Guides · 7 min read
Vulnerability scan vs code audit vs pentest: which one does your app need?
“Is my app secure?” can mean three very different checks. They don’t look at the same things, don’t cost the same, and don’t answer the same question. Here’s how to pick the right one.
The short version
| Vulnerability scan | Code audit | Pentest | |
|---|---|---|---|
| Looks at | Your live app, from the outside | Your source code and database rules | Your live app, attacked by a human |
| How | Automated, passive checks | Reading the code, with tools and reviewers | Active attacks by security specialists |
| Time | Seconds to minutes | Minutes to days | Days to weeks |
| Best for | A quick first check | Finding the flaws that matter, with fixes | Compliance and enterprise requirements |
Vulnerability scan: the outside view
A vulnerability scan looks at what anyone on the internet can see from your URL: security headers, your HTTPS certificate, files that shouldn’t be public (.env, .git, source maps) and secrets shipped in your JavaScript.
It’s great for: a fast, free first check, and for catching embarrassing leaks such as an API key in your front-end.
It misses: almost everything that happens on your server — who can read which rows of your database, whether your API checks who is calling, what’s in your Git history. A clean scan is not a clean app.
Code audit: the inside view
A code audit reads your source code. A security-focused audit (often called a secure code review) checks authentication, authorisation, database rules, secrets, injections and dependencies. A full code audit also looks at architecture and code quality.
It’s great for: apps built quickly — with AI tools, a freelancer or a small team — before launch, before fundraising, or when you inherit code. Because it reads the code, it can tell you exactly which file and line to change.
It misses: problems that only exist in the live environment, such as a misconfigured server or a third-party service. A good report says clearly what was and wasn’t checked — here’s what ours looks like.
Penetration test: the attacker’s view
In a pentest, security specialists actively try to break into your running app, the way a real attacker would, within an agreed scope. It’s the most realistic test, and the most expensive. I haven’t commissioned one for my own apps, but the quotes I’ve looked at for a small web app sat between $3,000 and $5,000, before weeks of scheduling.
It’s great for: companies whose customers or certifications require a pentest report, and for mature products that have already fixed the basics.
It’s overkill when: your app has never been reviewed. Paying specialists to find an open database table is an expensive way to discover what a code audit would have shown for a fraction of the price.
What my own mistakes say about it
In ten years of shipping apps, the serious problems I’ve caught in my own work were all simple: a database table pushed without access rules, a Supabase service key shipped in plain text, Stripe secret keys left in the front-end by an AI builder (that one cost me a Stripe account).
None of them needed a pentest. A scan of the live URL would have caught the two leaked keys, because they were sitting in public JavaScript. Only reading the code would have caught the open table. That’s the order I’d follow for any young app: scan, then audit, and a pentest only once the basics are fixed.
So which one do you need?
- You just shipped and want a quick sanity check: start with a vulnerability scan.
- You have real users, payments or personal data: get a code audit.
- An enterprise client or a compliance framework asks for a pentest: hire a pentest firm — ideally after a code audit, so they don’t bill you for the easy findings.
What ScanMyApp does (and doesn’t)
We do the first two. Our free vulnerability scan checks your live URL passively, and our code audits read your repository, from a $99 AI audit to a full audit with a senior engineer — all at fixed prices. We don’t run penetration tests or certify compliance: we only sell what we can deliver with certainty.
Not sure where your app stands? Run the free scan — it takes seconds and needs no signup.
