
ABOUT
What is UNPWNED?
UNPWNED is an outside-in, AI-aware web security scanner. A free scan runs 223 automated checks against a website in a couple of minutes; the full suite is 800 checks across websites and GitHub repositories. Free reports show what is wrong; paid reports from $9/month unlock full details and copy-paste AI fix prompts that show how to fix it. It is built for indie hackers, vibe coders, SaaS founders, and small teams who need fast, accessible security feedback before launch, not a $50,000 pentest or an enterprise scanner with a sales call.
Who is UNPWNED for?
UNPWNED is built for solo developers, indie hackers, and small teams shipping fast - especially developers who build with AI coding tools (Cursor, Lovable, Bolt, Replit, v0, Base44, Windsurf). It is also useful for SaaS founders running a pre-launch security check, agencies validating client work before handover, and Supabase or Firebase users who need to confirm their RLS rules and storage policies are tight.
What does UNPWNED scan?
UNPWNED scans live websites by domain and GitHub repositories by OAuth. The standard scan covers SSL/TLS configuration, HTTP security headers, exposed secrets and config files, Supabase and Firebase access, common API routes, CORS, DNS and email authentication, open ports, technology and AI-builder fingerprints, version-linked CVEs, privacy signals, and source-code secrets in connected GitHub repos. Verified Deep Scan adds broader sensitive-path, HTTP-method, JavaScript-library, form, redirect, error-disclosure, subdomain, and cloaking checks.
What makes UNPWNED different from other scanners?
Three things. First, Free reports show what is wrong, while paid reports include the full details and fix prompts tailored to the developer's AI coding tool. UNPWNED understands the gap between "you have a CSP problem" and "here is the exact policy to paste into your Next.js middleware". Second, it is purpose-built for code generated by AI tools, which has a distinct vulnerability profile (exposed Supabase keys, missing RLS, hardcoded credentials in client bundles, open CORS) compared to hand-written code. Third, the pricing model fits indie developers, with paid plans starting at $9/month rather than $500+/month enterprise pricing.
Is UNPWNED a penetration test replacement?
No. UNPWNED is an automated outside-in scanner, not a human-led penetration test. A real pentest involves manual exploit chaining, threat modeling, and creative attacks that automated tools cannot replicate. UNPWNED is best used as a pre-pentest baseline for common externally observable issues, so a human pentester can spend time on harder, higher-value attack paths. UNPWNED also does not replace runtime protection like a WAF, firewall, or DDoS mitigation.
Is UNPWNED safe to run on my domain?
Yes. The standard scan sends non-destructive requests only to the public attack surface and never writes, modifies, or deletes site data. Additional Deep Scan probes are gated behind domain ownership verification and run only on domains you explicitly verify (via DNS TXT record, file upload, or meta tag).
When should you use UNPWNED?
Run UNPWNED before every public launch, after every meaningful deploy, and on a continuous monthly schedule once you are live. Paid plans include scheduled monitoring with alerts on new findings or newly disclosed CVEs affecting your dependencies. The ideal moment to run a first scan is the day before launch, when there is still time to fix what comes back.
Who builds UNPWNED
UNPWNED is built and maintained by Raz Azulay, an independent developer and founder. It started as a personal tool to catch the security mistakes that slip into fast-moving and AI-assisted builds - exposed keys, missing RLS, absent security headers - and grew into a full outside-in scanner. It is run as a focused, independent product, not a faceless platform: when you email [email protected], you reach the person who builds it.
REAL TELEMETRY
See the data behind the scanner
59% of sites have no rate limiting. 58% have no CSP. Real telemetry, updated continuously.
METHODOLOGY
How the scanner actually works
Step-by-step breakdown of what each scanner does and how findings are scored.
Try it on your domain
Free scan, no signup required. 223 checks in a couple of minutes.