Skip to content
Security scan

A daily security check for every website you run

Outdated software is the most common way small websites get hacked. Helicopterview scans every site daily and tells you exactly what to update, before someone else finds it.

No credit card. Nothing to install.

Example from the fix list

kade-interieur.nl
WordPress 6.6.2 is out of date (latest is 6.8.3) High Security

This is a full release behind. Outdated WordPress is the most common way small sites get hacked.

Installed
6.6.2
Latest
6.8.3
How to fix · Back up, then update WordPress core, plugins and theme. Turn on automatic minor updates.
What we check

Everything security scan covers

Outdated WordPress core

We compare the installed version with the latest release and flag sites that fall behind.

End-of-life PHP

PHP versions that no longer get security patches, visible through server headers.

Vulnerable libraries

Old jQuery versions with known cross-site scripting issues, and other libraries we can detect.

Security headers

HSTS, X-Frame-Options or frame-ancestors, X-Content-Type-Options and Content-Security-Policy.

HTTPS everywhere

Whether http:// redirects to https://, and whether pages load insecure mixed content.

Version leaks

Server and generator headers that tell attackers exactly which version to target.

Why it matters

Small problems, big consequences

Automated bots scan the internet for known weak spots all day. A WordPress site that is one release behind, or a server still running PHP 7, is an easy target. A daily scan across your whole portfolio means no site is quietly left behind.

  • Part of one daily scan that also covers availability, security, speed, search, email and tracking.
  • Findings are ranked by impact across all your sites, so you always know what to do first.
  • Every finding explains why it matters and exactly how to fix it.

Frequently asked questions

Is this a penetration test?

No. We check what is visible from the outside, without logging in or attacking anything. It catches the most common, most exploited problems.

Does it work for sites that aren’t WordPress?

Yes. Headers, HTTPS, PHP versions and libraries are checked on every site. WordPress-specific checks run when we detect WordPress.

How do I fix what you find?

Every finding comes with a concrete fix, for example the exact setting in WordPress or DirectAdmin.

Will scanning slow down my site?

No. A daily scan is a handful of normal page requests, like one visitor.

See your sites from above

Scan one site free right now, or start a 14-day trial and add them all.