Skip to main content
UNPWNED

Pricing

Know what's exposed. Fix it fast.

721 security checks in the full suite after current ownership proof plus explicit active-testing authorization. Free shows what's broken. Paid gives you the exact fix, ready to paste, and keeps watching.

3,441+

Scans run

23,264

Vulnerabilities found

721

Full-suite checks after current ownership proof + explicit active-testing authorization

Free

Free plan mascot

Check any site in a couple of minutes

$0

Forever

  • 1 domain, checked on demand
  • Up to 721 checks with current ownership proof plus explicit active-testing authorization
  • Official score and grade after current ownership proof and sufficient coverage
  • All finding titles + severity
  • OWASP Top 10 checks
  • 1 lifetime deep scan (verified domain)
Get started free

Solo

FOR SOLO FOUNDERS
Solo plan mascot

1 monitored domain, unlimited re-scans

$9/mo

Billed monthly

  • Re-scan to verify your fix + before/after diff
  • Full finding details + AI fix prompts
  • Weekly & monthly monitoring + alerts
  • Unlimited deep scans + CVE alerts
  • PDF export, badge, GitHub, score trends
Scan first, then unlock

Studio

Studio plan mascot

5 monitored domains, unlimited re-scans

$29/mo

Billed monthly

  • Everything in Solo
  • Cover client sites and side projects
  • Monitoring up to every 3 days
  • Priority support
Scan first, then unlock

Scale

Scale plan mascot

15 monitored domains, unlimited re-scans

$49/mo

Billed monthly

  • Everything in Studio
  • Daily monitoring
  • Early access to new checks as they roll out
Scan first, then unlock

Prices are in USD. Applicable taxes (such as VAT) are calculated at checkout by Freemius. Fair use: unlimited re-scans are for verifying and monitoring your own domains, not bulk scanning.

Managing more than 15 client domains? Email us - an Agency plan with white-label reports is on the way, and early access is open.

B2B // Design partner

Agent Proof for AI organizations

Boundary evidence is not another Scanner subscription.

Agent Proof is a planned, scope-led engagement for AI Agent builders. It is separate from Free, Solo, Studio and Scale, and it does not begin with checkout or system access.

Current availability

Discovery open

Customer testing and staging connection are not yet available.

Proposed pilot structure

  • Written scope and authorized synthetic staging
  • Relevant tenant, tool and approval boundary methods
  • Findings and remediation review
  • One retest against a new build
  • Private, scope-bound Proof Pack

Custom scope after discovery // No public price // No checkout // Not certification

Scan once to find it. Re-scan to prove it is fixed.

Same scan. Different level of detail.

Free reportCritical

Missing Content Security Policy (CSP)

Severity: Critical

Upgrade to verify your fix worked

Paid reportCritical

Missing Content Security Policy (CSP)

Severity: Critical

Your site has no CSP header, allowing attackers to inject malicious scripts via XSS. This can lead to session hijacking, data theft, and defacement.

// AI fix prompt - copy to Cursor / Claude

Add Content-Security-Policy header:
default-src 'self'; script-src 'self';

Compare plans

FeatureFreeSoloStudioScale
Coverage
Monitored domains1515
Fresh scans2 / monthUnlimitedUnlimitedUnlimited
Re-scan the same domainOnce a monthAnytimeAnytimeAnytime
Monitoring & alertsWeeklyEvery 3 daysDaily
Deep scan (currently verified domain)1 lifetimeUnlimitedUnlimitedUnlimited
Active web testingSeparate explicit authorizationSeparate explicit authorizationSeparate explicit authorizationSeparate explicit authorization
Always-fresh scansFresh bounded public check
Find & fix
Security scan149 bounded checksUp to 721 with current ownership proof + explicit active-testing authorizationUp to 721 with current ownership proof + explicit active-testing authorizationUp to 721 with current ownership proof + explicit active-testing authorization
Finding titles + severityAll severitiesAll + full fixesAll + full fixesAll + full fixes
Score breakdown by categoryAll 7 categoriesAll 7 categoriesAll 7 categoriesAll 7 categories
Verify a fix (before/after diff)
AI fix promptsAll findingsAll findingsAll findings
Plain-English fix suggestions
Reports & integrations
PDF report export
Score trend over time
Security badge for your site
GitHub integration
Regulatory readiness (optional, per domain)
Jurisdiction-Aware Compliance (opt-in)
Israeli Privacy Readiness - Tikun 13 score + coverage
Signal-by-signal evidence & source links
Readiness appendix in PDF export
Support
Priority support
Early access to new checks as they roll out

FAQ

What is a monitored domain?+

A domain you actively protect with UNPWNED: we scan it continuously on your schedule, alert you when something changes, and let you re-scan it anytime to verify fixes. Solo covers 1 domain, Studio covers 5, Scale covers 15. Subdomains of the same site count as one domain.

Are re-scans really unlimited?+

Yes, within fair use. The whole point of fixing something is re-scanning to prove it worked, so paid plans never meter the fix-verify loop on your monitored domains. Fair use means protecting your own sites, not bulk-scanning the internet.

Is re-scanning to check my fix free?+

Free re-scans the same domain once a month, so you can watch your score over time. Instantly re-scanning right after a fix, plus the before/after diff that proves the issue is gone, is a paid feature.

What does a scan check?+

The Free public check runs 149 bounded checks for externally observable headers, DNS, certificate-transparency and technology signals. Current ownership verification unlocks the 428-check surface suite. The 721-check full suite also requires explicit active-testing authorization. Deep Scan adds owner-authorized CVE fingerprinting, cloaking detection, ghost-page sampling, and deep CORS/method testing. Paid reports that pass Green Light can activate an UNPWNED VERIFIED badge.

Will UNPWNED scans trigger my firewall or WAF?+

Sometimes. A confirmed WAF challenge can interrupt checks; that means scanner access was limited, not that every application control is secure. Anonymous scanner addresses must never receive a broad firewall Allow rule. Verified owner scans can use UNPWNED's published dedicated scanner IP; allow only that IP for the exact verified domain through the guided access flow. If you are behind Cloudflare, follow the Cloudflare scan guide for the safe access flow.

Are Free public checks cached?+

No. Public cache reuse is currently disabled, so a new Free public check runs fresh. It remains a bounded, partial assessment and does not publish an official grade. Current ownership verification unlocks the owner-authorized surface checks. The active-testing tier requires separate explicit authorization.

What if a paid plan isn't worth it for me?+

You can cancel anytime with one click, no questions asked. The Free plan is always there if you only need a basic check.

Why not just use free security tools?+

Single-purpose tools check one thing at a time (SSL, headers, DNS). UNPWNED runs 149 checks free in one scan. The 721-check full suite requires current ownership proof plus explicit active-testing authorization. Paid reports add deterministic fix guidance and AI-ready Fix Prompts to copy into your editor.

Can I change plans?+

Yes. You can move between Solo, Studio, and Scale at any time. Changes take effect immediately and are prorated by our payment provider.

What payment methods do you accept?+

We accept all major credit and debit cards via Freemius. All payments are processed securely - we never store your card details.

See what needs attention before it becomes an incident.

Run your first scan in a couple of minutes. No credit card required.

3,441+ scans already run - 23,264 vulnerabilities found

UNPWNED is operated by Raz Azulay, Israeli sole proprietor (osek patur).

PO Box 716, Ofakim 8751602, Israel

Freemius is the merchant and seller of record for paid purchases.