructure for known vulnerabilities, outdated components, typical misconfigurations and deliver a prioritized report. To see weak spots and close them. Honestly upfront: a scanner finds KNOWN typical vulnerabilities, but it is an automated check with false positives/negatives — it does NOT replace a manual pentest and is not a formal certified report.

Price
$3,000
Duration
usually 3–6 business days; can be made regular

Vulnerability scanning — overview

Vulnerability scanning — price, timeline & scope

Vulnerability scanning is a job (can be made regular): we run the site/application/infrastructure through scanners (e.g. OWASP ZAP, Nuclei, dependency checks, config scanners), identify known vulnerabilities, outdated/vulnerable components and libraries, typical misconfigurations, missing headers/updates, and form a prioritized report with recommendations. Honestly about the nature, this is key: an automated scanner looks for KNOWN, documented vulnerabilities by databases — it is fast and useful for hygiene, but does NOT find complex attack logic, business-logic holes, chains and 0-days; it has FALSE POSITIVES (flags as unsafe what is not exploitable) and MISSES — so findings need verification, and this is not a 'full security check'. Honestly about the boundary: this is NOT a manual pentest (deep human check — separate) and NOT a formal certified report for regulators/compliance. Honestly about the essence: this is detection and prioritization, NOT fixing — fixing what is found is separate work (we can do it separately); scanning by itself does not protect the site. Honestly about tools: some scanners are paid — billed separately. Honestly about the snapshot: the result is valid at the time of the scan; after changes and new CVEs a rescan is needed. Honestly about access: access/permission to scan is needed. An important boundary: this is scanning, not a pentest, not code audit and not fixing. Picture this: instead of 'we don't know which known holes are open' — a prioritized list with recommendations. The base price starts from 15,000 ₽ per scan; it depends on scope and infrastructure.

Problems we solve

  • You do not know which known vulnerabilities are open.
  • Outdated components/libraries with known CVEs.
  • Typical misconfigurations and missing updates.
  • There is no regular check of weak spots.

What's included in the Vulnerability scanning service

  • Running scanners (application/infrastructure/dependencies)
  • Identifying known vulnerabilities and outdated components
  • Checking typical misconfigurations
  • Verifying findings (filtering false positives)
  • A prioritized report with recommendations
  • Indicating boundaries (not a pentest/not a certificate)
  • A frequency recommendation (new CVEs)
  • Reviewing results with you

What you get

  • Known vulnerabilities and weak spots are visible
  • Priorities for what to close first
  • Fewer false positives (verified)
  • A base for fixing (fix/pentest — separately)

How the work goes: steps

  • We agree on scope and scan permission; collect access
  • We run scanners, verify findings
  • We compile a prioritized report, review with you

Why PDV Expert

  • Fixed price and timeline — no surprises on the invoice.
  • Report and recommendations in plain language — clear without a technical background.
  • In touch at every step and answering questions about the result.

FAQ

  • Will scanning find all vulnerabilities?

    No. A scanner finds KNOWN typical vulnerabilities by databases, but not complex attack logic, business-logic holes and 0-days; there are false positives and misses. We verify findings. For a deep check a manual pentest is needed (separate).

  • Is this a certified audit/pentest?

    No. It is an automated check for hygiene, not a formal certified report for regulators/compliance and not a manual pentest. If you need a certificate or a deep audit — those are separate services (pentest/formal audit).

  • Will you fix what is found?

    Scanning identifies and prioritizes, while fixing is separate work (we can do it separately). The scan itself does not protect the site; plus the result is a snapshot: after changes and new CVEs a rescan is needed.

About the provider

The «Vulnerability scanning» service is provided by PDV Expert — a team specialising in «Site quality». We work under contract and deliver a written report with recommendations.

Prepared by PDV Expert · updated