Simple, transparent pricing
Whether you are securing a single personal project or monitoring an entire client portfolio, we have a plan for you.
Basic
Perfect for single domains and quick checks.
- ✓Full one-time security scan
- ✓SSL/TLS, headers, DNS & email spoofing checks
- ✓IP blacklist & CMS/plugin vulnerability checks
- ✓Downloadable PDF report
- ✓No account required
Starter
For solo devs monitoring a handful of projects.
- ✓Up to 5 monitored domains
- ✓Daily automated re-scans
- ✓Full scan history & before/after comparison
- ✓Email alerts on grade drops or new blacklist hits
- ✓Automatic monthly PDF report emailed to you
- ✓Everything in Free, continuously
Pro
Continuous monitoring and business risk protection.
- ✓Unlimited monitored domains
- ✓Daily automated re-scans
- ✓Full scan history & before/after comparison
- ✓Email alerts on grade drops or new blacklist hits
- ✓Automatic monthly PDF report emailed to you
- ✓Everything in Free, continuously
Choose your plan
Frequently asked questions
Is the free scan really free?
Yes. The one-time domain scan on the home page requires no signup, no credit card, and no account. You get an instant grade and a downloadable PDF report.
What does the free scan actually check?
SSL/TLS (certificate validity plus the protocol and cipher your server negotiates), HTTP security headers, accidentally exposed files like .env and .git, cookie security flags (Secure, HttpOnly, SameSite), SPF/DMARC/DKIM email spoofing protection, IP blacklist status, and — for WordPress, WooCommerce, and Shopify sites — exposed admin logins and outdated plugins. We also report security.txt, CAA, and DNSSEC as informational signals; those don't affect your grade since most sites don't have them configured.
Will I be charged automatically when I start a free trial?
If the plan you choose includes a free trial, it may require a payment method up front and converts to the paid subscription automatically unless you cancel before the trial ends. You'll see the full checkout details, including whether a trial applies, before anything is confirmed.
Can I cancel anytime?
Yes, from your account at any time. When you cancel, you keep full access through the end of your current billing period — there's no immediate cutoff.
What's the difference between Starter and Pro?
Both include daily re-scans, full scan history with before/after comparison, email alerts on regressions, and an automatic monthly PDF report. Starter covers up to 5 monitored domains for $9/month; Pro covers unlimited domains for $29/month, with no per-domain fee. You can upgrade from your account anytime — domains you already added are kept, you just can't add more past your plan's limit until you upgrade or free up a slot.
What data do you store about me and my domains?
Just what's needed to run the service: your account email (via our authentication provider, Clerk), the domains you add, and scan results about those domains. We don't sell data or use advertising trackers — see our Privacy Policy for the full breakdown.
Is the dependency vulnerability scanner free too?
Yes. Upload a package-lock.json, yarn.lock, requirements.txt, or composer.lock and every dependency is checked against OSV.dev's public vulnerability database — no signup required, and the file itself is never stored, written to disk, or logged.
What's the difference between the free scan and continuous monitoring?
The free scan is a one-time snapshot. Starter and Pro both add continuous re-scanning on the schedule you choose, full scan history with before/after comparison, email alerts the moment something regresses — a grade drop or a new blacklist hit — and an automatic monthly PDF report emailed to you.
Do I still get a PDF report if I never download one myself?
Yes. Every monitored domain on Starter or Pro automatically gets a PDF security report emailed to its owner once a month, built from the most recent scan — on top of the on-demand download available from any scan result.