SSL certificates · Web Inspector · scanning, not certificates

Web Inspector

Find the malware on your site and get it removed

Web Inspector is a scanning service, not an SSL certificate. It crawls your site on a schedule, looks for malware, defacement and known vulnerabilities, and tells you what it found and where. If you came here for HTTPS and a padlock, this is the wrong page and the link below is the right one.

  • Scanning service, not a certificate
  • Scheduled automatic scans
  • Blocklist monitoring
  • PCI options available
  • 4 products, from $110

What this actually is

Web Inspector is Sectigo’s website scanning product, sold under the Comodo name for most of its life. It does not encrypt anything and it does not affect the padlock in a browser. What it does is check whether your site is serving malware, whether it has been defaced, and whether it has been added to a search engine or antivirus blocklist — the things you generally find out about from an angry customer rather than from your own monitoring.

Sold by
Sectigo, formerly branded Comodo
What it does
Scheduled malware, defacement and vulnerability scanning
What it is not
Not an SSL certificate — it will not put a padlock on your site
Reports
Findings by URL, with blocklist status

Looking for an SSL certificate instead? Sectigo certificates start at a few pounds a year, or compare every certificate by what it covers.

  • Lowest price guaranteeFind the same plan cheaper anywhere and we match it.
  • Scans run on a scheduleYou are told what changed, not left to check by hand.
  • Reports name the URLSo your developer has somewhere to start rather than a score.
  • Free setup supportWe get the first scan running and the reports going to the right inbox.

What scanning is for

A certificate protects traffic in transit. It does nothing whatever about a compromised site, which is a separate problem with separate consequences.

  • Being blocklisted is worse than being downOnce a search engine flags a site as harmful, visitors get an interstitial warning instead of your page, and getting the flag removed takes far longer than the compromise took to happen.
  • Most compromises are quietInjected code that redirects mobile visitors or skims a checkout is written to be invisible to the site owner. Scheduled scanning is how you find out without waiting for a complaint.
  • HTTPS does not help hereA certificate encrypts the connection. It cannot tell whether the page at the other end has been altered, which is why these are sold separately.
  • Some card processing asks for itIf your processor requires quarterly scanning to keep card processing enabled, the PCI options in this list are the ones that produce the report they want.

Is this the right brand for you?

A brand name in a requirement is worth following. A brand name you picked because you recognised it usually is not, and the second list is a route out rather than a dead end.

Buy from this brand if

  • You want to know if your site starts serving malware before your customers do
  • You have been blocklisted before and would rather not repeat it
  • A card processor has asked you for scanning evidence
  • You run a site you do not log into every day

Look at this instead if

If you would rather not read a price list

Three out of the 4 below, chosen for the three reasons people actually buy on. Every price, warranty and specification here is read from the catalogue, so it is what the cart will charge.

  • Our pick

    Web Inspector Starter Anti-Malware

    The entry-level plan, and enough for a brochure site or a small shop. Scheduled scanning with reporting on what was found and where, without the enterprise reporting nobody reads.

    • Not a certificatescanning service
    • Scheduled scans · reports name the URL
    $110 $149 save 26% per year
    Full specification →
  • Busier sites

    Comodo Website Inspector Plus

    More frequent scanning and deeper coverage for a site that changes often or takes payments, where a week between scans is too long a gap.

    • Not a certificatescanning service
    • Scheduled scans · reports name the URL
    $172 $179 save 4% per year
    Full specification →
  • Most thorough

    Comodo Web Inspector Premium

    The premium tier, for sites where a compromise would be expensive and the reporting has to satisfy somebody other than you.

    • Not a certificatescanning service
    • Scheduled scans · reports name the URL
    $287 $299 save 4% per year
    Full specification →

Every Web Inspector product we sell, cheapest first

All 4 of them, grouped by what the product actually is and sorted by price inside each group. Any price is a buy button — it opens the same order card as the product page.

Scanning and trust marks

4 products

Services that check a site for malware, defacement and known vulnerabilities on a schedule. These are not certificates and will not put a padlock on your site.

Product Validation Covers Warranty Issued in From
Web Inspector Starter Anti-Malware Not a certificatescanning service 1-3 Days $110 $149
Comodo Website Inspector Plus Not a certificatescanning service 1-3 Days $172 $179
Comodo Web Inspector Premium Not a certificatescanning service 1-3 Days $287 $299
Comodo Web Inspector Enterprise Daily Scan Not a certificatescanning service 1-3 Days $518 $539

Prices are for one year. Most certificates can be bought for two, which is the longest term the industry rules allow to be sold — the saving is shown on the product page.

Questions we get asked about Web Inspector

Is Web Inspector an SSL certificate?

No. It is a scanning service. It will not encrypt your site, it will not put a padlock in the address bar and it will not stop a browser warning about an insecure connection. For that you need an SSL certificate.

Do I need this if I already have an SSL certificate?

They solve different problems. A certificate protects data moving between the visitor and your server; scanning tells you whether your server is serving something it should not be. Sites that take payments generally want both.

What happens if it finds something?

You get a report naming the affected URLs and what was detected, so you or your developer can remove it. Scanning identifies the problem; fixing the site is a separate job.

Will it get me off a blocklist?

It helps you find and remove the cause, which is what a blocklist removal request needs. The removal itself is requested from whoever applied the listing.

Does this satisfy PCI scanning requirements?

The PCI options in this list produce the quarterly external scan report that card processors ask for. If you are not certain which requirement applies to you, send us what your processor asked for and we will tell you which product answers it.

The other authorities we sell

This is the only scanning-only brand on the site. Everything else listed here issues certificates.

Not sure this is the brand you were told to buy?

Send us the requirement — the line from the tender, the audit finding or your host’s documentation — and we will tell you which certificate satisfies it and what the cheapest one that does costs. Including when that is not the brand you are looking at. No obligation and no sales call.