How Vulny works
Vulny runs one safe, automated scan that covers three things at once: security, SEO and AI-search (GEO). You enter a website address you own, and Vulny tests it the way an attacker, a search engine and an AI assistant each would — then returns prioritised findings with a plain-language fix for each. Here is what happens at each stage.
How does an external vulnerability scan work?
An external scan looks at your systems from the public internet, exactly as an attacker would before breaking in. Vulny discovers your internet-facing hosts, finds every open port, and fingerprints the service and version behind each one — web servers, mail servers, databases, remote-access services and more. It then matches each service against known vulnerabilities, so you see what an outsider could reach and exploit. No credentials or agents are installed: the scan runs entirely from the outside, which is why you can start one in minutes on any domain or IP you own. This outside-in view is the one that matters most, because it is exactly the surface attackers probe first — every exposed service, including the forgotten subdomain or staging box nobody remembered was still live.
What does the web application scanner check?
Every web service Vulny finds is tested for the issues that most often lead to a breach. That includes the OWASP Top 10 classes — injection, broken access control, security misconfiguration and more — plus exposed sensitive files such as backups, .git directories, and config or environment files, missing or weak security headers, and default pages that should never be public. Detection templates are updated continuously, so the scanner keeps checking for newly published web weaknesses, not just a fixed list from the day it shipped. Each finding comes back with its severity, the affected URL and a plain-language fix, so a developer can reproduce and close it without needing a security specialist. The tests are non-destructive: Vulny confirms a weakness exists without exploiting it or changing your data.
What is shadow-API scanning?
Shadow APIs are endpoints that exist but are not in your documentation — old versions, forgotten admin routes, or services a team shipped without telling anyone. They are a favourite target because no one is watching them. Vulny crawls your application to discover both documented and undocumented API endpoints, then safely fuzzes them for authentication and authorization flaws and injection bugs including SSRF, LFI, SSTI and path traversal. The result is a map of your real API surface — including the parts you forgot you had — and where each one is weak. This matters more every year, because attackers increasingly breach companies through APIs rather than the front-end website, and you cannot defend an endpoint you do not know exists.
How does Vulny check your TLS / SSL configuration?
Vulny inspects the certificate and encryption setup on every service that uses TLS. It flags certificates that are expired, self-signed or issued by an untrusted authority, and configurations that still allow deprecated protocol versions or weak ciphers an attacker could downgrade to. A weak TLS setup quietly undermines everything else, so these checks run on each encrypted port — not just your main website — and tell you exactly what to change. Bad TLS rarely throws an obvious error, which is why it goes unnoticed for years: the site still loads and the padlock still shows, but the connection can be intercepted or downgraded. Vulny surfaces those silent weaknesses with the specific certificate, protocol or cipher to fix.
How does Vulny match vulnerabilities to CVEs?
Once Vulny knows the software and versions you run, it matches them against a detection database of 357,755+ vulnerability tests. Each match is enriched with its CVSS severity, whether it is on the CISA KEV list of vulnerabilities known to be exploited in the wild, its EPSS probability of exploitation, and any public exploit code. That context is what turns a long list into a short one: instead of a thousand theoretical issues, you get the handful that are genuinely dangerous for you, ranked first. The database refreshes every two hours, so you are re-checked against brand-new CVEs the same day they are disclosed. Because matching uses the precise versions Vulny fingerprinted, it avoids the false positives that plague generic scanners, which flag a CVE on every host running roughly the right product regardless of version.
How does the SEO audit work?
In the same pass, Vulny checks how ready your pages are to rank on Google. It loads each page the way a search engine does and reviews the signals that decide visibility — from how crawlable and fast the page is to how clearly it tells Google what it is about. You get a single SEO score with the specific issues holding you back and a plain-language fix for each, so you can climb the rankings without hiring an SEO agency. The point is simple: the most secure website in the world still fails if customers can’t find it on Google, so security and findability belong in one scan, not two tools.
How does the AI-search (GEO) audit work?
Buyers increasingly ask ChatGPT, Perplexity and Google’s AI for recommendations instead of scrolling a results page — and those engines only quote pages they can read and trust. Vulny’s GEO (Generative Engine Optimisation) audit checks whether your site is visible and quotable to AI assistants, then scores how likely you are to be cited and tells you what to improve. This is the newest front in being found online, and most of your competitors aren’t watching it yet — which is exactly why it’s an advantage to fix now. Security, SEO and AI-search, one scan, one report.
What does a typical scan find?
A first scan of a small business website often surfaces a handful of real issues: an out-of-date web server with a known CVE, a couple of missing security headers, an exposed backup or .git folder, and a TLS configuration still allowing an old protocol. Each finding comes with its severity, the affected host and port, and a plain-language fix. You can export the whole assessment as a branded PDF or editable DOC report — ready for an auditor, a client, or your own engineers to work through. Crucially, the findings are ranked by real-world risk rather than dumped as an undifferentiated list, so you spend your time on the one or two issues an attacker would actually use, not on a hundred low-priority notes.
Is scanning safe and non-disruptive?
Vulny is built to be non-destructive: it identifies and verifies weaknesses without exploiting them, deleting data or taking services offline. Scans are rate-aware so they do not overload your servers, and you may only scan assets you own or are authorised to test — Vulny verifies domain ownership before the first scan of any new target. That makes it safe to run continuously in the background rather than only during a scheduled maintenance window. You get the same depth of testing an attacker would attempt, but without the risk to availability or data integrity that a real intrusion — or a reckless scanner — would carry, which is what makes always-on scanning practical instead of a once-a-year event.
See it on your own site
Run one scan for security, SEO and AI-search (GEO) — and get a branded, ISO 27001 ready PDF report.
Scan my site →