What is Hack My Website?
Hack My Website is an automated security scanner for websites, web apps, and SaaS products. It runs over 200 checks using OWASP ZAP, Nuclei, and Semgrep, then scores launch readiness from 0 to 100. Each finding comes with a prompt you can hand to Cursor or Claude to patch code.
Top Features:
- Multi-engine scans: combines runtime testing, CVE templates, and static code analysis together.
- Launch score: rates security readiness from 0 to 100 across four clear risk bands.
- Fix prompts: generates copy-paste prompts that Cursor or Claude can use to patch code.
Use Cases:
- Pre-launch audits: check a new SaaS app for XSS, SQL injection, and auth gaps.
- Secret detection: scan repositories for leaked API keys and hardcoded credentials in code.
- Fix verification: retest issues after patching to confirm each vulnerability is gone.
Who Can Use Hack My Website?
- Solo founders: check vibe-coded apps for security holes without hiring a pentester.
- Agencies: scan client sites and deliver white-label reports under their brand.
- Engineering teams: connect scans to GitHub and track issues across several targets.
Pricing
- Free (₹0 per month): one target and one scan monthly, with blurred findings only.
- Starter (₹1,999 per month): three scans monthly, full reports, the launch score, and fix prompts.
- Agency (₹4,999 per month): ten targets, unlimited scans, white-label reports, and SOC 2 compliance mapping.
Pros and Cons
Pros:
- Legal by design: ownership checks block anyone from scanning sites they do not control.
- Fast results: most audits finish in three to eight minutes without downtime.
- Ready-to-use fixes: prompts plug straight into AI code editors and save research time.
Cons:
- Local pricing: plans are listed in rupees, which may confuse buyers outside India.
- Blurred free results: the free plan hides detailed findings until you pick a paid plan.
- Automated only: scans cannot replace a manual penetration test for complex apps.
FAQs:
1) Is scanning legal?
Yes, you verify ownership with a DNS TXT record or file first.
2) Which tools power the scans?
It combines OWASP ZAP, Nuclei, Semgrep, and custom SaaS misconfiguration checks.
3) How long does a scan take?
Most scans take three to eight minutes without taking sites offline.
4) Can AI fix the problems it finds?
It writes fix prompts you paste into Cursor or Claude to patch code.
5) Is there a free plan?
Yes, one target and one monthly scan are free, with blurred findings.