You pay for how deep you want to go — each level includes the one before. One-time payment, no plan, no subscription.
Free scan · $0 — no signup, no card
A 0-to-100 score for your app · The full list of flaws, by severity · OWASP, CWE and data-protection classification · Prioritized action plan, with time estimates
AvailablePublic
$19.90 / site
The home and every public page — plus everything the browser downloads (bundles, configs). That is where most AI-built app leaks show up.
- Where each flaw is — file, line, endpoint
- Cause, impact, and before/after code
- Fix prompt per assistant (Claude Code, Cursor, Lovable, Windsurf)
- Retest included for 7 days
- Report exportable to Markdown and PDF
Coming soon+ User
$49.90 / site
Everything in Public plus the logged-in user area. You create a test account; we run it in an isolated session and wipe it afterward.
- Everything in the Public level
- Pages and actions available to the logged-in user
- One user's data reachable by another (IDOR)
- Permission flaws inside the account
Coming soon+ Admin
$99.90 / site
The complete audit: everything in the levels below plus the admin panel and the most valuable test of all.
- Everything in the Public and User levels
- Admin panel and privileged actions
- Privilege escalation: a regular user reaching admin-only areas
- Broken access control between roles
The first scan is free — you only pay if you want the proof and the fix.