# UNPWNED > Security scanner for developers who ship fast. A public check runs 149 bounded checks for externally observable signals. The currently enabled Deep Scan has up to 702 configured checks after current ownership verification. The scanners are deterministic and AI does not invent findings. ## About UNPWNED is a security scanning platform at https://unpwned.io that detects vulnerabilities in live websites and connected GitHub repositories. A public check runs 149 bounded checks for headers, DNS, certificate-transparency and technology signals. Current ownership verification unlocks the 428-check surface suite. The currently enabled Deep Scan has up to 702 configured checks. Findings, scores and remediation guidance are deterministic. Claude may draft only the optional executive summary. Tagline: "Scan Before You Get Pwned" ## What It Scans UNPWNED's currently enabled external Deep Scan is organized across 9 web-scan categories: - **Secrets & Credentials** - **Browser Security Controls** - **SSL/TLS Configuration** - **Authentication & APIs** - **DNS & Email Security** - **Database & Storage Exposure** - **Dependencies & CVEs** - **Content Integrity** - **Compliance Signals** ## Key Features - 149 bounded checks in a public check; 428 surface checks after current ownership verification; up to 702 configured checks in the currently enabled Deep Scan after current ownership verification - Deterministic plain-English remediation guidance and AI-ready Fix Prompts for detected findings - Supports scanning both live websites (by domain) and GitHub repositories (via OAuth) - GitHub Repo Monitoring: scheduled scans of connected repositories for secrets, dependencies, and config files with email alerts, webhook notifications, and automatic GitHub Issue creation - Deep Scan with active probing: CVE fingerprinting, error disclosure analysis, form security testing, and open redirect detection - Config file detection: identifies exposed .env files, credentials.json, SSH keys, and other sensitive files - OWASP Top 10 coverage across multiple attack categories - Security score grading from A through F - PDF report export for stakeholders and compliance (paid) - Score trend tracking over time (paid) - Domain verification via DNS TXT record or file upload - Copy-paste fix prompts tailored for 14+ AI coding tools and platforms - Security blog with developer-focused articles on web security best practices - Referral program: invite others and earn rewards - Automated email drip onboarding sequence for new users ## Platform Integrations UNPWNED generates ready-to-use fix prompts optimized for the tools developers already use: - ChatGPT - Claude - Cursor - GitHub Copilot - Lovable - Bolt - Replit - Gemini - VS Code - Windsurf - WordPress - V0 - Elementor - Base44 ## Pricing Plans are domain-based: you pay for the domains you actively monitor, with unlimited re-scans of them (fair use). - Free: $0 - 2 scans per month that show completed findings, severity counts, every detected problem type with occurrence counts, and an assessed score when eligible; an official grade and active checks require current ownership verification - Solo: $9/month or $90/year ($7.50/month) - for solo founders, 1 monitored domain, unlimited re-scans - Studio: $29/month or $290/year ($24.17/month) - 5 monitored domains, unlimited re-scans - Scale: $49/month or $490/year ($40.83/month) - 15 monitored domains, unlimited re-scans - All paid plans include: full finding details, AI fix prompts, PDF report export, score trends, continuous monitoring with CVE alerts, GitHub integration, public security badge - Studio and Scale add priority support; Scale adds early access to new checks - No per-seat fees ## Use Cases - Vibe coders scanning AI-generated apps before going live - Indie hackers checking their SaaS for security hygiene before launch - Developers auditing projects for leaked secrets, misconfigurations, and missing headers - Teams verifying security posture after deployment or infrastructure changes - BaaS users (Supabase, Firebase) validating that security rules are properly configured - WordPress and no-code site owners running a quick, comprehensive security audit - Anyone wanting a plain-English security report without hiring a penetration tester ## Target Audience - Developers building with AI coding tools (Cursor, Copilot, Claude, ChatGPT, and more) - Vibe coders using platforms like Lovable, Bolt, Replit, V0, Base44, and similar tools - Indie hackers and solo SaaS builders - Small teams without dedicated security engineers - WordPress and no-code site owners - Anyone shipping code generated by AI who wants confidence it's secure ## CVE Radar UNPWNED publishes a public CVE Radar at https://unpwned.io/cve covering the vulnerabilities most likely to be exploited. Unlike static CVE databases, each entry is ranked by real exploitation signal (CISA Known Exploited Vulnerabilities status and FIRST.org EPSS exploit probability, not social media hype) and, where the data supports it, shows what share of the sites UNPWNED scans run the affected technology. Every CVE page links straight to a free scan so a reader can check whether their own site is exposed. An RSS feed of the current set is available at https://unpwned.io/cve/rss.xml. ## Links - Website: https://unpwned.io - CVE Radar: https://unpwned.io/cve - actively exploited and high-risk CVEs ranked by CISA KEV and EPSS, each with a "check if your site is exposed" scan link - CVE Radar RSS feed: https://unpwned.io/cve/rss.xml - Pricing: https://unpwned.io/pricing - Comparisons: https://unpwned.io/compare - honest comparisons vs manual security checks, built-in platform security, free single-purpose scanners (SSL Labs, securityheaders.com, MDN Observatory), Vibe App Scanner, VibeEval, SafeToShip, Snyk, Detectify, and Intruder - Jurisdiction-Aware Compliance: https://unpwned.io/jurisdiction-aware-compliance - optional, opt-in, per-domain regulatory-readiness layer separate from the security scan. Israel is live: the Israeli Privacy Readiness package produces a Tikun 13 Technical Readiness Score from public technical signals only. It is technical readiness, NOT legal advice, a compliance determination, or a certification, and it never affects the security score, grade, or public badge - FAQ: https://unpwned.io/faq - Privacy Policy: https://unpwned.io/privacy - Terms of Service: https://unpwned.io/terms - Blog: https://unpwned.io/blog - Security: https://unpwned.io/security