New: Active Pentest Package — Try it free
BreakMesh shield BreakMesh – Vulnerability Simulator & Cyber Range

Scanner packages

Every scan package, in one place

Each package is a focused set of non-destructive checks you can run independently against a verified target. Pick one, or run several to build full coverage.

Passive scan packages

Basic Hygiene

Headers, HTTPS, TLS, cookies, server disclosure, and exposure checks.

15 checks

Learn more

OWASP Starter

CORS, CSP, source maps, open redirects, directory listings, and sensitive files.

14 checks

Learn more

Threat Readiness

WAF/CDN, bot, rate-limit, DDoS readiness, and origin exposure signals.

8 checks

Learn more

Auth & Session

Login, reset, rate-limit, enumeration, and session cookie checks.

15 checks

Learn more

API Security

API docs, auth signals, CORS, rate limits, JWT analysis, GraphQL, shadow API, and leakage checks.

16 checks

Learn more

Compliance Evidence

Security contact, privacy policy, and terms evidence checks.

10 checks

Learn more

Web Quality Evidence

Accessibility, SEO, social, and digital-readiness evidence snapshots.

2 checks

Learn more

AI Security

Safe canary probes for applications with LLM or AI chat interfaces.

10 checks

Learn more

Cloud Posture (CSPM)

Read-only AWS/Azure/GCP checks: public storage exposure, open security-group/firewall ingress, and stale IAM credentials.

10 checks

Learn more

Mobile Static Analysis (APK/IPA)

Offline static analysis of an uploaded Android APK or iOS IPA: hardcoded secrets, ATS/cleartext-traffic misconfiguration, insecure storage flags, and sensitive permission review. Zero network traffic — the artifact is inspected entirely offline.

1 check

Learn more

Active penetration testing

Consent-gated active probes — require a signed pentest engagement before they run.

Pentest Basic

Active exploitation probes covering OWASP A01–A07: SQLi, XSS, path traversal, open redirect, auth bypass, IDOR, and BFLA. Requires a signed pentest engagement with client consent.

11 checks

See in pricing

Pentest Advanced

Active probes for OWASP A03–A10: command injection, SSRF, insecure deserialization, file upload bypass, mass assignment, header injection, and business logic flaws. (XXE is covered by the Pentest Basic package, included with every plan that unlocks Pentest Advanced.) Requires Enterprise plan and a signed pentest engagement with client consent.

9 checks

See in pricing

Ready to check a verified website?

Start with a safe Basic Hygiene scan and turn findings into practical fixes.

Start free scan View pricing