Security scanning built for people who build websites
Warden is an automated DAST platform — dynamic application security testing, run against your live site rather than your source code. Standard checks are read-only. Anything active is authorised by you, per domain.
Security expertise required
Automated security checks per scan
Starting price per month — no minimum term
Security audits shouldn't require a six-figure budget
Qualys Web Application Scanning starts at $1,995/year for 25 applications. Intruder's entry tier is $149/month. Acunetix and Invicti require custom quotes that rarely come back under $4,000 per year. None of these make sense for a developer with three client sites or a startup trying to pass a security audit.
Meanwhile, clients and procurement teams are asking more questions about security than ever. Supplier audits, insurance requirements, and enterprise procurement checklists increasingly demand documented evidence that your website is secure.
| Feature | Warden | Scanner SaaS | Consultancy pen test |
|---|---|---|---|
| Entry price | $14.99/mo | $149–$1,995/mo | $2,000–$20,000+ |
| Getting your report | Automated, self-service | Automated, self-service | 2–6 week engagement |
| Active DAST (XSS / SQLi) | ✓ Pro+, authorised | ✓ | ✓ |
| Authenticated scanning | ✓ Pro+ | Enterprise tiers only | ✓ |
| Broken access control (IDOR) | ✓ Pro+ | Rarely | ✓ |
| Business-logic & chained exploits | ✗ | ✗ | ✓ |
| No security expertise needed | ✓ | ✗ | ✗ |
| Plain-English findings | ✓ | Varies | Varies |
| Monthly billing available | ✓ | Often annual-only | N/A |
| White-label available | ✓ Agency+ | Rarely | Depends |
| Compliance mapping | ✓ | Varies | ✓ bespoke |
| Fix-verification rescans | ✓ | Rarely | Extra cost |
| Slack / webhook / Jira | ✓ | Enterprise tiers only | N/A |
| REST API access | ✓ Business | Enterprise tiers only | N/A |
The check set
Every check, grouped by discipline
Open a discipline to see exactly what runs. Availability by plan is noted where it differs.
- TLS protocol version
- Cipher suite strength
- Certificate validity
- Certificate chain
- HSTS header
- HSTS preloading
- Certificate-expiry email alerts
- Content-Security-Policy
- X-Frame-Options
- X-Content-Type-Options
- Referrer-Policy
- Permissions-Policy
- Cross-Origin policies
- Secure flag
- HttpOnly flag
- SameSite attribute
- Cookie scoping
- HTTP to HTTPS redirect
- Mixed content detection
- HTTP methods allowed
- Clickjacking protection
Reporting & evidence
What the scan turns into once it's finished.
Compliance mapping
CWE, OWASP and CVSS tagging on every finding, rolled up against PCI DSS, ISO 27001 Annex A, SOC 2, Cyber Essentials and OWASP ASVS. Your report contributes vulnerability-assessment evidence toward ISO 27001 control A.8.8.
Pro and up · control coverage rollup on Pro and up
SEO health
Page-by-page titles, meta descriptions and headings, Open Graph and structured data, image alt text, URL structure, page size, sitemap and robots.txt. Scored 0–100 with plain-English fixes.
Every plan · informational, never affects your grade
Site map & attack surface
Crawls your public pages into a page inventory: forms and login forms with form-protection detection, external links, email addresses, third-party scripts and broken links.
Pro and up · informational, never affects your grade
From sign-up to a graded report
Sign up in under two minutes and pick the plan that fits.
A DNS TXT record or a small verification file. Under five minutes, and it confirms you are authorised to scan.
Warden runs 30+ checks in the background. Standard checks are read-only; Deep Scan is authorised separately. We email you when it's ready.
Your A–F grade, health score, and every finding with a plain-English explanation and step-by-step fix.
Resolve findings using the guidance, then mark them fixed — Warden rescans to verify and re-grades your report.
Set a weekly or monthly schedule so your report stays current without anyone remembering to click scan.
Built for builders, not enterprises
Five ways people use Warden, and the plan that usually fits.
Freelance developer
Deliver a security report alongside every site launch. A high-value deliverable that takes you no extra time.
Indicative tier: Solo
Digital agency
Scan every client site from one dashboard, white-label the reports, and add a recurring service line.
Indicative tier: Agency
SaaS startup
Pass supplier security audits and enterprise procurement checklists with an independent report.
Indicative tier: Pro
IT manager
Monitor your organisation's web properties continuously, and get alerted to new issues between scans.
Indicative tier: Business
Marketing team
Your website is a business-critical asset. Know its security posture without waiting on IT.
Indicative tier: Starter
Ready to find out your security grade?
Every plan includes the full scan engine. Cancel any time.
