Nullstack
Deno
UNPWNED
Sucuri
Qualys
Vibe App Scanner
Detectify
HostedScan.com
Socket
Intruder
UNPWNED is a passive web security scanner that runs 700+ automated checks against websites and GitHub repositories in under two minutes. It detects misconfigurations, leaked API keys and secrets, weak HTTP security headers, SSL/TLS issues, DNS and email auth gaps (DNSSEC, SPF, DKIM, DMARC), exposed config files (.env, credentials.json, SSH keys), Supabase and Firebase RLS problems, open API routes, dependency vulnerabilities, and more.
Every finding comes back in plain English with a copy-paste AI Fix Prompt that developers can paste into Cursor, Claude, ChatGPT, GitHub Copilot, Lovable, Bolt, Replit, v0, or any other AI coding agent โ turning security findings into one-shot fixes.
Built for: indie hackers, vibe coders, AI-builders, SaaS founders, and small teams shipping fast on Cursor / Lovable / Bolt / Replit / v0 / Base44.
Not a pentest replacement. UNPWNED is automated and passive (Deep Scan with active probing requires domain ownership verification). It is best used as a pre-launch and post-deploy hygiene check, plus continuous monitoring on Pro plans.
Pricing: Free plan includes 5 scans/month. Pro plans start at $9/mo and add unlimited fix prompts, PDF reports, scan history, GitHub repo monitoring with auto-issue creation, continuous monitoring with CVE alerts, and priority support.
The UNPWNED CLI (npm install -g unpwned) is open-source on GitHub. The hosted scanner platform itself is a closed-source SaaS.
Nullstack
UNPWNEDNo UNPWNED videos yet. You could help us improve this page by suggesting one.
Deno - A secure runtime for JavaScript and TypeScript built with V8, Rust, and Tokio.
Sucuri - Website Protection, Malware Removal, and Blacklist Prevention