Tool Comparison

Free Scan vs Self-Check CLI

See the real difference. We ran both tools on example.com to show you exactly what Pro customers get.

Live results from example.com
FREE

Free Web Scan

$0 - Lead capture teaser

Subdomains Found

1
of 12 checked

Results for example.com

  • www.example.com Found
  • api.example.com -
  • staging.example.com -
  • dev.example.com -
  • + 8 more prefixes... -
  • 12 common subdomain prefixes
  • 6 CDN providers (headers only)
  • No Certificate Transparency
  • No WAF detection
  • No origin exposure analysis
PRO / ENTERPRISE

Self-Check CLI

Included with Pro ($8,000/mo)

Subdomains Found

6
via Certificate Transparency

Results for example.com

  • example.com EXPOSED
  • www.example.com Cloudflare
  • dev.example.com No A record
  • m.example.com No A record
  • products.example.com No A record
  • support.example.com No A record
  • 500+ subdomains via crt.sh
  • 12 CDN providers + CNAME chain
  • 8 WAF providers detected
  • Origin IP exposure analysis
  • Risk score (5.0/10 High)

Why the CLI Found 6x More Subdomains

🔒

Certificate Transparency

CLI queries crt.sh to find ALL subdomains that ever had SSL certificates issued - not just common prefixes.

🔍

Hidden Subdomains

m.example.com, products.example.com, support.example.com - none are in typical wordlists.

Origin Exposure

CLI detected that example.com (23.215.0.136) is directly exposed while www is behind Cloudflare.

Complete Feature Comparison

Capability Free Web Scan Self-Check CLI (Pro)
Subdomain Discovery 12 common prefixes 500+ via Certificate Transparency
CDN Detection 6 providers (headers) 12 providers + CNAME chain analysis
WAF Detection No 8 providers (Cloudflare, Imperva, F5...)
API Gateway Detection No 4 providers (Kong, Apigee, AWS, Azure)
Service Mesh Detection No 4 providers (Envoy, Istio, Linkerd)
Multi-layer Analysis No CDN → WAF → LB → Origin
Origin Exposure Detection Basic Full IP + direct access testing
Risk Scoring Simple (Low/Med/High) 1-10 scale with findings breakdown
Output Formats Web UI only JSON, HTML, Markdown
CI/CD Integration No GitHub Actions, cron jobs
Local/Offline Scans No Unlimited

Ready to See What You're Missing?

The free scan is a teaser. For comprehensive DDoS vulnerability assessment with full subdomain discovery, upgrade to Pro.