Overview

Scan tiers

Free — $0#

  • Command: curl https://qsa.sh
  • Delivery: live terminal stream
  • Typical time: about 30 seconds
  • Rate: 1 scan per IP per 24 hours
  • Ports: top 1,000 TCP
  • Service and CVE: nmap -sV --script vulners
  • Vulnerability checks: roughly 2,000 curated templates
  • Findings shown: ports, versions and the top 3 findings in full
  • Stored: nothing

Full Pro — $5 per month#

  • Command: curl https://qsa.sh/<token>
  • Delivery: asynchronous, returns when ready
  • Typical time: 2 to 12 minutes
  • Rate: 1 scan per IP per hour
  • Ports: all 65,535 TCP
  • Vulnerability checks: roughly 2,000 curated templates across all ports
  • Findings shown: full list with remediation
  • Stored: single read or 24 hour Redis, no database

Deep — $7 per scan#

  • Command: curl https://qsa.sh/<token>
  • Delivery: asynchronous, report emailed
  • Typical time: 13 to 16 minutes
  • Rate: unlimited
  • Ports: all 65,535 TCP
  • Vulnerability checks: the full set of roughly 10,500 templates plus custom checks
  • Findings shown: full list with remediation, emailed
  • Stored: emailed, single read or 24 hour Redis, no database

Times are typical rather than guaranteed. A scan takes longer with higher network latency, more open ports, or more checks matching your services.

Which tier fits#

Use Free to see what the internet sees of one host today. Use Full Pro when you are fixing findings and want to re-scan every hour to confirm each change. Use Deep before an audit or a launch, when you want the full template set rather than the curated subset.

Next#