Skip to main content
Back to Home

Frequently Asked Questions

Everything you need to know about UNPWNED and how it keeps your domains secure.

What does UNPWNED scan?

UNPWNED runs 800 security checks across 9 categories on your domain covering SSL/TLS analysis, security headers, exposed secrets, config file detection (.env, credentials.json, SSH keys), open ports, DNS configuration, cookie security, cloud misconfigurations, source code analysis, and more. Deep Scan adds active probing including CVE fingerprinting, error disclosure analysis, form security testing, and open redirect detection for verified domains. You can also connect your GitHub repositories for scheduled scans of secrets, dependencies, and config files.

Can I monitor my GitHub repos?

Yes. UNPWNED offers GitHub Repo Monitoring on paid plans. Connect your GitHub account via OAuth, select the repositories you want to monitor, and UNPWNED will run scheduled scans checking for leaked secrets (34+ patterns), vulnerable dependencies, and exposed config files like .env, credentials.json, and SSH keys. When issues are found, you get notified via email and webhooks, and UNPWNED can automatically create GitHub Issues in the affected repository so your team can track and resolve findings directly in your workflow.

Is it safe to scan my domain?

Yes. The standard scan performs read-only, non-intrusive checks - the same information any security researcher could find. Deep Scan performs active probing (testing HTTP methods, probing paths, etc.) but only on domains you've verified ownership of. We never attack, modify, or exploit your site.

How long does a scan take?

Most standard scans finish in a couple of minutes. Deep scans run many more checks and usually take several minutes. The exact time depends on how many checks apply and how quickly the site and external APIs respond. You'll receive a notification when your report is ready.

Why did my scan return results instantly?

If we recently scanned the same domain for another user, we serve a cached version of those results to you instead of running new scanners. This keeps things fast and prevents abuse. Cached results show severity counts and all finding titles. Detailed remediation guidance is reserved for paid users on fresh scans. To always get a fresh scan, verify your domain ownership or upgrade.

What's the difference between Free and the paid plans?

Free shows you what is wrong: 2 on-demand scans a month with severity breakdown, all finding titles, score and grade when coverage supports a reliable result, plus one (1) lifetime deep scan on a verified domain. Paid shows you how to fix it: full details and AI fix prompts, unlimited re-scans, unlimited deep scans, PDF export, scan history, score trends, continuous monitoring with CVE alerts, GitHub integration, and a security badge. Solo costs $9/month or $90/year for 1 domain, Studio costs $29/month or $290/year for 5 domains, and Scale costs $49/month or $490/year for 15 domains. Studio and Scale add priority support. Cancel anytime.

How does the AI report work?

After the scan completes, we feed the raw results into an AI engine that translates technical findings into plain-English explanations. Each vulnerability comes with a severity rating, a clear description of the risk, and step-by-step instructions to fix it. No security expertise required.

Do you store my scan data?

Yes, scan results and generated reports are stored securely in our database so you can access them anytime from your dashboard. All data is encrypted at rest and in transit. If you delete your account, all associated scan data is purged within 90 days. We never sell or share your data with third parties.

Can I share my report with my team?

Yes. Every report gets a unique shareable link (token-based URL) that you can send to teammates, clients, or stakeholders. The link provides read-only access to the report without requiring a login.

What if I find a critical vulnerability?

Don't panic. The AI report will explain exactly what the issue is and how to fix it with step-by-step instructions. For critical findings, we recommend addressing them immediately and running a follow-up scan to confirm the fix. If you need help, Studio and Scale subscribers get priority support.

Who built UNPWNED?

UNPWNED is built and maintained by Raz Azulay, an independent developer and founder. It started as a way to catch the security mistakes that slip into fast-moving and AI-assisted builds, and has grown into a full outside-in scanner.

How do I contact support?

Reach us anytime at [email protected]. Studio and Scale subscribers get priority response times. We typically respond within 24 hours.

Still Have Questions?

Reach out to us at [email protected] and we'll get back to you within 24 hours.

Start Scanning Free