Joomla
Quick profile plus full Joomla security scanner pathway.
Transparent vulnerability scanning cost: subscription credits or pay-as-you-go packs. Compare tiers, see per-scan pricing, and start free with bonus credits.
Switch between recurring subscriptions and one-time credit packs.
10 credits one-time
100 credits per month
250 credits per month
Standard $29 per site per month ($290/year) or Deep $49 ($490/year). Daily pulse plus a weekly scan at the locked depth. Credits are not used. Agencies buy one seat per watched origin. Standard and Deep do not share spare seats.
Contact us for enterprise plans with unlimited scans and custom solutions.
What each subscription includes. Website Watch and pentest are sold separately.
Swipe to compare plans
| Feature | Free | ProBest value | Team | Enterprise |
|---|---|---|---|---|
| Credits & Scans | ||||
| Credits included | 10 signup bonus | 100/month | 250/month | Custom |
| Buy extra credits | ||||
| Credit rollover | ||||
| Max rollover | 200 credits | 500 credits | Custom policy | |
| Scheduled scans | Up to 3 | Up to 10 | Unlimited | |
| Reports & Access | ||||
| Dashboard and scan history | ||||
| Free public tools | ||||
| Basic security reports | ||||
| HTML, PDF, TXT, and JSON exports | ||||
| Compliance mappings on completed scans | ||||
| Email scan notifications | ||||
| Team & Automation | ||||
| Organization workspace | Owner only | Owner only | Up to 10 seats | Unlimited seats |
| Outbound webhooks | ||||
| Slack and Jira integrations | ||||
| API keys | Up to 5 | Unlimited | ||
| White-label report controls | ||||
| 14-day client report links | ||||
Platform-specific teams can start with free quick profiles and unlock comprehensive mode through account-backed workflows.
Quick profile plus full Joomla security scanner pathway.
Storefront checks and Shopify-focused security workflows.
WordPress footprint checks and deeper account-backed scans.
Common questions about vulnerability scanning cost, credits, and plan changes.
Vulnify uses pay-per-scan credits instead of opaque annual licenses. Subscriptions bundle monthly credits with rollover caps; pay-as-you-go packs let you buy credits when you need them. A standard scan costs 18 credits — compare live tiers above.
Vulnerability scanning cost depends on scan depth and credit packs. Start free with signup bonus credits, then choose subscription tiers or one-time bundles. No long-term contract — you pay for scans you actually run.
Vulnify vulnerability scanning pricing is listed transparently on this page: subscription monthly credits versus pay-as-you-go packs, with per-scan credit cost shown for each tier.
Vulnerability scanner pricing is credit-based — free public SSL, headers, and DNS tools need no signup; full OWASP-aligned scans use credits from subscriptions or purchased packs.
Vulnify pricing covers website and web application scanning. For internal network appliance licensing, teams often pair Vulnify DAST with dedicated network scanners — compare credit tiers here for internet-facing app coverage.
Website Watch is Standard $29 or Deep $49 per site per month ($290 or $490 yearly) for daily pulse plus a weekly scan at the depth you lock at checkout. Scheduled scans stay on credits for custom cadence and Comprehensive.
Subscription credits roll over to the next month up to the plan cap. For example, if you have a Pro plan and use 10 of your 100 monthly credits, the remaining 90 can roll over, giving you up to 190 available credits next month.
Yes! You can upgrade or downgrade your plan at any time. Upgrades take effect immediately with prorated charges. Downgrades take effect at the end of your current billing period.
No! Credits purchased through credit packages never expire. Only subscription credits have a rollover limit (2 months). You can mix subscription and purchased credits.
Absolutely! Even with a subscription, you can purchase additional credit packages anytime. These credits never expire and can be used alongside your subscription credits.
We accept all major credit cards (Visa, Mastercard, American Express) through our secure payment processor, Stripe. All transactions are encrypted and secure.
You can cancel anytime from your Dashboard under Billing settings. Your subscription will remain active until the end of your billing period, and you will keep all remaining credits.
Pay, consent, verify, confirm the engagement plan, then receive HTML and PDF. Reports are usually ready 30 to 60 minutes after testing starts. Included retests depend on the tier you order.
Wrapped industry engines
The same catalog wraps Nuclei, OWASP ZAP, SQLMap, and Playwright. Vulnify owns confirmation, evidence, and the report. These names are not partner badges.
Names identify software we wrap. No affiliation or endorsement.
$297
Automated evidence-backed testing with HTML, PDF, and one included retest
$497
Everything in Pen Test plus extra engines, up to five extra verified hosts tested, a two-role matrix, a detailed, actionable PDF for security specialists and developers, and two retests
Review scanner capabilities and platform features before you choose a credit tier.
Enroll from your account, complete Stripe Connect, share a readable partner code, and get paid through Stripe.
Sign in, enroll, then complete Stripe Connect before you can receive payouts. You get a partner code plus a shareable ?ref= link. Rewards apply to the first Pro or Team subscription and the first credit-pack purchase from each referred account. Clicks count for 90 days. Watch and pentest are not included.
Create or sign in to a Vulnify account, then enroll in the portal. Enrollment starts at a 20% payout rate. Stripe Connect is still required before you can be paid.
Stripe Connect is required to be a paid affiliate. Complete Stripe identity and bank setup from the portal. Rewards stay pending for 30 days, then pay out once your approved balance reaches $50.
Send your referral link or a vanity code people can type at signup. The first touch is attributed to you for 90 days. Self-referrals are blocked.
Create a free account for starter credits, or pick a plan that matches your workflow.