Is your site secure?Find out in 60 seconds.
Free, instant recon for any domain — plus scanners that confirm real vulnerabilities with a working proof-of-concept.
Only scan domains you own or are authorised to test.
2,300+ scans run · 140+ checks · DPIIT-recognised startup
Confirmed, not noisy
Every active finding is exploited with a working proof-of-concept and re-verified to kill false positives — so you fix what’s real, not chase a wall of maybes.
Safe by design
Intrusive scans require domain-ownership verification and recorded consent first, and every request passes strict scope + anti-SSRF guards.
Transparent, predictable pricing
Recon is free and needs no account. Pro — unlimited active scans, Deep Scan and every specialized audit — starts at ₹349/mo, billed as one flat monthly fee with no per-scan or per-target charges.
Popular tools
Jump straight in, or browse the full toolkit.
Free to start. Pro when you need more.
Unlimited recon for everyone. Unlock unlimited Active scans, authenticated Deep Scan and every Pro security tool — from ₹349/mo ($12/mo).
Need humans, not just automation?
ONEROXE runs operator-led VAPT, red teaming and incident response — every operator in-house, no subcontractors.
Frequently asked questions
Is it really free?
Yes — every recon tool and the passive vulnerability scanner are free and need no sign-in. Create a free account and you also get a couple of confirmed-exploitation Active scans every month.
Is scanning safe and legal?
Public, read-only recon only observes what is already exposed, so it can run without authentication. Active and Deep scans send real test payloads, so they require you to verify domain ownership and record explicit authorization first. Only scan systems you own or are authorised to test.
How is this different from other scanners?
We confirm vulnerabilities with a working proof-of-concept and an independent re-verification pass, instead of dumping unconfirmed “potential” issues. Findings are mapped to OWASP, CWE and CVSS.
Do I need to install anything?
No. Everything runs in your browser against the target you enter — no agents, no downloads. Mobile APK analysis is a simple file upload.
See what an attacker would.
Run your first scan in seconds — no sign-up, no install.
Run a free scan