Open your project dashboard, paste a URL, and press Scan. That’s the entire setup. SmartScanner immediately explores the site the way a user would, learning forms, routes, and states as it goes. You can narrow scope with include and exclude rules, set a crawl depth, or keep defaults for a quick sweep. Provide login details or a session cookie to test member-only paths; the scanner walks through sign-in screens and preserves sessions automatically. Single-page apps are handled with a headless browser, so dynamic content, API calls, and client-side routing are covered. As results arrive, you see a live inventory of pages, parameters, and services, with issues sorted by severity and risk so you know where to act first.
For day-to-day development, drop SmartScanner into your CI. Use the CLI or container to hit preview or staging URLs on every pull request. Configure a policy to fail builds on high or critical findings, and let moderate issues pass with warnings. Baseline mode compares new runs to previous ones so you catch regressions without noise. Tag scans by microservice or repository and schedule nightly sweeps for broader coverage. Short on time? Run a fast check that targets changed paths only; before a release, run a deeper pass that exercises forms, file uploads, and authenticated flows. All activity and outcomes are recorded for audit and compliance.
Fixing issues is straightforward. Each finding includes the exact request and response, reproduction steps, and a replay button for validation in a safe sandbox. The scanner also identifies the framework and server stack in use and tailors guidance accordingly, offering framework-specific fixes and sample patches where possible. Mute known false positives, set due dates, and push tickets to Jira, Azure Boards, or GitHub with one click. After a patch, run Retest to verify the fix in isolation and close the loop. Export machine-readable results (JSON or SARIF) for tooling, or generate clean PDFs for stakeholders with executive summaries and technical detail.
Advanced controls let you scan responsibly in any environment. Throttle request rates, honor 429s, and respect allowlists and blocklists to avoid disruption. Add custom headers, route traffic through a proxy, or use client certificates for hardened backends. SmartScanner probes for common web risks including injection flaws, cross-site scripting, SSRF, path traversal, auth and session weaknesses, misconfigurations, and secret exposure. It also checks policy gaps like missing security headers, weak cookie flags, and permissive CORS. Use the API to orchestrate scans across many apps, apply consistent policies, and stream results to your SIEM. Whether you are validating a bug bounty report, prepping for a penetration test, or protecting a fast-moving release train, SmartScanner fits cleanly into your workflow and keeps findings actionable.
Free
Free
Unlimited Targets
Unlimited Scans
On-premises Installation
Limited Functionality*
Pro
$20.00 per month
Unlimited Targets
Unlimited Scans
On-premises Installation
Full Functionality
Regular Updates
Priority Support
Perpetual
$599.00 per Seat
Unlimited Targets
Unlimited Scans
On-premises Installation
Full Functionality
1 Year Free Updates
1 Year Priority Support
Offline Scans
Comments