forumNew topic

Free site security scanners gave three different results — which one should we trust?

SSultan A***Member
Job title
QA Tester
Sector
Freight
Organization type
300-person organization
Joined
Aug 2025
Message
143

Doki · KVKK compliance consulting · 2023

#1

Last week, we noticed an odd slowdown on our e-commerce site where we sell wholesale design goods to customers in the US. To check our site—which turns over about 18,000 dollars a month and gets 800-900 unique visitors a day—we ran three popular free site security scanners online. But now we're completely confused because each tool painted an entirely different picture.

The first scanner said the site is completely clean and up to date, while the second reported detecting a suspicious redirect in an external JavaScript file and warned that the site might get blacklisted. The third found no malicious code, but flagged the site as high risk due to the SSL certificate and HTTP headers. This inconsistency between scanners has us seriously worried, since our quote for a full-scope audit from a professional cybersecurity firm is around 1,500 dollars right now, and we want to understand the situation before spending that kind of money.

Which of these contradictory reports from the free scanners should we take seriously? Is it even possible to tell if a site is actually infected with malware using external scanning tools, or what server-side steps do we need to take?

BBetülExpert
Job title
Management consultant
Joined
Oct 2023
Message
164
Most Helpful#2

Short answer: You can't fully trust any free external scanner since they only see your site as an outside visitor; however, if even one of them flagged malicious code, you should treat it as an active breach until proven otherwise. The scanner reporting clean might have simply missed the threat because it can't read server files or databases.

External free scanners only inspect the scanned page's source code, loaded third-party scripts, and public blacklist registries. Malware is usually designed to hide; it serves a clean page to search engine bots or known security scanner IPs, while triggering the payload only for real users or specific browsers. Inspect the JavaScript file flagged by the second scanner immediately using your browser's developer tools and see if it's sending requests to an unknown external domain.

No need to blow a 1,500 dollar consulting budget right away. First, list any core files modified in the last 14 days on the server side, review admin accounts in the database, and filter your server access logs for suspicious POST requests coming from foreign IPs. Once your codebase is audited, it will become clear whether this warning is just from an outdated analytics plugin or an actual injection.

IIrmak V***Member
Job title
Front office accounting
Sector
E-commerce
Organization type
a company within a holding
Joined
Feb 2025
Message
312
#3

The JavaScript alert flagged by the second tool is probably a conditional redirect mechanism. Malicious code usually stays hidden from logged-in admins and only triggers for visitors with a Google referer header. Pull the page source from the terminal using curl with different User-Agent and Referer values. Search the file for suspicious functions like eval, base64_decode, or document.write.

GGökhan A***Member
Job title
Manufacturer · furniture
Joined
Oct 2023
Message
74
#4

Before you panic, check two things right away: First log in to your Google Search Console dashboard and check the Security Issues tab; if Google detected a threat it will be clearly listed there. Second, check the date of your website's last clean backup. If the issue started a few days ago, diffing against a backup is the fastest way to spot it.

RReyhan A***Member
Job title
Digital marketing specialist
Sector
Jewelry
Organization type
regional distributor
Joined
Oct 2024
Message
97
#5

We ignored a similar warning last year because two scanners said it was clean. 48 hours later, our site got hit with a red screen block by the search engine. Our ads stopped running, and we lost about 4,200 dollars in revenue that week. External scanners giving a clean bill of health create a false sense of security; always prioritize the report that flags an infection.

GGürkan U***Member
Job title
Technical service technician
Sector
Retail
Organization type
medium-sized business
Joined
Jan 2023
Message
2
#6

The third scanner marking it as high risk just because of HTTP headers is a typical marketing gimmick. Many free tools blow missing security headers out of proportion making it look like your server is infected just to push their paid plugin. Don't confuse a missing configuration with an active malware infection.

edit: fixed a few typos.

OOsman K***VeteranCommunity member
Joined
Feb 2026
Message
279
#7

definitely don't skip the external script warning imo. it's usually old forgotten hit counters or third-party chat pixels that get compromised and start injecting redirects. check between the head tags in the source code, any foreign domain will stick out like a sore thumb.

ZZehra T***Member
Job title
Operations manager
Sector
Freight
Organization type
early-stage startup
Joined
Apr 2026
Message
68

Doki · Penetration test · 2025

#8

Is your site built on WordPress, or is it custom-coded from scratch? Also, is that suspicious JavaScript file hosted on your own server, or is it being pulled from an external host? If you can share these two details, it’ll be much easier to guide you.

VVeli P***Expert
Job title
Product Manager
Sector
Textile
Organization type
chain store
Joined
Dec 2024
Message
23
#9

To clear up the conflicting reports, follow these steps: 1) Save the full URL of the script file that the second scanner flagged. 2) Open the file's source code on the server and check for unauthorized redirect code. 3) Check its last modified date via FTP or your server control panel. 4) Leave the third tool's certificate and header warnings for later.

BBeren N***Member
Job title
Project manager
Sector
Insurance
Organization type
300-person organization
Joined
Mar 2024
Message
6

Doki · Interface design · 2025

#10

Don't let it get you down, false alarms or minor script injections happen on live e-commerce sites all the time. If you're hesitant to touch the code yourself, just open a ticket with your hosting provider's support team and share the log from the second scanner; they will run an internal server antivirus scan for free.

OOsman A***ExpertCommunity member
Joined
Aug 2025
Message
316
#11

I went through the same thing two years ago. Start with a small trial; don't commit to everything at once.

I'm also curious if anyone does it differently.

DDilekNew member
Job title
Pastry Shop
Organization type
a company within a holding
Joined
Nov 2024
Message
19
#12

i think it's hard to be that definitive about free site security scanner. people defend habits, not processes. resistance coems from there.

KKemal S***Member
Job title
Content Editor
Sector
Sports and fitness
Organization type
a company within a holding
Joined
Jul 2022
Message
1
#13

Do you think this works at any scale? Your time to detect an issue directly determines its cost.

Good luck with that.

OOnur Ç***MemberCommunity member
Joined
Dec 2024
Message
222
#14

We got stuck at the same point for a while. When you try to change everything at once, nothing settles.

Start with a small trial; don't commit to everything at once. This is my opinion, I'm not claiming it's absolute truth.

OOya Ç***Member
Job title
Quality control inspector
Sector
Media and publishing
Organization type
regional distributor
Joined
Oct 2023
Message
248
#15

trhee different views emerged, they all complement each other. like if permission and scope arent in writing dont start that test.

if I were you I'd go this route.

ÖÖzlemMember
Job title
Advertising agency
Organization type
20-person company
Joined
May 2024
Message
108
#16

Correct. The answer varies greatly by industry; there is no one-size-fits-all rule.

I'm also curious if anyone does it differently.

NNeslihan K***Expert
Job title
IT Manager
Sector
Catering
Organization type
chain store
Joined
Jan 2023
Message
40
#17

I completely agree. Forgotten test environments are more often the entry point than live systems.

I'm also curious if anyone does it differently.

CCansu C***MemberCommunity member
Joined
Mar 2022
Message
66
#18

I agree and I'd like to emphasize that. People defend habits not processes. Resistance comes from there.

Proven by experience.

FFerhat O***Member
Job title
Software team lead
Sector
Packaging
Organization type
20-person company
Joined
Sep 2023
Message
52

Doki · Infrastructure migration · 2024

#19

My question might sound amateurish, sorry about that. Your time to detect an issue directly determines its cost.

When making decisions, write down the worst-case scenario too, not just the best. Just leaving this note, it might be useful.

ÜÜmit Ö***Member
Job title
Sales Manager
Sector
Printing
Organization type
medium-sized business
Joined
Nov 2024
Message
108
#20

I'm writing this so you don't make the same mistake. Don't hesitate to ask; those who don't ask always pay more.

That's all, sorry if I went on too long.

Reply