Beyond disk space
Malware protection
There is no scanner, and there will not be one. What you get instead is your Mac's own security state, read out and dated — a measurement you can check rather than a claim you have to trust.
Why not a scanner
A scanner is only as good as the threat feed behind it, and a feed is paid for every month for as long as the app exists. A one-time price cannot fund one. The honest choices are a subscription, or no scanner — and a scanner whose definitions quietly stopped updating is worse than none at all, because it still reports that it found nothing.
There is a second reason. macOS already runs one, for free, and has since Yosemite. Selling a second one means either a better feed than Apple's — which is a real business, not a feature — or duplicating something already there.
What the app reports instead
The Maintenance screen carries a row with no Run button, because there is nothing to run. It reads your Mac and says:
- The XProtect definition version and when macOS last installed it — taken from the system's own install history, not from the bundle's modification date, which moves for reasons that have nothing to do with the signatures.
- The XProtect Remediator version, which is the part that removes families Apple already knows about.
- Whether Gatekeeper is on, so an accidentally disabled Mac says so out loud.
Every one of those is checkable against Apple's own records. That is the difference between a measurement and a reassurance.
When a real scanner is still worth having
XProtect knows what Apple has seen. It is signature-based, so a genuinely new family can run for a while before it is covered, and it does not scan files you are forwarding for somebody else's benefit — a Windows macro, for instance. There are jobs where a real scanner with a real feed earns its subscription. It is just not something a disk cleaner should pretend to be, and a one-time price could not pay for it anyway.