Vulnerability scanning
We run automated vulnerability scanning with third-party tools: we check the site and infrastructure for known vulnerabilities, outdated components, typical misconfigurations and deliver a prioritized report. To see weak spots and close them. Honestly upfront: a scanner finds KNOWN typical vulnerabilities, but it is an automated check with false positives/negatives — it does NOT replace a manual pentest and is not a formal certified report.
Vulnerability scanning — overview

Vulnerability scanning is a job (can be made regular): we run the site/application/infrastructure through scanners (e.g. OWASP ZAP, Nuclei, dependency checks, config scanners), identify known vulnerabilities, outdated/vulnerable components and libraries, typical misconfigurations, missing headers/updates, and form a prioritized report with recommendations. Honestly about the nature, this is key: an automated scanner looks for KNOWN, documented vulnerabilities by databases — it is fast and useful for hygiene, but does NOT find complex attack logic, business-logic holes, chains and 0-days; it has FALSE POSITIVES (flags as unsafe what is not exploitable) and MISSES — so findings need verification, and this is not a 'full security check'. Honestly about the boundary: this is NOT a manual pentest (deep human check — separate) and NOT a formal certified report for regulators/compliance. Honestly about the essence: this is detection and prioritization, NOT fixing — fixing what is found is separate work (we can do it separately); scanning by itself does not protect the site. Honestly about tools: some scanners are paid — billed separately. Honestly about the snapshot: the result is valid at the time of the scan; after changes and new CVEs a rescan is needed. Honestly about access: access/permission to scan is needed. An important boundary: this is scanning, not a pentest, not code audit and not fixing. Picture this: instead of 'we don't know which known holes are open' — a prioritized list with recommendations. The base price starts from 15,000 ₽ per scan; it depends on scope and infrastructure.
Problems we solve
- You do not know which known vulnerabilities are open.
- Outdated components/libraries with known CVEs.
- Typical misconfigurations and missing updates.
- There is no regular check of weak spots.
What's included in the Vulnerability scanning service
- Running scanners (application/infrastructure/dependencies)
- Identifying known vulnerabilities and outdated components
- Checking typical misconfigurations
- Verifying findings (filtering false positives)
- A prioritized report with recommendations
- Indicating boundaries (not a pentest/not a certificate)
- A frequency recommendation (new CVEs)
- Reviewing results with you
What you get
- Known vulnerabilities and weak spots are visible
- Priorities for what to close first
- Fewer false positives (verified)
- A base for fixing (fix/pentest — separately)
How the work goes: steps
- We agree on scope and scan permission; collect access
- We run scanners, verify findings
- We compile a prioritized report, review with you
Why PDV Expert
- Fixed price and timeline — no surprises on the invoice.
- Report and recommendations in plain language — clear without a technical background.
- In touch at every step and answering questions about the result.
FAQ
Will scanning find all vulnerabilities?
No. A scanner finds KNOWN typical vulnerabilities by databases, but not complex attack logic, business-logic holes and 0-days; there are false positives and misses. We verify findings. For a deep check a manual pentest is needed (separate).
Is this a certified audit/pentest?
No. It is an automated check for hygiene, not a formal certified report for regulators/compliance and not a manual pentest. If you need a certificate or a deep audit — those are separate services (pentest/formal audit).
Will you fix what is found?
Scanning identifies and prioritizes, while fixing is separate work (we can do it separately). The scan itself does not protect the site; plus the result is a snapshot: after changes and new CVEs a rescan is needed.
About the provider
The «Vulnerability scanning» service is provided by PDV Expert — a team specialising in «Site quality». We work under contract and deliver a written report with recommendations.