NewEvery finding now mapped to CWE, OWASP Top 10 & CVSS

//Pricing

Finding out is free.

Every check runs on the free tier. You never have to pay to learn where you stand. Pro is for the work that follows.

Free

$0

forever

A full external scan of your live app, with every check we run.

  • One free scan per website
  • Every check runs, nothing is skipped
  • Your worst finding in full, with proof and the fix
  • Grade, severity counts and headline
  • CWE, OWASP and CVSS on every finding
  • Live-key verification status
Run your free scan

no account · no card

Pro

$19 / mo

billed monthly

Everything in Free, plus the part that comes after finding out.

  • Every finding in full, evidence and the exact fix
  • Unlimited rescans, so you can confirm a fix worked
  • Toxic combinations: how your findings compound
  • Scan history across every project you own
  • Markdown export for issues, docs and agents
  • Connect your database for a live schema & RLS audit
  • Scheduled rescans & drift alerts
  • Git-history secret scan (flare-deep CLI)
  • Private, password-protected reportssoon
Sign in to upgrade

free account · takes 20 seconds

Enterprise

Custom pricing.

For orgs scanning many apps, wiring Flare into CI at scale, or needing SSO and a contract. We price to the footprint, not a seat multiplier.

  • Volume pricing across many apps and teams
  • SSO, invoice billing and a named contact
  • Custom SLAs, retention and data residency
  • Priority support for CI and MCP rollouts
Talk to us

usually a same-week reply

If the free scan comes back clean, you don’t need Pro. That’s a good outcome, and we’d rather you reached it than paid us for reassurance.

Every difference, in full

FeatureFreePro
// scanning
Scans per website1Unlimited
Rescan to confirm a fixNot includedIncluded
Every detection runsIncludedIncluded
Scheduled rescans & drift alertsNot includedIncluded
// results
Grade, headline and severity countsIncludedIncluded
CWE · OWASP · CVSS on every findingIncludedIncluded
Live-key verification statusIncludedIncluded
Findings shown in fullWorst oneAll
Evidence and fix for every findingNot includedIncluded
Toxic-combination analysisCount onlyIncluded
// detection
Secrets in client bundlesIncludedIncluded
Live-key verificationIncludedIncluded
Server-to-client (RSC) leaksIncludedIncluded
NEXT_PUBLIC_ secret detectionIncludedIncluded
Shadow API routesIncludedIncluded
Tokens in URLsIncludedIncluded
Supabase & Firebase exposureIncludedIncluded
Security headers, CORS & cookiesIncludedIncluded
Exposed .env / .git / backupsIncludedIncluded
SPF & DMARCIncludedIncluded
Per-table RLS & policy audit (live schema)Not includedIncluded
Migration-history reviewIncludedIncluded
Git-history secret scan (flare-deep CLI)IncludedIncluded
Dependency CVE lookup (OSV)IncludedIncluded
// workflow
JSON APIIncludedIncluded
MCP server (Cursor, Claude Code, Windsurf)IncludedIncluded
Markdown exportNot includedIncluded
Scan history & dashboardNot includedIncluded
Private, password-protected reportsNot includedPlanned
CLI & GitHub Action (runs locally)IncludedIncluded
Fail the build on critical findingsIncludedIncluded

Questions

What does “one free scan per website” mean?+

You can scan any number of different websites for free, once each. Rescanning the same site after a fix is a Pro feature, because that fix-and-confirm loop is the part teams use day to day.

Is the free tier limited in what it detects?+

No. Every external check runs on free, including live-key verification, you see your grade, every severity count, and your worst finding in full. Pro adds the evidence and fix for the rest, the compound-risk analysis, unlimited rescans, history and Markdown export. Connected scanning of your live database (per-table RLS & policy audit) is available today; full git-history secret scanning is still on the roadmap and marked as such above.

Do I need an account to scan?+

No. Paste a public URL and you get a report, no login, no repo access, no card. An account only matters once you want scan history and rescans.

How does billing work?+

Monthly, on a card, through Stripe Checkout, so we never see or store your card details. Cancel any time from the billing portal, and you keep Pro until the end of the period you’ve paid for.

Can I use it on client work?+

Yes, on apps you own or are authorised to test. Every check is read-only, but permission is about intent, not just impact.

read-only checksno repo accesscancel any time

Not sure yet? Run your free scan and decide with a real report in front of you.