Scan in progress
Surface scan · 36 scannersChecking exposed services and public files
Find security issues before launch
700+ checks in under 2 minutes. Findings are free; paid plans unlock AI fix prompts.
No credit cardRead-only scanSee findings free
Checking exposed services and public files
NVD · CISA KEV · EPSS · OSV · OWASP Official security checker · SaaStore Featured on Let's AIThis product uses the NVD API but is not endorsed or certified by the NVD.
Attack surface coverage
UNPWNED coordinates multiple scanners across the exposed layers of your site, then turns the signals into one prioritized report.
Headers · CSP · cookies
Routes · CORS · forms · rate limits
TLS · DNS · email · ports
Secrets · CVEs · source maps · storage
Product walkthrough
The whole picture
A score is not enough. UNPWNED shows your overall posture, the findings that need attention first and the areas the scan covered.
Your overall state at a glance.
Start with the risks that matter most.
Where you stand, layer by layer.
Beyond the first scan
UNPWNED stays in the developer workflow after the score appears. Explore the core ways it turns security evidence into action.
Redacted, finding-specific instructions for the AI tool you already use.
app/static/chunks/config.js
client-visible bundleFix prompt ready →Fix a critical client-side exposure in a Next.js app.
Connected developer workflow
From source code to the final fix, UNPWNED connects, alerts, adapts and detects across the tools you already use.
Grouped by what each one actually does. None of them is a requirement.
Personal API key · your scan data only · built for developer clients
Opt-in Amendment 13 readiness checks · not certification
Every prompt is plain text, so it works in any AI tool. These are the ones we shape the output for.
A sample of what the scanner fingerprints. Scanning runs on any stack, listed here or not.
Read-only and revocable. This is the complete list; nothing else is ever connected.
Slack, Discord, or any endpoint you point a webhook at.
Brand marks identify compatible services and supported workflows. No partnership or endorsement is implied.
Questions
What developers ask before their first scan. More in the full FAQ.
Everything scans over the network - the same way a browser visits your site. We never access your source code, server, or database. GitHub scans use read-only tokens you can revoke anytime. All data encrypted with AES-256.
No tool catches everything - and we are upfront about that. But finding exposed .env files, leaked API keys, and missing security headers before an attacker does matters. Think of it as a pre-flight checklist, not a guarantee.
You can check this stuff manually for free, but it will take 40+ hours to cover what UNPWNED checks in under 2 minutes. Plus you would need to learn OWASP Top 10, HTTP security headers, DNS security, CSP policies, and repeat it after every deployment.
Bots do not check your company size. Automated scanners hit every domain on the internet looking for exposed .env files, open admin panels, and default credentials. If you are online, you are a target.
Free includes 2 scans a month and shows what is wrong: score, grade, severity, and all finding titles. Paid plans show how to fix it and add unlimited re-scans, fix verification, deep scans, full details, AI fix prompts, PDF reports, monitoring, and scan history. Solo costs $9/month or $90/year for 1 domain, Studio costs $29/month or $290/year for 5 domains, and Scale costs $49/month or $490/year for 15 domains.