SSL certificates · Web Inspector · scanning, not certificates
Find the malware on your site and get it removed
Web Inspector is a scanning service, not an SSL certificate. It crawls your site on a schedule, looks for malware, defacement and known vulnerabilities, and tells you what it found and where. If you came here for HTTPS and a padlock, this is the wrong page and the link below is the right one.
- Scanning service, not a certificate
- Scheduled automatic scans
- Blocklist monitoring
- PCI options available
- 4 products, from $110
What this actually is
Web Inspector is Sectigo’s website scanning product, sold under the Comodo name for most of its life. It does not encrypt anything and it does not affect the padlock in a browser. What it does is check whether your site is serving malware, whether it has been defaced, and whether it has been added to a search engine or antivirus blocklist — the things you generally find out about from an angry customer rather than from your own monitoring.
- Sold by
- Sectigo, formerly branded Comodo
- What it does
- Scheduled malware, defacement and vulnerability scanning
- What it is not
- Not an SSL certificate — it will not put a padlock on your site
- Reports
- Findings by URL, with blocklist status
Looking for an SSL certificate instead? Sectigo certificates start at a few pounds a year, or compare every certificate by what it covers.
- Lowest price guaranteeFind the same plan cheaper anywhere and we match it.
- Scans run on a scheduleYou are told what changed, not left to check by hand.
- Reports name the URLSo your developer has somewhere to start rather than a score.
- Free setup supportWe get the first scan running and the reports going to the right inbox.
What scanning is for
A certificate protects traffic in transit. It does nothing whatever about a compromised site, which is a separate problem with separate consequences.
- Being blocklisted is worse than being downOnce a search engine flags a site as harmful, visitors get an interstitial warning instead of your page, and getting the flag removed takes far longer than the compromise took to happen.
- Most compromises are quietInjected code that redirects mobile visitors or skims a checkout is written to be invisible to the site owner. Scheduled scanning is how you find out without waiting for a complaint.
- HTTPS does not help hereA certificate encrypts the connection. It cannot tell whether the page at the other end has been altered, which is why these are sold separately.
- Some card processing asks for itIf your processor requires quarterly scanning to keep card processing enabled, the PCI options in this list are the ones that produce the report they want.
Is this the right brand for you?
A brand name in a requirement is worth following. A brand name you picked because you recognised it usually is not, and the second list is a route out rather than a dead end.
Buy from this brand if
- You want to know if your site starts serving malware before your customers do
- You have been blocklisted before and would rather not repeat it
- A card processor has asked you for scanning evidence
- You run a site you do not log into every day
Look at this instead if
- You actually need HTTPS and a padlockSSL certificates
- You want a certificate that includes scanningCertificates with scanning
- You are not sure which you needAsk us
If you would rather not read a price list
Three out of the 4 below, chosen for the three reasons people actually buy on. Every price, warranty and specification here is read from the catalogue, so it is what the cart will charge.
-
Our pick
Web Inspector Starter Anti-Malware
The entry-level plan, and enough for a brochure site or a small shop. Scheduled scanning with reporting on what was found and where, without the enterprise reporting nobody reads.
- Not a certificatescanning service
- Scheduled scans · reports name the URL
$110Full specification →$149save 26% per year -
Busier sites
Comodo Website Inspector Plus
More frequent scanning and deeper coverage for a site that changes often or takes payments, where a week between scans is too long a gap.
- Not a certificatescanning service
- Scheduled scans · reports name the URL
$172Full specification →$179save 4% per year -
Most thorough
Comodo Web Inspector Premium
The premium tier, for sites where a compromise would be expensive and the reporting has to satisfy somebody other than you.
- Not a certificatescanning service
- Scheduled scans · reports name the URL
$287Full specification →$299save 4% per year
Every Web Inspector product we sell, cheapest first
All 4 of them, grouped by what the product actually is and sorted by price inside each group. Any price is a buy button — it opens the same order card as the product page.
Scanning and trust marks
4 productsServices that check a site for malware, defacement and known vulnerabilities on a schedule. These are not certificates and will not put a padlock on your site.
| Product | Validation | Covers | Warranty | Issued in | From | |
|---|---|---|---|---|---|---|
| Web Inspector Starter Anti-Malware | — | Not a certificatescanning service | — | 1-3 Days |
$110
|
|
| Comodo Website Inspector Plus | — | Not a certificatescanning service | — | 1-3 Days |
$172
|
|
| Comodo Web Inspector Premium | — | Not a certificatescanning service | — | 1-3 Days |
$287
|
|
| Comodo Web Inspector Enterprise Daily Scan | — | Not a certificatescanning service | — | 1-3 Days |
$518
|
Prices are for one year. Most certificates can be bought for two, which is the longest term the industry rules allow to be sold — the saving is shown on the product page.
Questions we get asked about Web Inspector
Is Web Inspector an SSL certificate?
No. It is a scanning service. It will not encrypt your site, it will not put a padlock in the address bar and it will not stop a browser warning about an insecure connection. For that you need an SSL certificate.
Do I need this if I already have an SSL certificate?
They solve different problems. A certificate protects data moving between the visitor and your server; scanning tells you whether your server is serving something it should not be. Sites that take payments generally want both.
What happens if it finds something?
You get a report naming the affected URLs and what was detected, so you or your developer can remove it. Scanning identifies the problem; fixing the site is a separate job.
Will it get me off a blocklist?
It helps you find and remove the cause, which is what a blocklist removal request needs. The removal itself is requested from whoever applied the listing.
Does this satisfy PCI scanning requirements?
The PCI options in this list produce the quarterly external scan report that card processors ask for. If you are not certain which requirement applies to you, send us what your processor asked for and we will tell you which product answers it.
The other authorities we sell
This is the only scanning-only brand on the site. Everything else listed here issues certificates.
-
The largest commercial authority there is. Was Comodo CA until 2018.
-
The same certificates under the name they were sold under before the rename.
-
Polish authority in every root store. The cheapest EV and S/MIME on this site.
-
A DigiCert brand. Mid-market, and the name most hosting panels still list.
-
A DigiCert brand, and one of the oldest names in the business.
-
A DigiCert brand. Domain validated only, and priced for one small site.
-
Legacy listings. The business became DigiCert in 2017 and the brand is retired.
-
Malware and PCI scanning from Sectigo. Not an SSL certificate. You are here
Not sure this is the brand you were told to buy?
Send us the requirement — the line from the tender, the audit finding or your host’s documentation — and we will tell you which certificate satisfies it and what the cheapest one that does costs. Including when that is not the brand you are looking at. No obligation and no sales call.