Pricing
Free to scan. Pay for depth and active testing.
Every scan is graded against CVSS 3.1, CWE, and OWASP Top 10 — no black-box scores. Paid plans add deep crawls, and Advanced unlocks authorized active testing on domains you've verified you own.
Free
Quick checks and solo use
Pro
PopularFreelancers and small teams
Advanced
Active testingSecurity teams and agencies
Enterprise
Platforms and marketplaces
| Feature | Free | Pro | Advanced | Enterprise |
|---|---|---|---|---|
| Scanning | ||||
| Scans per day | 5 | 20 | Unlimited | Unlimited |
| Instant scan | ||||
| Deep multi-page crawl | ||||
| All scan types (cyber, quantum, GEO, AI, blockchain) | ||||
| Security findings | ||||
| CVSS 3.1 · CWE · OWASP-graded findings | ||||
| CVE correlation (OSV live feed + curated KB) | ||||
| Deep passive engines (cipher enum, exposure, takeover) | ||||
| Active testing on verified domains (XSS · SQLi · SSRF) | ||||
| Remediation plans + full technical evidence | ||||
| Reporting & workflow | ||||
| Saved report history | ||||
| PDF export | ||||
| Shareable report links | ||||
| Priority processing | ||||
| Platform | ||||
| Bulk URL API + evidence-level JSON | ||||
| SSO / SAML | ||||
| SLA & dedicated rate limits | ||||
Common questions
01Is there really a free plan?
Yes. Anonymous visitors get 3 instant scans/day; a free account raises that to 5/day. Free scans are fully standards-graded — every finding carries a CVSS score, CWE id, and OWASP category.
02What is active testing, and why does it need a verified domain?
Active testing sends real (but non-destructive) payloads — reflected XSS, SQL injection, path traversal, open redirect, and out-of-band SSRF — to find exploitable flaws. Sending payloads to a site you don't own is unauthorized testing, so we only run it against domains you have proven you control via a DNS TXT record or hosted file. It's available on the Advanced plan.
03What's the difference between instant and deep scans?
Instant scans the homepage plus DNS/TLS/headers for a fast graded snapshot. Deep crawls a bounded multi-page sample and runs the heavier passive attack-surface engines (cipher enumeration, sensitive-file exposure, subdomain-takeover detection). Deep scans are included from Pro upward.
04How current is the CVE data?
Detected components with a version are matched against a curated high-signal knowledge base and, in parallel, the live OSV.dev feed — so newly published advisories surface without waiting for an app update.
05Are the findings a black-box score?
No. Every finding shows the raw evidence, the CVSS 3.1 vector it was scored from, the CWE and OWASP references, and remediation steps — so you (or an auditor) can verify it independently.
06Can I cancel anytime?
Yes. Cancel from your dashboard; your plan stays active until the end of the current billing period.