Free security tool

Nmap Output Risk Explainer: Turn Scan Results into a Fix List

Paste your Nmap output and this free tool rates every open port, explains why it matters, and tells you what to do about it. It reads normal, grepable and XML output, runs entirely in your browser, and sends nothing anywhere.

  • Free
  • No signup
  • Runs in your browser
  • Text, grepable and XML
  • File upload
Where did you scan from?
Runs in your browser; nothing you paste or upload is sent to ScanTitan. Ratings are guidance based on port, service and banner text, not proof of a vulnerability. The example is made up and uses a reserved documentation address. Only scan systems you own or have written permission to test.

How it works

  1. 1Paste the outputPaste Nmap output or upload the file. Choose whether you scanned from outside or inside.
  2. 2Get a rating per portEach open port gets a severity, a plain-English reason and a fix, plus script findings.
  3. 3Fix the top three firstA short priority list, a CSV, and links to generate the firewall commands.

How to get Nmap output for this tool

Run Nmap with service detection and save the result to a file, then paste or upload it. Only scan systems you own or have written permission to test.

nmap -sV -oN scan.txt 203.0.113.10
nmap -sV -oX scan.xml 203.0.113.10
nmap -sV --script "smb-protocols,smb-security-mode,smb-vuln-ms17-010,ftp-anon,ssl-cert,ssl-enum-ciphers" -oN scan.txt 203.0.113.10

The first two give you the ports and service versions. The third adds the script results that this tool also reads, such as SMBv1, SMB signing, anonymous FTP, expired certificates and old TLS versions. Use a documentation address like 203.0.113.10 only as an example, and replace it with your own target.

How the risk rating works

The same open port gets a different rating depending on where you scanned from, because an exposed database on the internet is an emergency and the same database on a private network is normal. The table shows how the tool rates common services.

Port Service Scanned from outside Scanned from inside
445/139SMB file sharingCriticalMedium
3389Remote Desktop (RDP)CriticalMedium
23TelnetHighHigh
21FTPHighMedium
22SSHMediumLow
5900/5901/5902/5903VNC remote desktopHighMedium
5985/5986WinRM remote managementHighMedium
1433Microsoft SQL ServerCriticalMedium
3306MySQL / MariaDBCriticalMedium
5432PostgreSQLCriticalMedium
1521Oracle database listenerCriticalMedium
6379RedisCriticalHigh
27017/27018MongoDBCriticalHigh
9200/9300ElasticsearchCriticalHigh
11211MemcachedCriticalMedium
2375Docker API (unencrypted)CriticalHigh
161SNMPHighMedium
389LDAPHighLow
636LDAP over TLSMediumInfo
135Windows RPC endpoint mapperHighLow
2049NFS file exportsHighMedium
111rpcbindMediumLow

Ports that are not in the list get a low rating and a prompt to confirm what runs there. Web ports 80 and 443 are rated as info, because they are normal on a web server.

What the tool looks for beyond open ports

It reads Nmap script output and version banners and adds findings to the port they belong to, and it raises the rating when something is wrong.

  • SMB: SMBv1 enabled, SMB signing not required, and the MS17-010 (EternalBlue) check.
  • FTP: anonymous login allowed.
  • TLS: expired certificates, and support for SSLv3, TLS 1.0 or TLS 1.1.
  • Old software: end-of-life Windows, IIS, Apache 2.x, PHP 5, Samba 3 and old MySQL banners, plus the vsftpd 2.3.4 backdoor release.
  • CVE IDs: any CVE named in the output is collected and can be sent to the CVE Priority Checker to see which to patch first.

What to do with the results

Fix the critical and high items first, then close what is not needed, then confirm from outside that the change worked.

  1. Close exposed services that nobody outside needs. The Port Exposure Fix Generator writes the firewall commands for Windows, Linux and the major clouds.
  2. Restrict the services that must stay open to the addresses that need them, and harden them (keys, MFA, current versions).
  3. Patch the CVEs in the output in order of exploitation risk.
  4. Rescan from outside your network and compare the new output with the old.

Our guide to the port 445 vulnerability walks through one of the most common findings in detail.

Limits of this tool

It rates what Nmap saw, so it can only be as good as the scan you give it. A version warning can be wrong when a distribution backports fixes, and a banner can be changed. It does not test whether a service is actually exploitable, and it cannot see ports that were not scanned.

Frequently asked questions

Which Nmap output formats does this tool read?It reads normal text output (the default, or -oN), grepable output (-oG) and XML output (-oX). Paste the output or upload the file. XML gives the most reliable results because every field is labelled.
Is an open port always a vulnerability?No. An open port is a service you chose to run, and many are meant to be open, such as 80 and 443 on a web server. The risk depends on whether the service needs to be reachable from where the scan ran, how it is configured, and whether it is patched. That is why the tool rates the same port differently for an internet-facing scan and an internal one.
Why does the severity change between external and internal?A database or file-sharing port that is exposed to the internet is an emergency, while the same port on an internal network is normal and mainly needs hardening. Choose External for scans from outside your network and Internal for scans of private ranges. The tool switches to Internal automatically when every host is a private address.
What do open, closed and filtered mean?Open means a service answered. Closed means the host replied that nothing is listening. Filtered means a firewall dropped the traffic, so Nmap cannot tell. The tool analyses open ports and ignores closed and filtered ones. For UDP, open|filtered means Nmap could not tell, so it is shown as low.
How accurate are the version warnings?They match on the banner text Nmap reports, so they can be wrong. Some Linux distributions keep an old version number while backporting security fixes, and a banner can be changed. Treat a version warning as a reason to check, not proof.
Is my scan data uploaded?No. The tool runs in your browser and nothing you paste or upload is sent to ScanTitan or anyone else.
Can I scan any server with Nmap?No. Only scan systems you own or have written permission to test. Unauthorised scanning can be illegal, and it can set off alarms or disrupt fragile devices.

Nmap shows one moment in time. Keep watching your exposed ports automatically.

Run a free network scanSee pricing