Sucuri SiteCheck asks "has this website already been hacked?" Scan.now asks "is this website easy to hack?" Those are different questions, and you may want both answers.
Think of a house. One tool walks through the rooms looking for someone who already broke in. The other walks around the outside checking whether the windows are locked. Neither one replaces the other.
Already hacked, or not yet?
Use Scan.now to find out why your site is an easy target, which is the question you can still do something about. It checks the certificate, the headers, the cookies, the files that should not be public, the outdated JavaScript, the email records and the WordPress plugins — 179 checks in one pass. Sucuri SiteCheck answers a different question: whether the break-in has already happened.
Two different questions
| Sucuri SiteCheck | Scan.now | |
|---|---|---|
| Main question | Has this site been hacked? | Is this site set up safely? |
| Looks for malware in pages | Yes | No |
| Checks blocklists | Yes, several | Google Safe Browsing, on links |
| Checks headers and TLS | Some | Yes, in detail |
| Checks email spoofing | No | Yes |
| Number of checks | Not published | 179, each documented |
| Sells cleanup and a firewall | Yes | No |
Finding the way in, not the intruder
We tell you how they would get in. A malware scan finds the burglar. It does not tell you the window was unlocked. Out-of-date plugins, a readable .git folder, a JavaScript library with a published CVE and an unprotected admin path are how sites get compromised, and all four are findings here.
We show our working. Every finding names the check, the evidence, the affected URLs and the exact change to make. Nothing is a score you have to trust.
It is the scan you can run before anything is wrong. Malware scanning is reactive by nature — there has to be malware. This is the one you run on a Tuesday, before there is an emergency, and again after you change anything.
What Sucuri sees that we cannot
Sucuri cleans up hacked sites for a living, so their signatures reflect what real infections look like this week, and they check whether Google and others have already blocklisted you. If you think you are infected right now, that is the tool for that hour.
If you think you are infected right now
If something feels wrong this minute, deal with the infection first — that is the emergency. Then run the website scanner to find the way in and close it, because a cleaned site with the same unlocked window gets hit again. On WordPress, run the WordPress scanner as well: out-of-date plugins are the most common route in by a wide margin.
Questions about malware scanning
Can Scan.now tell me if my site has malware?
Not on a website. We scan files you upload to the file scanner for malware, but we do not scan a live site's pages for infection. That is a real gap and we would rather say so than blur it.
My site is on a blocklist. What now?
Get it cleaned first, then ask for a review through Google Search Console. Cleaning it without fixing the way in usually means it comes back.
Is a clean malware scan the same as being safe?
No. It means nobody has broken in yet, or nobody has broken in with something recognisable. It says nothing about how hard breaking in would be.
Also in this series: vs securityheaders.com, passive vs active scanning, vs SSL Labs.