These check one thing at a time. A scan reads your whole repository and tells you what an attacker would find first.