- Job title
- QA Tester
- Sector
- Freight
- Organization type
- 300-person organization
- Joined
- Aug 2025
- Message
- 143
Doki · KVKK compliance consulting · 2023
Last week, we noticed an odd slowdown on our e-commerce site where we sell wholesale design goods to customers in the US. To check our site—which turns over about 18,000 dollars a month and gets 800-900 unique visitors a day—we ran three popular free site security scanners online. But now we're completely confused because each tool painted an entirely different picture.
The first scanner said the site is completely clean and up to date, while the second reported detecting a suspicious redirect in an external JavaScript file and warned that the site might get blacklisted. The third found no malicious code, but flagged the site as high risk due to the SSL certificate and HTTP headers. This inconsistency between scanners has us seriously worried, since our quote for a full-scope audit from a professional cybersecurity firm is around 1,500 dollars right now, and we want to understand the situation before spending that kind of money.
Which of these contradictory reports from the free scanners should we take seriously? Is it even possible to tell if a site is actually infected with malware using external scanning tools, or what server-side steps do we need to take?