Headers and cookies
Response hardening such as security headers and cookie posture.
From quick no-account diagnostics to Website Watch, agency-branded reports, automated scan workflows, and premium assessments — one platform for web security testing.
The platform is designed around the workflows teams actually use when moving from first check to recurring security review.
Coverage varies by tool, scan depth, and workflow. Website Watch and white-label reports follow in the next section.
Response hardening such as security headers and cookie posture.
Protocol and certificate health across HTTPS and TLS checks.
Common web-application security risk categories and surface issues.
Email security and DNS posture where relevant to the workflow.
Technology disclosure, crawlability, and attack-surface indicators.
Related remediation and educational content across tools, guides, and fix pages.
Extension-intelligence workflows for installation, administrator, API, and patch-risk reduction.
Storefront-focused profile workflows for ecommerce hardening.
Component-intelligence workflows for plugin and theme risk reduction.
Website Watch watches one HTTPS origin. White-Label Reports put your agency cover on scan and pentest deliverables.
Daily pulse for TLS, headers, mixed content, HTTP to HTTPS, and exposed paths. Weekly Standard or Deep scan, locked when you add the site. Email on new or worsened findings, score drop, and cert windows at 30 / 14 / 7 / expired. Mute accepted risk, then Unmute from the same watch page. Standard $29 or Deep $49 per site per month. Included runs do not use credits.
Copy a 14-day client view or email the branded PDF. Prepared for labels one client without a second brand pack. There is no logged-in client portal.
Quick checks are public. Comprehensive follow-up workflows are available after sign-in.
~2-3 minutes · ~40 checks · $4.50
Fast baseline coverage for core web security controls and obvious exposure gaps.
~5-7 minutes · ~80 checks · $9.00
The default choice for most production sites that need broader automated coverage.
~12-15 minutes · ~120 checks · $18.00
More extensive testing for teams validating higher-risk releases or complex apps.
~15-20 minutes · ~140+ checks · $36.00
The widest automated coverage for launch readiness, audits, and recurring security validation.
Common questions about free tools, scan credits, Website Watch, agency reports, and how Vulnify compares to other scanners.
Vulnify's free tools test for SSL/TLS misconfigurations, missing or weak security headers (CSP, HSTS, X-Frame-Options), exposed sensitive paths, XSS and SQL injection indicators, cookie security posture, CORS misconfiguration, and technology disclosure. No account or signup is required to run quick diagnostics.
No. Public security tools — CSP checker, SSL grader, headers analyzer, DNS checker, and payload libraries — run without an account. The website vulnerability scanner page is a guide. A full OWASP scan needs Get Started, email verification, and starter credits.
Public tools cover SSL grading, security headers, and related checks at no cost with no account. A full OWASP-aligned scan needs a free verified account with starter credits. Paid scanners such as Acunetix offer deeper authenticated crawling, but Vulnify lets you run public tools immediately and a credited scan without a procurement process.
Vulnify is designed for testing websites you own or are explicitly authorized to test. Free public tools run lightweight, non-intrusive checks on any publicly accessible domain. Deeper automated scans require you to confirm ownership or authorization of the target before running. Penetration Test and Comprehensive Pentest also require hostname verification before engines start.
The $297 Penetration Test is automated evidence-backed testing with HTML, PDF, and one included retest. The $497 Comprehensive Pentest adds extra engines, up to five extra verified hosts, a two-role matrix when two login profiles are supplied, a detailed, actionable PDF for security specialists and developers, ticket-ready remediation, an auditor-ready evidence pack that is not a certificate, and two retests. Neither is a human consultant engagement.
Website Watch is always-on monitoring for one HTTPS origin. Vulnify runs a daily pulse and one weekly Standard or Deep scan (chosen when you add the site), then emails you when something new or worse appears, the score drops, or the certificate hits 30, 14, 7, or expired. Standard is $29 per site per month or $290 per year. Deep is $49 or $490 per year. Included runs do not use credits. Mute and unmute live on the watch page.
Yes on Team and Enterprise. White-Label Reports apply your organization name, logo, colors, and support line to scan, pentest, and compliance reports. You can hide Powered by Vulnify and send a 14-day client view. Free and Pro keep Vulnify branding. There is no logged-in client portal.
Website Watch is a per-origin seat: daily pulse plus one weekly Standard or Deep scan locked at checkout. Included Watch runs do not use credits. Scheduled scans run on credits at a cadence you set, including Comprehensive, and start on Pro (up to 3), Team (up to 10), and Enterprise (unlimited). Use Watch for always-on alerts on one HTTPS origin. Use scheduled scans for a custom credit cadence or a deeper depth.
Go deeper on the security topics Vulnify tests — step-by-step guides written for developers and security teams.
A step-by-step runbook for scanning a site and deciding what to fix first.
Read guideWhat the current Top 10 means in practice, and which checks catch each class.
Read guideWhen to use code review, a running-app scan, or a dependency check.
Read guideThe three flags that stop session theft, and the mistakes scanners still flag.
Read guideHow SSRF works, where it shows up, and how to close the request path.
Read guideStart with the website vulnerability scanner guide, then pair point-in-time checks with transport and header tools.
Free OWASP-aligned scan guide for SQL injection, XSS, exposed paths, and misconfigurations.
Verify Strict-Transport-Security headers, max-age, and preload eligibility on any URL.
Free SSL checker online — test SSL certificate, TLS grade, HTTPS chain, and cipher strength.
Check CSP, HSTS, X-Frame-Options, and other response headers, with fix-oriented guidance.
Start with public tools for quick answers, or move straight into broader platform workflows if you need saved history, recurring scans, and richer reporting.