Growthzi Secure · Audit

Find what’s broken before your users do.

One-time scans of your website or codebase. Real findings ranked by severity with OWASP, CVSS, and remediation guidance. PDF report delivered to your inbox.

Get Website Security report 15 categories · 70 probes · results in minutes
110 sites secured to date
What the scan actually does
Fifteen categories, seventy probes, and a finding you can hand to a developer.

Active Pentest

$19.99 per target

For site owners who need to know where they stand.

  • Reflected XSS & SQL injection
  • Path traversal & CORS tests
  • JavaScript secret scanning
  • Authentication & session flaws
  • Security headers & TLS
  • Subdomain enumeration
  • Directory bruteforce
  • CVSS vectors & OWASP mapping
  • 40–70 page report
  • One free rescan within 7 days
Get Website Security report

Report Builder

$5.99 per report

For consultants who already have the findings.

  • Your logo on the cover page
  • Unlimited findings per report
  • Up to 2 screenshots per finding
  • AI-assisted wording (optional)
  • CVSS and OWASP fields built in
  • Password-protected PDF option
  • 30-day edit window after payment
  • No subscription
Get Website Security report

How it works

Step 1

Submit

Enter your URL, or upload a codebase for the report builder.

Step 2

Pay

Secure Razorpay checkout. Card details never touch our servers.

Step 3

Scan

The scanner runs every check. Close the tab, we email you when it’s done.

Step 4

Report

A professional PDF with findings, evidence and fixes.

Methodology drawn from
  • OWASP Top 10 2025
  • OWASP API Top 10
  • CWE Top 25
  • CVSS 3.1
  • PCI-DSS
  • NIST

15 categories. 70 individual probes.

Every check below runs on every audit. Each finding in your PDF includes the exact HTTP request that triggered it, the response we received, the CVSS 3.1 vector, the relevant OWASP and CWE references, and concrete remediation steps.

Deployment

4 probes

Configuration mistakes on production servers. Outdated software, debug modes left on, internal files leaked through the web.

  • Known vulnerable software versions
  • Verbose error messages
  • Development artifacts in production
  • Directory listing

Information Disclosure

5 probes

Recon data you leak to attackers without realising. Server versions, internal comments, framework fingerprints.

  • Verbose server banners
  • Sensitive HTML comments
  • Exposed metadata files
  • Stack fingerprintability
  • CMS version disclosure in HTML

Transport Security

6 probes

HTTPS configuration, certificate validity, redirect behaviour, and protection against downgrade attacks.

  • HTTPS is enforced
  • Valid TLS certificate
  • HTTP redirects to HTTPS
  • HTTP Strict Transport Security
  • Mixed content
  • CAA DNS record

Security Headers

5 probes

Browser security primitives that block whole classes of attack when configured correctly.

  • Content-Security-Policy
  • X-Frame-Options
  • X-Content-Type-Options
  • Referrer-Policy
  • Permissions-Policy

Cookies and Sessions

5 probes

How cookies are scoped, who can read them, and whether they protect session integrity correctly.

  • Secure flag on cookies
  • HttpOnly flag on cookies
  • SameSite attribute
  • __Host- or __Secure- prefix
  • Cache-Control: no-store

Authentication

4 probes

Login forms. Discoverable, rate limited, CSRF protected, with sensible password policies.

  • Login form discoverability
  • Rate limiting on login
  • CSRF on state-changing forms
  • Password policy strength

Injection

9 probes

The classic exploit categories, and the largest group in the audit because this is what gets sites breached.

  • SQL injection
  • Reflected XSS
  • Command injection
  • Path traversal
  • Open redirect
  • Host header injection
  • XML External Entity (XXE)
  • Server-Side Request Forgery
  • Server-Side Template Injection

Authorization

2 probes

Once a user is logged in, can they see or do things they should not?

  • Exposed administrative interfaces
  • IDOR, insecure direct object references

API Security

4 probes

Surface level API misconfigurations. Permissive CORS, unsafe methods, GraphQL introspection, JWT pitfalls.

  • CORS misconfiguration
  • Dangerous HTTP methods
  • GraphQL introspection
  • JWT implementation

Client-Side

3 probes

The JavaScript bundles you ship to browsers. Leaked secrets, unsafe inline handlers, missing integrity checks.

  • Hardcoded secrets in JavaScript
  • Inline event handlers
  • Subresource Integrity (SRI)

Email Security

3 probes

DNS level email authentication that stops your domain being spoofed.

  • SPF record
  • DMARC record
  • DKIM signing

DNS

2 probes

Domain level reconnaissance. What an attacker finds before touching your site.

  • Discoverable subdomains
  • Unauthorized DNS zone transfer

Network

5 probes

Network level checks against the target host, including a scan of the top 1000 TCP ports.

  • Unnecessary open TCP ports
  • Outdated services on open ports
  • Admin endpoints on the internet
  • Sensitive files reachable over HTTP
  • /.well-known/security.txt

SEO and Discoverability

6 probes

Search engine and crawler signals, in the audit because a site nobody can find has a different problem.

  • robots.txt
  • sitemap.xml
  • Page titles
  • Meta descriptions
  • Open Graph tags
  • Viewport meta tag

Site Quality

7 probes

Hygiene checks that signal a professionally maintained site, and catch simple production mistakes.

  • Valid HTML doctype
  • lang attribute on html
  • h1 usage
  • Alt text on images
  • console.log in production
  • Excessive HTML page weight
  • Favicon

A 40 to 70 page PDF. Password protected.

Within about 5 to 10 minutes of payment you get an email with a signed download link. The PDF uses AES-256 encryption and the password is in the same email. The format follows the layout professional pentest firms use: same sections, same severity scheme, same evidence requirements.

01

Executive summary

One page for non technical stakeholders. Count by severity, top three risks, business impact, recommended next steps.

02

Methodology and scope

What was tested, how, what was out of scope, what tools were used. This is the section a compliance auditor reads.

03

Findings table

Every finding with severity, CVSS 3.1 vector, CWE reference, OWASP category and status.

04

Per finding detail

Description, technical impact, the exact HTTP request that triggered it, response evidence, proof of concept payload, and remediation with code samples.

05

OWASP and CWE mapping

A cross reference table mapping each finding to OWASP Top 10 2025, CWE Top 25, and where applicable NIST and PCI-DSS controls.

06

Appendices

Full request and response logs for confirmed findings, a TLS report card, scan timing data, and the complete checklist of all 117 distinct tests performed.

07

One free rescan

Fix the issues, then rerun the entire scan once at no extra cost, any time within 7 days of delivery. Confirm your remediation worked and get a fresh report, free.

Every check says how sure it is

Classes that need a human are marked honestly rather than guessed. The false positive rate on confirmed findings is under 2% on our internal benchmark.

Failed

An issue was confirmed with concrete evidence. An XSS canary reflected unescaped, or a SQL injection payload that changed the query result.

Passed

Tested, no issue found.

Not Detected

Actively probed with several techniques but nothing confirmed. Full assurance on these classes needs a manual test.

Not Tested

Needs authenticated access, a second account or human reasoning, so it is out of scope for an unauthenticated scan.

Severity scheme
  • Critical
  • High
  • Medium
  • Low
  • Info

What’s in, what’s out

Be honest with yourself. This is automated black box testing, not a manual pentest by a human. It catches what humans test for first, fast and at scale, but it does not replace a manual engagement for complex application logic flaws. We sell that too, further down.

Included

  • Reflected XSS in standard contexts
  • SQL injection, error based, boolean based and time based blind
  • Path traversal and LFI probing
  • Directory and subdomain bruteforce
  • Permissive CORS policies
  • Login rate limit testing
  • JavaScript secret scanning
  • Security header audit
  • TLS configuration audit
  • Cookie attribute audit
  • Information disclosure
  • Common file exposure, .git and .env
  • TCP port scan and service version detection, top 1000 ports

Not included

  • Stored XSS, needs authenticated access
  • Business logic flaws
  • Privilege escalation testing
  • Authenticated session attacks
  • Social engineering and phishing
  • Physical security testing
  • Denial of service and load testing
  • Brute force on real user accounts
  • Mobile app testing
  • Deep network testing beyond a port scan
  • Manual exploit chain development
  • Post exploitation activities

Against a traditional pentest engagement

We are not pretending to be a boutique pentest firm. We fill a different gap: fast, cheap, automated checks for the things that actually get exploited in the wild.

AttributeA pentest consultantGrowthzi Secure Audit
Price₹50,000 to ₹5,00,000$19.99 one time
Turnaround2 to 6 weeks5 to 10 minutes
CoverageCustom logic flawsOWASP Top 10 and common misconfigurations
MethodologyManual plus toolingAutomated black box
Retest includedUsuallyYes, one free rescan within 7 days
NDA requiredYesNo, a consent form only
Best forCompliance audits, complex applicationsPre launch checks, ongoing assurance
Human delivered, expert tier

A real pentester tests what the scanner couldn’t.

Automated scans confirm the obvious. The findings that actually get companies breached, business logic flaws, broken access control between accounts, chained exploits, stored XSS, need a human. Our pentesters pick up exactly where your automated report’s Not Tested and Not Detected items leave off.

  1. 1

    Tell us the scope

    We pull in the pending items from your automated report automatically.

  2. 2

    We scope and quote

    A pentester reviews it and we confirm scope and a fixed price. No surprises.

  3. 3

    Pay 20% to start

    A secure deposit link kicks off the engagement. Testing begins once it is paid.

  4. 4

    Delivered in 4 to 7 days

    Pay the balance and the password protected report lands in your inbox.

No payment now. This is a human delivered service billed separately from the automated scan. We confirm scope and a fixed price with you before you pay anything.

What a finding looks like

Every issue in the report follows this shape. Severity, evidence, fix. One page, no digging.

F-003HighCVSS 8.2A03:2021 Injection

Reflected XSS on /search

Description
The `q` query parameter is reflected into the DOM without escaping. An attacker can craft a URL that runs arbitrary JavaScript in a visitor's browser.
Recommended fix
Encode `q` on output with a context-aware escaper. Add a Content-Security-Policy that blocks inline scripts.
One of 40 to 70 pages. Each report includes proof-of-concept requests, screenshots where relevant, and step-by-step remediation.

Your data, handled properly

Payment card details never touch our servers. Razorpay processes them directly. Everything is encrypted in transit (TLS) and at rest, reports auto-delete after 30 days, and we never sell your data or share it for advertising. We only scan sites you own or are authorised to test.

Fixed it? Now keep it fixed.

An audit tells you what is wrong today. It goes stale the next time anyone touches the site, and most sites get touched weekly. Monitoring watches uptime, certificates, attacks and every file that changes, and tells you the moment one of them moves.

See monitoring

Frequently Asked Questions

Build your AI business platform in 60 seconds.

Website. Industry CRM. AI social media manager. One AI conversation. Free to start.

Get StartedNo credit cardLive in 60s
Chat on WhatsApp
Loading your dashboard