Site quality · Site security

Web app vulnerability scan (no formal report)

We run a web app vulnerability scan with tools + manual review of the results and give you a working list of found problems with priorities. To see typical and known weak spots and understand what to fix first. Honestly upfront and right in the title: this is a SCAN, NOT a full manual pentest and NOT a formal report/certification — it finds what scanners can find, may miss logical and non-standard vulnerabilities and give false positives.

Price
$3,600
Duration
usually 3–6 business days (depends on the size)

Web app vulnerability scan (no formal report) — overview

Web app vulnerability scan (no formal report) — price, timeline & scope

A web app vulnerability scan is a run of your site with automated security scanners followed by MANUAL review of the results: we cut off false positives, confirm real findings, prioritize by severity and give a clear list of 'what to fix and why'. Typical and known classes are checked (outdated components with known CVEs, open points, typical injection/XSS patterns, configuration errors, weak headers, etc.). Honestly about the type, this is even in the title: this is a SCAN, NOT a full manual pentest and NOT a formal report/audit/certificate. The difference is fundamental: a scanner finds the KNOWN and typical, but may MISS logical vulnerabilities, chains and non-standard holes (false negatives), and also produce false positives (we filter them out manually). Honestly about the result: you get a working list of findings with priorities for fixing — this is NOT a legal compliance document or a 'security certificate' for regulators/partners (a formal audit/pentest with a report is a separate, more expensive work). Honestly about fixing: the scan itself reveals problems; fixing what is found is a separate scope of work (we can estimate afterward). Honestly about the point in time: a scan shows the state on the check date — new code and new CVEs require a repeat scan. Honestly about access: access to the site/staging and approval are needed (a scan is load and active checks). An important boundary: this is a scan without a formal report, while a full pentest with a report and a compliance audit are separate. Picture this: instead of 'we don't know what our weak spots are' — a specific prioritized list of what is worth fixing. The base price starts from 18,000 ₽; it depends on the size of the application.

Problems we solve

  • It is unknown what typical and known vulnerabilities the site has.
  • Outdated components with known CVEs go unnoticed.
  • Configuration errors and open points are not identified.
  • No prioritized list of 'what to fix first'.

What's included in the Web app vulnerability scan (no formal report) service

  • A run of the site with automated security scanners
  • Manual review and filtering of false positives
  • Confirmation of real findings
  • Prioritization by severity (what is critical)
  • A clear list of 'what to fix and why'
  • A clear statement of boundaries (a scan, not a pentest, not a formal report)
  • Approval and safe conduct of the scan
  • Handover and review of results with you

What you get

  • A list of typical and known vulnerabilities is visible
  • Findings prioritized by severity
  • It is clear what to fix first
  • A working list (a formal pentest/report — separate)

How the work goes: steps

  • We agree the scope and access, warn about the scan load
  • We run the scanners, manually filter false positives
  • We prioritize, hand over the list, review boundaries with you

Why PDV Expert

  • Fixed price and timeline — no surprises on the invoice.
  • Report and recommendations in plain language — clear without a technical background.
  • In touch at every step and answering questions about the result.

FAQ

  • Is this a pentest? Will you give a security report?

    No, and that is honestly stated in the title. This is a scan with tools + manual review: it finds typical and known vulnerabilities, but does not replace a full manual pentest and does NOT give a formal report/certificate for regulators or partners. If you need exactly an official pentest with a report — that is a separate, more expensive work; we will suggest a contractor/scope.

  • Will the scan find all vulnerabilities?

    No. Scanners are good at finding the known and typical (old components with CVEs, typical injections, configuration errors), but may miss logical vulnerabilities and non-standard chains (false negatives) and give false positives (we filter those manually). It is a valuable check, but not a guarantee that no holes remain.

  • Do you also fix what is found?

    The scan itself is the identification and prioritization of problems. Fixing what is found is a separate scope of work: after the scan we will estimate what and how long it takes to fix. This is more honest: you see the real picture, and you make the decision on the fixing scope deliberately.

About the provider

The «Web app vulnerability scan (no formal report)» service is provided by PDV Expert — a team specialising in «Site quality». We work under contract and deliver a written report with recommendations.

Prepared by PDV Expert · updated