SCANNING

External Vulnerability Scanning

See your business the way an attacker does — before they do.

What it is

We scan your internet-facing systems — websites, mail servers, remote access, anything exposed — for known vulnerabilities and misconfigurations, on a recurring schedule, and report what we find in plain English with a clear priority order.

If your site runs on WordPress, we scan that specifically: the WordPress version itself, every plugin and theme, and the known vulnerabilities affecting them. Plugins are the single most common way small business websites get taken over, and they go out of date quietly.

It is detection only: we look, we never touch. And because it runs regularly, you see whether your exposure is improving, not just a single snapshot.

Why it matters

Attackers scan the entire internet constantly, looking for the one exposed service that has not been patched. A one-off penetration test a year ago does not help against a vulnerability disclosed last week.

Most small businesses have no idea what they are exposing. An out-of-date plugin, an open management port, an expired certificate — this finds them while they are still cheap to fix.

A hacked website is not just an IT problem. It gets you blocklisted by Google, it can quietly serve malware to your own customers, and it is the kind of thing people remember about a business.

What's included

  • Recurring external scans of your internet-facing systems
  • WordPress scanning — core version, plugins, themes and known vulnerabilities
  • Known-vulnerability and misconfiguration detection
  • Plain-English report with a clear priority order
  • Trend tracking across scans, not a single snapshot
SMB1001

Regular vulnerability assessment is the specific control required for SMB1001 Gold — this service satisfies it, and it is included in Gold and above.

Common questions

Do you scan WordPress sites?

Yes. WordPress gets its own scan: the core version, every plugin and theme, and the publicly known vulnerabilities affecting them. Outdated plugins are the most common way a small business site gets compromised, and it is usually a plugin nobody remembered was installed.

What do you do about what you find on our website?

You get a plain-English report with the highest-risk items first. If we also manage your patching, the fixes can be handled for you; if someone else manages your site, the report is written so you can hand it straight to them.

Is this a penetration test?

No. This is automated detection-only scanning — it finds known vulnerabilities and misconfigurations. Penetration testing is a deeper, human-led engagement, required at SMB1001 Platinum, and offered separately.

Could it break our website?

No. It is detection only — it looks, it does not exploit, and it is rate-limited to avoid load.

Do you scan anything we ask?

Only systems you own or are authorised to test. We confirm authorisation before scanning — it is the law, and we take it seriously.

Ready to get external vulnerability scanning?

Backed by our 90-day money-back guarantee. If you're not happy, we refund everything you've paid.

© 2026 Aussie Cyber · Australian owned and operated since 1999