Comprehensive Pentest

Comprehensive Pentest $497

You must own the target or have written permission to test it. Everything in Pen Test plus extra engines, up to five extra verified hosts tested, a two-role matrix, a detailed, actionable PDF for security specialists and developers, and two retests. Usually 30 to 60 minutes after testing starts.

Included

What you get

Everything in Pen Test plus extra engines, up to five extra verified hosts tested, a two-role matrix, a detailed, actionable PDF for security specialists and developers, and two retests

You authorize the target

Pay, then confirm you own the hostname or have written permission. Testing does not start until consent and verification are complete.

Confirm the engagement plan

Review what will run. Active engines wait until you confirm. Start now or schedule a window with timezone and blackouts.

HTML and PDF for specialists

A do-this-week list, ticket-ready findings, and evidence. Not a consultant letter and not a compliance certificate.

Included retest

The $297 tier includes one targeted retest. The $497 tier includes two. Full refund until testing starts.

  • Everything in the $297 Penetration Test
  • Extra engines: GraphQL, JWT, template injection, NoSQL, XXE, and public-repo secret scanning
  • Up to 5 extra verified hosts tested after you prove control
  • Two-role authorization matrix when two profiles are supplied
  • Attack-surface appendix in the report
  • Detailed, actionable PDF plus HTML for specialists and developers
  • Two included targeted retest cycles
  • Ticket-ready remediation
  • Auditor-ready evidence pack (not a certificate)

Wrapped industry engines

The same catalog wraps Nuclei, OWASP ZAP, SQLMap, and Playwright. Vulnify owns confirmation, evidence, and the report. These names are not partner badges.

  • Nuclei
  • OWASP ZAP
  • SQLMap
  • Playwright

Names identify software we wrap. No affiliation or endorsement.

See the full methodology

How testing works

Automated penetration test methods

Published engines, OWASP-aligned checks, and a specialist PDF — not a tools roundup.

This automated penetration test runs hosted engines against the hostname you authorize. Coverage is web-application focused: injection, cross-site scripting, exposed paths, headers, and related OWASP-style checks. Vulnify confirms findings, attaches evidence, and writes ticket-ready remediation. It is not a network CVE scanner and not a certified audit.

If you only need a free public check first, start with the website vulnerability scanner or a free security scan. Order this $297 automated penetration test when you want HTML and PDF plus one retest on a target you own.

How it runs

From order to report

Pay, consent, verify, confirm the plan, then receive HTML and PDF.

  1. Pay and authorize

    Order this tier, then confirm you own or are authorized to test the hostname.

  2. Verify the target

    Prove control of the primary hostname before any active testing starts. Comprehensive extra hosts stay out of scope until you verify them or continue primary-only.

  3. Attach login profiles when needed

    A healthy scanner login profile enables authenticated families. Skip it and those checks are not tested. Comprehensive can add a second profile for the two-role matrix.

  4. Confirm the plan, then start or schedule

    Review the automated engagement plan. Engines do not start until you confirm. Full refund remains available until they do.

  5. Report and retest

    Usually 30 to 60 minutes after testing starts. HTML and PDF include numbered remediation. Included retests depend on the tier you ordered.

Proof

See a sample report

Same structure as the deliverable for this tier. Sample data only.

Limits

What this is not

Honest limits so you order the right product.

Automated, not a human consultant

Automated evidence-backed testing — not a human consultant. Vulnify wraps published engines and owns confirmation, evidence, and the report.

Not a certified audit

This is an automated, evidence-backed assessment. It is not a PCI DSS, SOC 2, ISO 27001, or certified penetration test, and it is not a human consultant letter.

Refunds stop when engines start

Full refund until testing starts. After engines start, use request stop instead of a refund.

Need the core catalog only? Penetration Test — $297 · Website Security Scanner · Website Watch · How to scan a website for vulnerabilities · OWASP Top 10 explained · SAST vs DAST vs SCA · Cookie security explained · SSRF explained · Vulnify home

FAQ

Comprehensive Pentest FAQ

Authorization, timing, and how this tier differs from the other pentest.

Vulnify's comprehensive pentest ($497) includes everything in the $297 Penetration Test plus extra engines, up to five extra verified hosts tested after you prove control, a two-role matrix when two profiles are supplied, a detailed actionable PDF for security specialists and developers, ticket-ready remediation, an auditor-ready evidence pack, and two included retests.

Order the Comprehensive Pentest

$497. Usually 30 to 60 minutes after testing starts. You must own the target or have written permission.