Free website security scan: what the grade means
Campus and agency web teams want a free website security scan before they change DNS. What does the grade actually measure? Is a website vulnerability scan with no signup the same as a pentest? What should you do after an F grade on a WAF scan report? This is the straight read for higher-ed web/IT, public-sector teams, and agencies: what the passive scan checks (headers and exposure style), how to read the report, and the calm Protect {domain} → 14-day trial path — count-first, not day-one deny theater.
What the free scan is (and is not)
The free passive scan at /scan grades a public hostname. No signup required: enter a domain, get a letter grade and a short explanation.
It is not a pentest, exploit run, authenticated assessment, CMS CVE dump, or a promise that an A means “never get attacked.”
It is a fast, passive posture check: Is there evidence of a managed shield in front? Are important security headers present? Does the public surface look exposed in ways a WAF edge usually hardens?
Treat it as a WAF scan report grade — a before picture for central IT, a CIO, or an agency NOC — not a red-team binder.
What the scan checks (headers / exposure style)
The report focuses on passive signals visible from the public internet. Scores combine those signals into a letter grade. An A typically means a shield is in front and the important headers are present. A weak grade usually means missing headers, no managed shield detected, or both — not an invented CVE list.
TLS issues and public software leaks can also pull a grade down. We do not invent scores for named campuses here. Run your domain on /scan and read your report.
| Check style | What you learn | Why operators care |
|---|---|---|
| Security headers | HSTS, framing / MIME sniffing controls, referrer and permissions posture, related response headers | Missing basics show up as a weak grade even when the CMS “feels fine” |
| Edge / shield signals | Whether a managed shield appears to sit in front of the site | Separates “headers only” from “traffic already hits an edge” |
| Exposure-style posture | Public surface clues that matter before DNS cutover, including TLS and leaked server software when present | Useful before you decide whether to trial a managed WAF |
How to read an F grade (without scare spam)
An F on a ProtectMyWebsite report is a soft signal, not a breach notice.
Common operator meaning:
1. No managed shield detected — public traffic may still hit origin-style hosting without a ProtectMyWebsite-style edge in front.
2. Important security headers missing or incomplete — HSTS, framing / MIME controls, and related headers that a hardened edge usually sets.
3. The site can still be “up” and useful — grades measure posture signals, not uptime or content quality.
What an F is not: proof you were compromised, a mandate to yank DNS tonight, or a reason to flip deny packs on day one.
Protect website after F grade scan is the practical next question. The report’s soft, domain-aware CTA — Protect {domain} — start 14-day trial — sends you to /signup with the domain ready. Trial CTAs can carry scan-report UTMs; the path stays signup → DNS → count → promote.
Many departmental properties: Talk to sales team for Campus Estate. No Estate dollar amounts on this page.
Protect {domain} → 14-day trial (accurate path)
The funnel is intentional and short:
1. Scan at /scan — free, no signup required for the grade.
2. Read the report — grade, headers/shield signals, plain-language summary.
3. Protect {domain} — primary CTA into /signup with the domain prefilled when available.
4. 14-day trial — card at Stripe at checkout; self-serve is $150/site/month after — see /pricing.
5. DNS cutover — point the public hostname at the edge (self-serve or concierge). Hosting and CMS stay put.
6. Count → promote — managed rules start in count. After ~24 hours the dashboard shows what’s safe; you still click once. Promote Copilot recommends Promote, Hold, or Needs allowlist — it does not auto-block.
Full go-live path: Managed WAF setup. Promote language: What's safe to block on a WAF.
You can stop after the free report. The trial is optional; the scan is not a gated unlock or a scare drip.
Why count-first after you shield
Campus and agency forms punish block-first rollouts. Admissions POSTs, citizen uploads, CMS editors, IdP/LMS callbacks — all look “noisy” to aggressive packs on day one.
After Protect {domain}:
Day 0: DNS live, SSL at the edge — traffic through the managed firewall, still in count.
~First 24 hours: Managed rules for injection, XSS-class noise, known exploit patterns, bad bots, malicious IPs, plus useful rate limits — all start in count. Matches log; no deny yet.
After ~24 hours: Dashboard shows what’s safe. Copilot explains; you still click once.
Ongoing: New noise lands in count until you promote.
An F grade should mean observe first, not “flip DNS and hope deny is quiet.” See DIY WAF vs managed if you are still weighing console vs operator.
Who this scan is for
Share a passive grade before campus DNS talks, agency FOIA-heavy reviews, or a client-site proposal. Single-site owners can use it as a before picture, then self-serve trial if they want a shield.
| Audience | Why it helps | Next step |
|---|---|---|
| Higher-ed web/IT | Share a passive grade before campus DNS talks | Higher education · Protect or Talk to sales team |
| Government / agency | Posture story for public and FOIA-heavy sites | Government · trial or Talk to sales team |
| Agencies / multi-site | Grade a client hostname before proposing edge | DIY vs managed · count-mode go-live |
| Single-site owners | Before picture, then self-serve trial if you want a shield | Signup · pricing |
FAQ
Is the free website security scan really no signup? Yes. Run a domain on /scan and open the report without creating an account. Signup is only for the 14-day trial when you choose Protect {domain}.
Is this a website vulnerability scan or a pentest? Neither in the classic sense. It is a passive headers-and-exposure-style posture grade plus shield signals — not authenticated testing, exploit PoCs, or a CMS CVE dump. Use it as a before picture before DNS, not a scoped assessment substitute.
What does an F grade mean on the WAF scan report? Usually no managed shield detected and/or important security headers missing. It is not a breach notice. Soft next step: Protect {domain} for a count-first trial, or fix headers yourself if you already run an edge. We do not invent scores for named schools on this page — scan your domain.
What happens after Protect {domain}? You go to /signup (domain prefilled when available), start the 14-day trial (card at Stripe), point DNS at the edge, and rules start in count. After ~24 hours the dashboard shows what’s safe; Copilot explains Promote / Hold / Needs allowlist — no auto-block. Details: Managed WAF setup.
How much is self-serve, and when do we Talk to sales? Self-serve is $150/site/month with a 14-day trial — see /pricing. Many departmental properties or mixed DNS ownership: Talk to sales team for Campus Estate (no Estate dollar amounts here). Copilot is included on self-serve and estate paths.
Start here
ProtectMyWebsite’s free scan is a passive grade — headers and exposure style, no signup wall — then an optional Protect {domain} path into a count-first 14-day trial. Soft CTA, human promote, no auto-block.
Related
- All guides
- Managed WAF setup: DNS cutover to count mode
- What is WAF count mode? (and why you start there)
- What's safe to block on a WAF?
- DIY WAF vs managed: console burden or operator?
- HTTP security headers, explained
- Managed WAF pricing: is $150/site worth it?
- Pricing
- WAF for higher education
- WAF for government
- Free security scan
- Start a 14-day trial