One-time scans of your website or codebase. Real findings ranked by severity with OWASP, CVSS, and remediation guidance. PDF report delivered to your inbox.
Enter your URL, or upload a codebase for the report builder.
Step 2
Pay
Secure Razorpay checkout. Card details never touch our servers.
Step 3
Scan
The scanner runs every check. Close the tab, we email you when it’s done.
Step 4
Report
A professional PDF with findings, evidence and fixes.
Methodology drawn from
OWASP Top 10 2025
OWASP API Top 10
CWE Top 25
CVSS 3.1
PCI-DSS
NIST
15 categories. 70 individual probes.
Every check below runs on every audit. Each finding in your PDF includes the exact HTTP request that triggered it, the response we received, the CVSS 3.1 vector, the relevant OWASP and CWE references, and concrete remediation steps.
Deployment
4 probes
Configuration mistakes on production servers. Outdated software, debug modes left on, internal files leaked through the web.
Known vulnerable software versions
Verbose error messages
Development artifacts in production
Directory listing
Information Disclosure
5 probes
Recon data you leak to attackers without realising. Server versions, internal comments, framework fingerprints.
Verbose server banners
Sensitive HTML comments
Exposed metadata files
Stack fingerprintability
CMS version disclosure in HTML
Transport Security
6 probes
HTTPS configuration, certificate validity, redirect behaviour, and protection against downgrade attacks.
HTTPS is enforced
Valid TLS certificate
HTTP redirects to HTTPS
HTTP Strict Transport Security
Mixed content
CAA DNS record
Security Headers
5 probes
Browser security primitives that block whole classes of attack when configured correctly.
Content-Security-Policy
X-Frame-Options
X-Content-Type-Options
Referrer-Policy
Permissions-Policy
Cookies and Sessions
5 probes
How cookies are scoped, who can read them, and whether they protect session integrity correctly.
The JavaScript bundles you ship to browsers. Leaked secrets, unsafe inline handlers, missing integrity checks.
Hardcoded secrets in JavaScript
Inline event handlers
Subresource Integrity (SRI)
Email Security
3 probes
DNS level email authentication that stops your domain being spoofed.
SPF record
DMARC record
DKIM signing
DNS
2 probes
Domain level reconnaissance. What an attacker finds before touching your site.
Discoverable subdomains
Unauthorized DNS zone transfer
Network
5 probes
Network level checks against the target host, including a scan of the top 1000 TCP ports.
Unnecessary open TCP ports
Outdated services on open ports
Admin endpoints on the internet
Sensitive files reachable over HTTP
/.well-known/security.txt
SEO and Discoverability
6 probes
Search engine and crawler signals, in the audit because a site nobody can find has a different problem.
robots.txt
sitemap.xml
Page titles
Meta descriptions
Open Graph tags
Viewport meta tag
Site Quality
7 probes
Hygiene checks that signal a professionally maintained site, and catch simple production mistakes.
Valid HTML doctype
lang attribute on html
h1 usage
Alt text on images
console.log in production
Excessive HTML page weight
Favicon
A 40 to 70 page PDF. Password protected.
Within about 5 to 10 minutes of payment you get an email with a signed download link. The PDF uses AES-256 encryption and the password is in the same email. The format follows the layout professional pentest firms use: same sections, same severity scheme, same evidence requirements.
01
Executive summary
One page for non technical stakeholders. Count by severity, top three risks, business impact, recommended next steps.
02
Methodology and scope
What was tested, how, what was out of scope, what tools were used. This is the section a compliance auditor reads.
03
Findings table
Every finding with severity, CVSS 3.1 vector, CWE reference, OWASP category and status.
04
Per finding detail
Description, technical impact, the exact HTTP request that triggered it, response evidence, proof of concept payload, and remediation with code samples.
05
OWASP and CWE mapping
A cross reference table mapping each finding to OWASP Top 10 2025, CWE Top 25, and where applicable NIST and PCI-DSS controls.
06
Appendices
Full request and response logs for confirmed findings, a TLS report card, scan timing data, and the complete checklist of all 117 distinct tests performed.
07
One free rescan
Fix the issues, then rerun the entire scan once at no extra cost, any time within 7 days of delivery. Confirm your remediation worked and get a fresh report, free.
Every check says how sure it is
Classes that need a human are marked honestly rather than guessed. The false positive rate on confirmed findings is under 2% on our internal benchmark.
Failed
An issue was confirmed with concrete evidence. An XSS canary reflected unescaped, or a SQL injection payload that changed the query result.
Passed
Tested, no issue found.
Not Detected
Actively probed with several techniques but nothing confirmed. Full assurance on these classes needs a manual test.
Not Tested
Needs authenticated access, a second account or human reasoning, so it is out of scope for an unauthenticated scan.
Severity scheme
Critical
High
Medium
Low
Info
What’s in, what’s out
Be honest with yourself. This is automated black box testing, not a manual pentest by a human. It catches what humans test for first, fast and at scale, but it does not replace a manual engagement for complex application logic flaws. We sell that too, further down.
Included
Reflected XSS in standard contexts
SQL injection, error based, boolean based and time based blind
Path traversal and LFI probing
Directory and subdomain bruteforce
Permissive CORS policies
Login rate limit testing
JavaScript secret scanning
Security header audit
TLS configuration audit
Cookie attribute audit
Information disclosure
Common file exposure, .git and .env
TCP port scan and service version detection, top 1000 ports
Not included
Stored XSS, needs authenticated access
Business logic flaws
Privilege escalation testing
Authenticated session attacks
Social engineering and phishing
Physical security testing
Denial of service and load testing
Brute force on real user accounts
Mobile app testing
Deep network testing beyond a port scan
Manual exploit chain development
Post exploitation activities
Against a traditional pentest engagement
We are not pretending to be a boutique pentest firm. We fill a different gap: fast, cheap, automated checks for the things that actually get exploited in the wild.
Attribute
A pentest consultant
Growthzi Secure Audit
Price
₹50,000 to ₹5,00,000
$19.99 one time
Turnaround
2 to 6 weeks
5 to 10 minutes
Coverage
Custom logic flaws
OWASP Top 10 and common misconfigurations
Methodology
Manual plus tooling
Automated black box
Retest included
Usually
Yes, one free rescan within 7 days
NDA required
Yes
No, a consent form only
Best for
Compliance audits, complex applications
Pre launch checks, ongoing assurance
Human delivered, expert tier
A real pentester tests what the scanner couldn’t.
Automated scans confirm the obvious. The findings that actually get companies breached, business logic flaws, broken access control between accounts, chained exploits, stored XSS, need a human. Our pentesters pick up exactly where your automated report’s Not Tested and Not Detected items leave off.
1
Tell us the scope
We pull in the pending items from your automated report automatically.
2
We scope and quote
A pentester reviews it and we confirm scope and a fixed price. No surprises.
3
Pay 20% to start
A secure deposit link kicks off the engagement. Testing begins once it is paid.
4
Delivered in 4 to 7 days
Pay the balance and the password protected report lands in your inbox.
No payment now. This is a human delivered service billed separately from the automated scan. We confirm scope and a fixed price with you before you pay anything.
What a finding looks like
Every issue in the report follows this shape. Severity, evidence, fix. One page, no digging.
F-003HighCVSS 8.2A03:2021 Injection
Reflected XSS on /search
Description
The `q` query parameter is reflected into the DOM without escaping. An attacker can craft a URL that runs arbitrary JavaScript in a visitor's browser.
Recommended fix
Encode `q` on output with a context-aware escaper. Add a Content-Security-Policy that blocks inline scripts.
Your data, handled properly
Payment card details never touch our servers. Razorpay processes them directly. Everything is encrypted in transit (TLS) and at rest, reports auto-delete after 30 days, and we never sell your data or share it for advertising. We only scan sites you own or are authorised to test.
Fixed it? Now keep it fixed.
An audit tells you what is wrong today. It goes stale the next time anyone touches the site, and most sites get touched weekly. Monitoring watches uptime, certificates, attacks and every file that changes, and tells you the moment one of them moves.
Most scans finish within ten minutes. Pentests can take 15 to 30 minutes depending on the size of the target. You can close the tab, we email the report when it is ready.
No. All probes are non-destructive and rate-limited. Nothing is modified or deleted.
No. You must own the domain or hold written authorisation to test it. You confirm authorization at checkout. Scanning without permission may be illegal.
A 40-70 page PDF: every finding ranked by severity, with the exact request used as evidence, CVSS vectors, OWASP mapping and step-by-step remediation.
Yes. The report PDF is encrypted and delivered via an email-verified, signed-token link. You verify your email to retrieve it.
Yes. One free rescan is included within 7 days. Open your report page and click Request free rescan to confirm the fixes worked.
Reports auto-delete after 30 days. Data is encrypted in transit (TLS) and at rest. We never sell your data or share it for advertising.
It is for security consultants. Bring your own findings and it produces a branded, client-ready PDF with AI-assisted wording. $5.99 per report, unlimited findings, 30-day edit window.
Build your AI business platform in 60 seconds.
Website. Industry CRM. AI social media manager. One AI conversation. Free to start.