Pricing
Know what's exposed. Fix it fast.
721 security checks in the full suite after current ownership proof plus explicit active-testing authorization. Free shows what's broken. Paid gives you the exact fix, ready to paste, and keeps watching.
3,441+
Scans run
23,264
Vulnerabilities found
721
Full-suite checks after current ownership proof + explicit active-testing authorization
Free

Check any site in a couple of minutes
Forever
- 1 domain, checked on demand
- Up to 721 checks with current ownership proof plus explicit active-testing authorization
- Official score and grade after current ownership proof and sufficient coverage
- All finding titles + severity
- OWASP Top 10 checks
- 1 lifetime deep scan (verified domain)
Solo
FOR SOLO FOUNDERS
1 monitored domain, unlimited re-scans
Billed monthly
- Re-scan to verify your fix + before/after diff
- Full finding details + AI fix prompts
- Weekly & monthly monitoring + alerts
- Unlimited deep scans + CVE alerts
- PDF export, badge, GitHub, score trends
Studio

5 monitored domains, unlimited re-scans
Billed monthly
- Everything in Solo
- Cover client sites and side projects
- Monitoring up to every 3 days
- Priority support
Scale

15 monitored domains, unlimited re-scans
Billed monthly
- Everything in Studio
- Daily monitoring
- Early access to new checks as they roll out
Prices are in USD. Applicable taxes (such as VAT) are calculated at checkout by Freemius. Fair use: unlimited re-scans are for verifying and monitoring your own domains, not bulk scanning.
Managing more than 15 client domains? Email us - an Agency plan with white-label reports is on the way, and early access is open.
Agent Proof for AI organizations
Boundary evidence is not another Scanner subscription.
Agent Proof is a planned, scope-led engagement for AI Agent builders. It is separate from Free, Solo, Studio and Scale, and it does not begin with checkout or system access.
Current availability
Discovery open
Customer testing and staging connection are not yet available.
Proposed pilot structure
- Written scope and authorized synthetic staging
- Relevant tenant, tool and approval boundary methods
- Findings and remediation review
- One retest against a new build
- Private, scope-bound Proof Pack
Custom scope after discovery // No public price // No checkout // Not certification
Scan once to find it. Re-scan to prove it is fixed.
Same scan. Different level of detail.
Missing Content Security Policy (CSP)
Severity: Critical
Upgrade to verify your fix worked
Missing Content Security Policy (CSP)
Severity: Critical
Your site has no CSP header, allowing attackers to inject malicious scripts via XSS. This can lead to session hijacking, data theft, and defacement.
// AI fix prompt - copy to Cursor / Claude
Add Content-Security-Policy header:
default-src 'self'; script-src 'self';
Compare plans
| Feature | Free | Solo | Studio | Scale |
|---|---|---|---|---|
| Coverage | ||||
| Monitored domains | 1 | 5 | 15 | |
| Fresh scans | 2 / month | Unlimited | Unlimited | Unlimited |
| Re-scan the same domain | Once a month | Anytime | Anytime | Anytime |
| Monitoring & alerts | Weekly | Every 3 days | Daily | |
| Deep scan (currently verified domain) | 1 lifetime | Unlimited | Unlimited | Unlimited |
| Active web testing | Separate explicit authorization | Separate explicit authorization | Separate explicit authorization | Separate explicit authorization |
| Always-fresh scans | Fresh bounded public check | |||
| Find & fix | ||||
| Security scan | 149 bounded checks | Up to 721 with current ownership proof + explicit active-testing authorization | Up to 721 with current ownership proof + explicit active-testing authorization | Up to 721 with current ownership proof + explicit active-testing authorization |
| Finding titles + severity | All severities | All + full fixes | All + full fixes | All + full fixes |
| Score breakdown by category | All 7 categories | All 7 categories | All 7 categories | All 7 categories |
| Verify a fix (before/after diff) | ||||
| AI fix prompts | All findings | All findings | All findings | |
| Plain-English fix suggestions | ||||
| Reports & integrations | ||||
| PDF report export | ||||
| Score trend over time | ||||
| Security badge for your site | ||||
| GitHub integration | ||||
| Regulatory readiness (optional, per domain) | ||||
| Jurisdiction-Aware Compliance (opt-in) | ||||
| Israeli Privacy Readiness - Tikun 13 score + coverage | ||||
| Signal-by-signal evidence & source links | ||||
| Readiness appendix in PDF export | ||||
| Support | ||||
| Priority support | ||||
| Early access to new checks as they roll out | ||||
FAQ
What is a monitored domain?+
A domain you actively protect with UNPWNED: we scan it continuously on your schedule, alert you when something changes, and let you re-scan it anytime to verify fixes. Solo covers 1 domain, Studio covers 5, Scale covers 15. Subdomains of the same site count as one domain.
Are re-scans really unlimited?+
Yes, within fair use. The whole point of fixing something is re-scanning to prove it worked, so paid plans never meter the fix-verify loop on your monitored domains. Fair use means protecting your own sites, not bulk-scanning the internet.
Is re-scanning to check my fix free?+
Free re-scans the same domain once a month, so you can watch your score over time. Instantly re-scanning right after a fix, plus the before/after diff that proves the issue is gone, is a paid feature.
What does a scan check?+
The Free public check runs 149 bounded checks for externally observable headers, DNS, certificate-transparency and technology signals. Current ownership verification unlocks the 428-check surface suite. The 721-check full suite also requires explicit active-testing authorization. Deep Scan adds owner-authorized CVE fingerprinting, cloaking detection, ghost-page sampling, and deep CORS/method testing. Paid reports that pass Green Light can activate an UNPWNED VERIFIED badge.
Will UNPWNED scans trigger my firewall or WAF?+
Sometimes. A confirmed WAF challenge can interrupt checks; that means scanner access was limited, not that every application control is secure. Anonymous scanner addresses must never receive a broad firewall Allow rule. Verified owner scans can use UNPWNED's published dedicated scanner IP; allow only that IP for the exact verified domain through the guided access flow. If you are behind Cloudflare, follow the Cloudflare scan guide for the safe access flow.
Are Free public checks cached?+
No. Public cache reuse is currently disabled, so a new Free public check runs fresh. It remains a bounded, partial assessment and does not publish an official grade. Current ownership verification unlocks the owner-authorized surface checks. The active-testing tier requires separate explicit authorization.
What if a paid plan isn't worth it for me?+
You can cancel anytime with one click, no questions asked. The Free plan is always there if you only need a basic check.
Why not just use free security tools?+
Single-purpose tools check one thing at a time (SSL, headers, DNS). UNPWNED runs 149 checks free in one scan. The 721-check full suite requires current ownership proof plus explicit active-testing authorization. Paid reports add deterministic fix guidance and AI-ready Fix Prompts to copy into your editor.
Can I change plans?+
Yes. You can move between Solo, Studio, and Scale at any time. Changes take effect immediately and are prorated by our payment provider.
What payment methods do you accept?+
We accept all major credit and debit cards via Freemius. All payments are processed securely - we never store your card details.
See what needs attention before it becomes an incident.
Run your first scan in a couple of minutes. No credit card required.
3,441+ scans already run - 23,264 vulnerabilities found
UNPWNED is operated by Raz Azulay, Israeli sole proprietor (osek patur).
PO Box 716, Ofakim 8751602, Israel
Freemius is the merchant and seller of record for paid purchases.
