Professional Penetration Testing, On-Demand

Identify vulnerabilities in your infrastructure with automated scans. Receive digitally signed PDF reports with RFC 3161 timestamps.

The only Freemium vulnerability scanning service in the world

RFC 3161 signed reports

EITCA/EITC Certifications

GDPR Compliant

Mandatory target ownership verification

How it works

1

Sign up and use free credits

Create your free account and purchase a credit package. Pay only when you want.

2

Verify target ownership

Prove that you own the domain or IP via DNS TXT record or HTTP file. No scanning without authorization.

3

Launch the scan and receive your report

Start the scan and receive a digitally signed PDF report with RFC 3161 timestamp. Email notification upon completion.

Advanced features

Beyond scanning: tools built for managing many assets.

Multiscan

Scan dozens of targets in parallel from a single session, with aggregated status and reports.

Geographic map

Geographic map

Geolocate IPs and hosts on a map: see where your assets β€” and exposed ones β€” are hosted. Find bottlenecks along the route.

3D scan view

3D scan view

Explore results in 3D: ports, services and CVEs on interactive concentric rings.

Anti-WAF rescan

Verify fixes even behind Web Application Firewalls, with resilient rescan techniques.

Intrusive scan

Deep mode: uncovers hidden versions of daemons and services (SSH, FTP, mail) not exposed by default.

Presets

Save recurring configs and target lists and relaunch them in one click.

Dedicated Scans

Keep your infrastructure under control

WordPress

Targeted WordPress scan: core, themes and plugins. Detects vulnerable versions and known CVEs on installed plugins, even behind catch-all reverse proxies.

WooCommerce

Dedicated check for WooCommerce stores: REST endpoints, checkout flow and e-commerce plugins, to protect orders and customer data.

Magento

Specific audit for Magento and Adobe Commerce: version, missing security patches and exposed components of your store.

Joomla

Tailored scan for Joomla: core, extensions and templates, matching known CVEs against detected versions.

PrestaShop

Dedicated check for PrestaShop: CMS version, modules and themes, to surface known vulnerabilities in your store.

Targeted CVE

Targeted scan on one or more specific CVEs: precisely verify whether your asset is exposed to a vulnerability you care about.

AI Reports

Not just the list of vulnerabilities: a security analysis written by AI

The system can analyze complex scans and adds, alongside the usual list of vulnerabilities, a security analysis generated by AI: it puts the findings in context, highlights the real priorities and explains risks and fixes in plain language, even for non-experts.

Details β†’

Targeted Rescan

Verify fixes without repeating the entire scan

After fixing a vulnerability, verify the fix with a Targeted Rescan. Only 5 credits per vulnerability. Batch rescan to verify multiple fixes in parallel.

Single rescan β€” 5 credits
Batch rescan β€” 5 credits per vulnerability, parallel execution

Aruba legal timestamp

Legally valid proof, no notary needed

Certify your reports with a qualified Aruba timestamp (RFC 3161): the document's date and time become proof that holds up against third parties, with full legal value. A notary would charge €50–150 per deed for the same certainty. Useful for audits, compliance (ISO 27001, GDPR, NIS2) and disputes.

Legally binding against third parties β€” RFC 3161 Β· eIDAS
Like a notary for certified dating, saving €50–150 per deed

API + AI

Automate scans with a script or an AI agent

Everything you do from the dashboard is available via the REST API: launch scans, track their status, download reports. With our MCP server an AI agent (e.g. Claude) can run scans autonomously, authenticating with a personal API key.

Learn more β†’

Plans

Recurring credits every cycle, with rollover. Cancel anytime.

Starter

For small sites and first tests

14.9β‚¬βˆ’34%
9.9€/mo
100 credits / month
  • All scan types (Network, Web, Vulnerability, Full)
  • RFC 3161 signed PDF reports
  • Targeted Rescan included
  • Rollover credits (never expire)
  • Email support
Subscribe
PiΓΉ popolare

Medium

For professionals and SMBs

45β‚¬βˆ’34%
29.9€/mo
200 credits / month
  • Everything in Starter
  • Real-time terminal log
  • Priority scan queue
  • Bulk multi-target multiscan
  • Priority support
Subscribe

Maxi

For agencies and many domains

89β‚¬βˆ’33%
59.9€/mo
2500 credits / month
  • Everything in Medium
  • API access
  • Dedicated scan satellite
  • Dedicated account manager
  • Guaranteed SLA
Subscribe

Enterprise

For special needs, get in touch

Custom pricing
  • High scan volume
  • Enterprise service
  • Tailored service
  • Dedicated consulting

Don't hesitate to contact us for product upgrades or specific requirements for your company!

Latest CVE vulnerabilities

High-severity vulnerabilities published in the last 30 days

Juggle through 1.6.0 contains a remote code execution vulnerability that allows unauthenticated remote attackers to execute arbitrary OS commands by connecting to the exposed H2 database web console using default shipped...

CVSS: 9.8CWE: CWE-306NETWORK7/30/2026

IBM Langflow OSS 1.0.0 through 1.10.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot " sequences ( /.. /) to view arbitrary...

CVSS: 7.5CWE: CWE-22NETWORK7/30/2026

IBM webMethods Integration (on prem) 10.15, 10.11 could allow an unauthenticated remote attacker to execute arbitrary code on the system due to the deserialization of untrusted data.

CVSS: 9.8CWE: CWE-502NETWORK7/30/2026

Ready to discover the vulnerabilities in your infrastructure?

Create free account

Free diagnostic tools

Synchronous tools, no mandatory login, no limits for registered users.

πŸ—ΊοΈ

GeoTrace / MTR

Network path tracing with hop-by-hop geolocation and BGP details.

πŸ†“ Free
Try now β†’
🌐

DNS Deep Dive

Full DNS analysis: SPF, DMARC, DKIM, TTL, IPv6 and email security score.

πŸ†“ Free
Try now β†’
πŸ“‹

HTTP Headers

Audit security HTTP headers: HSTS, CSP, X-Frame-Options, Referrer-Policy.

πŸ†“ Free
Try now β†’
πŸ”

SSL/TLS Check

Verify certificate, supported protocols, cipher suites and known vulnerabilities.

πŸ†“ Free
Try now β†’
🏒

WHOIS Lookup

Domain registration info: registrar, dates, contacts.

πŸ†“ Free
Try now β†’
βœ‰οΈ

Email Security

Quick SPF/DKIM/DMARC test and blacklist check for your mail server.

πŸ†“ Free
Try now β†’
πŸ”Œ

Port Quick Scan

Fast scan of common ports with service identification.

πŸ†“ Free
Try now β†’
πŸ”

Web Audit Free

Free SEO, AI readiness & performance audit β€” 3 audits/30 days per IP, 1-hour link.

πŸ†“ Free
Try now β†’
πŸ“°

WordPress Audit

Free passive audit for WordPress sites β€” CMS fingerprint, public CVE correlation. 3 scans/day per IP.

πŸ†“ Free
Try now β†’
πŸ›’

WooCommerce Audit

Free passive audit for WooCommerce stores β€” CMS fingerprint, public CVE correlation. 3 scans/day per IP.

πŸ†“ Free
Try now β†’
🧩

Joomla Audit

Free passive audit for Joomla sites β€” CMS fingerprint, public CVE correlation. 3 scans/day per IP.

πŸ†“ Free
Try now β†’
πŸ›οΈ

Magento Audit

Free passive audit for Magento stores β€” CMS fingerprint, public CVE correlation. 3 scans/day per IP.

πŸ†“ Free
Try now β†’