I will scan your website attack surface for vulnerabilities
The Cyber Friend, where you can Trust Us, with your Security
Vetted by Fiverr Pro
Sam was selected by the Fiverr Pro team for their expertise.
Vetted for
Cybersecurity
About this Gig
Vetted Pro
Your website is the one part of your company that answers to anyone who asks. An expired certificate, missing security headers, an admin port left open, an SPF record never finished. None of it is visible to you. All of it is visible to whoever is scanning the internet tonight.
I scan it the way they do and tell you what is sitting there.
What you receive:
- Every finding rated by severity, ordered so you know what comes first
- Open ports and services answering from the internet
- SSL and TLS certificate health and configuration
- Security headers, and what each missing one leaves open
- SPF, DKIM, and DMARC records, and whether anyone can spoof you
- Subdomains you may not know are still live
- Step-by-step remediation written for people who are not analysts
I need nothing but the domain. No credentials, no agent, and no code on your site. This is an external assessment, not a penetration test.
Most people order this because a client questionnaire, an insurance renewal, or a new contract asked whether they scan, and they needed a dated report.
Message me with your domain, and I will tell you which tier fits.
Technology:
Cloud - IaaS
•
Mail services
•
Networking
•
Web application
Other Cybersecurity Services I Offer
FAQ
Do you need access to our website or servers?
No. Everything is done from the outside, the same position an attacker starts from. No credentials, no agent, no plugin, no code added to your site. I need your domain and written authorization, nothing else.
Is this a penetration test?
No, and I would not sell you one. This is an external assessment: I identify what your site exposes and rate it by severity. A penetration test means actively exploiting what is found. If that is what you need, hire a firm that does it.
Will the scan slow down or break our site?
No, and I would not sell you one. This is an external assessment: I identify what your site exposes and rate it by severity. A penetration test means actively exploiting what is found. If that is what you need, hire a firm that does it.
What is the difference between this and your vulnerability report review?
This is for when you have no report. I run the scan and produce it. That service is for when your vendor has already sent you one, and nobody can tell you what to fix first. If you already have output, that one is cheaper and faster.
Do we need permission to have our site scanned?
You need to own the domain or have written authorization from whoever does. If your site is on a shared host or managed by an agency, check your agreement. I will ask you to confirm authorization before anything runs.
What do we actually get?
A PDF report with every finding rated by severity, what each one means in plain language, the specific fix, and a prioritized order to work through. Standard adds a 30-minute findings call. Premium adds an executive briefing.
Our developer says the site is secure. Why scan it?
Your developer is right about the code they wrote. Most findings here are not code. Expired certificates, headers that were never set, DNS records left incomplete, a staging subdomain nobody took down. Those accumulate without anyone doing anything wrong.
How many subdomains do you cover?
Basic covers one domain. The Standard plan covers your primary domain plus up to 5 subdomains. Premium maps your full external footprint, including subdomains you may not know are still live. That last category is where the surprises usually are.
Can you fix what you find?
Fixing is your team or your host. I give step-by-step remediation guidance for every finding so they know exactly what to change. If you want the fixes verified afterward, Premium includes a rescan within 45 days.
Does this satisfy PCI compliance?
No. PCI quarterly external scans have to come from an Approved Scanning Vendor, and I am not one. This assessment covers the same technical ground and is useful preparation, but it will not satisfy that specific requirement. Do not order it for that.

