Pricing
Priced per monitored site, all core features included at each tier — the number of sites in your portfolio is the only thing that changes your bill.
| Plan | Price | What's included |
|---|---|---|
| Free scan | $0 | Unlimited one-off passive scans, no ongoing monitoring |
| Monitored + Connector | $14 / site / mo | Advisory matching, multi-site dashboard, remediation commands, historical trends, attack surface scanning, blast-radius incidents, mean time to patch, known-exploited prioritization, confirmed version accuracy, config drift detection, permissions & hardening audit, unmaintained module flagging, email/Slack/webhook alerts, white-label PDF reports, cross-site benchmarking |
Volume discounts apply automatically above 25 sites. No credit card required for the free scan.
FAQ
A small Drupal module you optionally install on a monitored site. It reports your exact module versions, PHP version, and config drift on a schedule — turning a "possible exposure" finding into a confirmed one, and enabling white-label reports and benchmarking.
No. The free plan works from a passive external scan alone — no credentials, no module install. The connector is what upgrades findings from "possible" to "confirmed," and is required for the Monitored + Connector plan's features.
Drupal 9, 10, and 11. The connector module targets Drupal 10/11 APIs; passive scanning works on any publicly reachable Drupal site regardless of version.
We store what's needed to detect and track findings — module names and versions, PHP version, and scan history. We don't access site content, user data, or databases.
Yes, month to month, no lock-in contract. Volume discounts apply automatically as your monitored site count grows, with no separate negotiation needed.
If you're managing 25+ sites or want white-label billing for your own clients, get in touch — we can talk through a volume or reseller arrangement.
No credit card, no commitment — see what's actually running on a site in under a minute.