| Usage limits |
| Verified targets |
1 |
3 |
10 |
25 |
Unlimited |
| Scans per month |
20 |
100 |
500 |
2,000 |
10,000 |
| URLs per scan |
50 |
50 |
500 |
1,000 |
1,000 |
| Workflow & delivery |
| Scheduling |
Manual only |
Weekly auto |
Daily auto |
Daily + priority queue |
Daily + priority queue |
| Report formats |
JSON |
JSON |
PDF + JSON |
PDF + JSON |
PDF + JSON + Pentest |
| White-label PDF reports |
– |
– |
– |
✓ |
✓ |
| Multi-user workspace |
– |
– |
✓ Admin + Analyst roles |
✓ Admin + Analyst roles |
✓ Admin + Analyst roles |
| Webhooks & API access |
– |
– |
– |
✓ CI/CD integration |
✓ CI/CD integration |
| Active penetration testing |
Pentest Basic
OWASP A01–A07
Show probes
- SQL Injection (error-based + blind)
- Reflected & Stored XSS
- XXE Injection (OOB callback + error-based)
- Path Traversal
- Open Redirect
- Auth Bypass
- IDOR Probe
- Broken Function Level Auth
- HTTP Parameter Pollution (HPP)
|
– |
– |
– |
– |
✓ With consent |
Pentest Advanced
OWASP A03–A10
Show probes
- Command Injection (timing)
- SSRF Callback
- Header Injection (Host header reflection)
- File Upload Bypass (dangerous extension / double extension)
- Mass Assignment
- Insecure Deserialization (timing)
- Business Logic — price manipulation
- HTTP Request Smuggling / Desync Readiness
- Web Cache Poisoning Readiness
|
– |
– |
– |
– |
✓ With consent |
| CVSS scores & PoC evidence |
– |
– |
– |
– |
✓ |
| Digital consent workflow (SOW + RoE) |
– |
– |
– |
– |
✓ |
| Emergency pause & scope enforcement |
– |
– |
– |
– |
✓ |
| Passive scan packages |
Basic Hygiene
15 checks
Show checks
- Security Headers
- HTTPS Redirect
- TLS Certificate
- TLS Chain and Expiry Depth
- TLS Protocol and Cipher Review
- HSTS Strength
- Mixed Content Detection
- Sitemap and Robots Exposure
- DNS Basics
- Open Risky Ports
- Cookie Security
- Server Header Disclosure
- Error Disclosure
- HTTP/2 and HTTP/3 Support
- Service/Version CVE Hints (Advisory)
|
✓ |
✓ |
✓ |
✓ |
✓ |
OWASP Starter
14 checks
Show checks
- CORS Policy
- CORS Edge Cases (null origin / preflight)
- Open Redirect
- Directory Listing
- Sensitive Files
- Secrets in JavaScript Bundles
- CSP Quality Review
- Trusted Types Signal
- Source Map Exposure
- Deprecated Browser APIs
- Harmless Reflected XSS Indicators
- Safe SQL Injection Indicators
- SSTI Template Injection Indicator
- Error Disclosure Expansion
|
– |
✓ |
✓ |
✓ |
✓ |
Threat Readiness
8 checks
Show checks
- WAF/CDN Detection
- WAF Harmless Canary Probe
- Bot Protection Detection
- Rate-Limit Readiness
- DDoS Readiness Evidence
- Origin Exposure Check
- Subdomain Discovery (Certificate Transparency)
- Subdomain Takeover Risk
|
– |
– |
✓ |
✓ |
✓ |
Auth & Session
15 checks
Show checks
- Login Surface Controls
- Session Cookie Scope
- Login Rate-Limit Simulation
- Password Reset Flow Checks
- Account Enumeration Indicators
- Credentialed Test-Account Checks
- Weak Password Policy Review
- MFA Configuration Indicators
- Authenticated Deep Crawl
- OAuth 2.0 / OIDC Security Checks
- BOLA / IDOR Two-Account Comparison
- BFLA Privilege Escalation Probe
- CSRF Protection Enforcement
- Session Fixation Check
- Password Spray Indicator
|
– |
– |
✓ |
✓ |
✓ |
API Security
16 checks
Show checks
- API Documentation Exposure
- HTTP Method Exposure
- Versioned Endpoint Discovery
- Endpoint Auth Indicators
- Excessive API CORS Checks
- Sensitive Response Pattern Detection
- API Rate-Limit Readiness
- API Third-Party Dependency Inventory
- JWT Weakness Detection
- GraphQL Introspection Exposure
- GraphQL DoS Readiness (Batching / Alias / Depth)
- Shadow API Discovery
- WebSocket Security Check
- Subresource Integrity (SRI) Missing
- Dependency CVE Matching (SBOM)
- Drive-by Download / Malicious Redirect Chain
|
– |
– |
✓ |
✓ |
✓ |
Compliance Evidence
10 checks
Show checks
- Security Contact Evidence
- Privacy and Terms Evidence
- Cookie Consent Mechanism
- DNSSEC Review
- WHOIS and Domain Expiry
- Mail Security SPF/DKIM/DMARC
- Mail/DNS Hardening (MTA-STS / TLS-RPT / CAA)
- Availability Status Evidence
- Blocklist and Reputation Checks
- GDPR/CCPA Data Subject Rights
|
– |
– |
✓ |
✓ |
✓ |
Web Quality
2 checks
Show checks
- Accessibility Evidence Snapshot
- SEO and Social Metadata Evidence
|
– |
– |
✓ |
✓ |
✓ |
AI Security
10 checks
Show checks
- AI Endpoint Discovery
- AI Prompt Reflection Check
- AI System Prompt Exposure
- Prompt Injection Indicator
- AI Response Data Leakage
- AI Endpoint Rate-Limit Readiness
- Training Data Extraction Indicator
- Model Extraction Risk Indicator
- Content Moderation Bypass Canary Probe
- Jailbreak Pattern Indicator
|
– |
– |
✓ |
✓ |
✓ |
Cloud Posture
10 checks
Show checks
- AWS Public S3 Storage Exposure
- AWS Open Security Group Ingress
- AWS IAM Stale Access Keys
- AWS Overly-Permissive IAM Policies
- AWS CloudTrail Logging Disabled
- AWS Default Encryption Gaps
- Azure Public Blob Storage Exposure
- Azure Open NSG Ingress Rules
- GCP Public Cloud Storage Exposure
- GCP Open VPC Firewall Ingress
|
– |
– |
✓ |
✓ |
✓ |
Mobile Security
1 check
Show checks
- Mobile App Static Analysis (APK/IPA) — offline, no network traffic
|
– |
– |
✓ |
✓ |
✓ |
|
Sign up
|
Get started
|
Get started
|
Get started
|
Get started
|