Network security · nmap · Security Pro
What is nmap? Network scanning for website owners
Published
What is nmap?
Nmap (Network Mapper) is an open-source network scanning tool used to discover hosts, open ports, and services on a network. Security teams run nmap scans to see what is exposed to the internet before an attacker does.
A typical nmap port scan answers questions like: Is SSH open to the world? Is an old database port reachable from outside the firewall? Did a staging server accidentally get a public IP?
nmap software vs a website QA audit
Nmap looks at your network surface — ports and services. A website QA audit looks at your HTTP surface — broken links, SEO metadata, HTTPS, mobile viewport, and accessibility basics on crawled pages.
Both matter for security and quality assurance, but they answer different questions. You can have a perfect Lighthouse score and still expose MySQL on port 3306. Pair network scanning with an SSL certificate check so TLS issues show up alongside open ports.
When to run a network scan
Run an nmap-class scan after launch, after infrastructure changes, or when compliance asks for evidence of external attack surface. Pair it with DNS verification so you only scan hosts you control.
QA Audit Security Pro includes an automated network slice with human-readable findings — not a replacement for a full penetration test, but a fast way to catch obvious exposure before it becomes an incident. See our network scanner overview for scope and framing.
