Methodology

Automated evidence-backed penetration testing

Two live levels: a $297 Penetration Test core catalog and a $497 Comprehensive Pentest. Engines record proof when a check succeeds and mark the check not applicable when preconditions are unmet — never a guessed finding, never a human consultant, never a certification stamp.

Wrapped industry engines

Vulnify wraps Nuclei, OWASP ZAP, SQLMap, Playwright, httpx, and katana inside a published check catalog. Vulnify owns confirmation, evidence, and the report. These vendors are not partners and do not certify the assessment.

  • Nuclei
  • OWASP ZAP
  • SQLMap
  • Playwright
  • httpx
  • katana

Names identify software we wrap. No affiliation or endorsement.

What this methodology covers

The public catalog is the same check set the worker plane runs after you pay, verify the hostname, and confirm the engagement plan.

Evidence first

Each check has a family, a required-or-recommended level, and a severity cap. A finding is stored only when the engine captured proof. If authentication, object IDs, or another precondition is missing, the result is not applicable.

Two commercial levels

The $297 Penetration Test runs Penetration Test core. The $497 Comprehensive Pentest includes that core, then adds extra engines, a verify-then-test cap of five extra hosts, deeper API authorization, and a two-role matrix when two profiles are supplied.

The two pentest levels

Pay, consent, verify, confirm the engagement plan, then receive HTML and PDF. Reports are usually ready 30 to 60 minutes after testing starts. Included retests depend on the tier you order.

$297

Penetration Test

Automated evidence-backed testing with HTML, PDF, and one included retest

  • Verified target and authorization consent before testing
  • Review and confirm the automated engagement plan
  • Usually 30 to 60 minutes after testing starts
  • HTML and PDF with a do-this-week list and ticket-ready findings
  • One included targeted retest with before and after evidence
  • Full refund until testing starts
  • Optional authenticated checks with a saved healthy scanner profile

$497

Comprehensive Pentest

Everything in Pen Test plus extra engines, up to five extra verified hosts tested, a two-role matrix, a detailed, actionable PDF for security specialists and developers, and two retests

  • Everything in the $297 Penetration Test
  • Extra engines: GraphQL, JWT, template injection, NoSQL, XXE, and public-repo secret scanning
  • Up to 5 extra verified hosts tested after you prove control
  • Two-role authorization matrix when two profiles are supplied
  • Attack-surface appendix in the report
  • Detailed, actionable PDF plus HTML for specialists and developers
  • Two included targeted retest cycles
  • Ticket-ready remediation
  • Auditor-ready evidence pack (not a certificate)

How an engagement runs

Active testing starts only after payment, authorization, hostname verification, and plan confirmation. You can start immediately or schedule a start window.

Pay and authorize

Choose the $297 Penetration Test or the $497 Comprehensive Pentest, then confirm you own or are authorized to test the hostname.

Verify the target

Prove control of the primary hostname before any active testing starts. Comprehensive extra hosts stay out of scope until you verify them or continue with the primary hostname only.

Attach login profiles when needed

A healthy scanner login profile enables authenticated families. Skip it and those checks are not tested. Comprehensive can add a second profile for the two-role matrix.

Confirm the plan, then start now or schedule

Review the automated engagement plan. Active engines do not start until you confirm. You can start immediately or set a start window with timezone and blackouts. Full refund remains available until engines start.

Worker catalog and report

The worker plane runs the published checks and delivers HTML and PDF with a do-this-week list, numbered remediation, and color-coded severity. There is no score circle and no PCI, SOC 2, or ISO badge. Included retests depend on the tier.

Penetration Test core catalog

These checks ship with every $297 Penetration Test. The $497 Comprehensive Pentest runs this catalog plus the extras below.

Unable to load the published check catalog.

CheckFamilyLevelSeverity cap

Limits you should expect

Automated evidence-backed testing — not a human consultant or compliance certification.

Vulnify does not send a human tester, does not issue ISO or PCI certificates, and does not invent vulnerabilities to fill a report. Use this page to compare the two live levels, then order from premium assessments or review pricing.

Penetration test FAQ

Clear answers about the published catalog, the $297 and $497 levels, and when a check is marked not applicable.

It is an evidence-backed, hands-off assessment of a hostname you own or are authorized to test. Engines run a published check catalog, record proof when a check succeeds, and mark a check as not applicable when preconditions are unmet. It is not a human consultant engagement and not a compliance certification.