All articles

Pentesting fundamentals

Priced Like a Scanner, Works Like a Pentester

Vulnix starts at $99 a month, scanner territory. But it signs in, chains attacks and proves each finding with a working exploit. Here is what that price buys.

By Vulnix Team9 min read

Put Vulnix's pricing next to the rest of the security testing market and it lands in an unexpected place.

What you buy How it is usually priced
Vulnerability scanners such as Intruder, Burp Suite DAST or Snyk Subscriptions, priced per target, per user or per developer
A human-led web app pentest, for example from Cobalt From about $8,500 per test
An autonomous pentesting service such as XBOW Publicly cited at $4,000 to $8,000 per test
Automated network pentesting such as NodeZero or Pentera From about $25,000 to $35,000 a year
Vulnix Free to start, then $99 a month (500 credits) or $299 a month (2,000 credits)

Competitor prices are from our comparison pages, reviewed in September 2026.

On price, Vulnix sits with the scanners. So it is fair to ask whether it is one.

The short answer: no. A vulnerability scanner runs a list of known checks and reports what might be vulnerable. Vulnix runs an AI agent that signs in to your app as a real user, works out how it could be attacked, tries those attacks, and reports only what it actually exploited, with the evidence. After you fix something, it replays the same exploit to confirm the fix holds. That is the job of a penetration tester (see what AI penetration testing is), and the rest of this article shows what it looks like in practice and how it fits into a scanner-sized price.

What a scanner does

A vulnerability scanner is a fast, repeatable checklist. Network scanners like Nessus look at ports, services and software versions. Web scanners (DAST tools) like ZAP or Burp Suite DAST crawl your site and send crafted requests. Template scanners like Nuclei run thousands of small community-written checks. Code scanners like Semgrep or Snyk read your source and your dependencies.

They share one way of working: each check looks for a known pattern, and each response is judged on its own. A scanner is excellent at "this server runs a version with a known CVE" or "this page reflects a script tag." It does not know who it is supposed to be, which data belongs to which customer, or what your app is for. That is why its output is a list of things that might be wrong, and why someone has to triage it.

A scanner robot stamps a building's locked front door PASSED, while the side door stands wide open under a NOT SCANNED sign and Dot, the Vulnix character, winks from the doorway

What Vulnix does that a scanner does not

Vulnerability scanner Vulnix
Starting point A fixed list of checks Your app, explored like an attacker would
Signed in as your users Often, as one user, once login is configured Yes, with the test accounts and headers you provide, and it compares what each one can reach
How it decides what to try The next check on the list Hypotheses based on what the app just returned
Multi-step attacks Only recorded sequences, such as a login Yes, it chains steps across requests and features
What a finding means "This might be vulnerable" "This was exploited; here is the request, the response and the impact"
After you fix it Run the whole scan again Validate-Fix replays the original exploit against that finding
Source code Pattern matching (SAST tools) Whitebox runs that test the code and point to the file and line, with an optional fix pull request
Pull requests Pattern checks in CI (SAST tools) A security review of each pull request before it merges
Can you see what it did? A list of checks run A full trace of every step the agent took

Most of those rows describe work you would normally pay a person to do.

It signs in. Most serious bugs sit behind the login. You give Vulnix a test user's login details, or a header such as an API token, once per target, and every run can test the app as that user.

It works from hypotheses. The agent reads each response and decides what to try next: this ID looks sequential, does the server check who is asking? This field is echoed back, where does it end up? When an idea fails, it changes the idea, the way a tester would.

It proves what it reports. A finding reaches your report only if the attack worked. You get the exact request, the response that came back and what an attacker gained, so an engineer can reproduce it in minutes. Leads that could not be proven are dropped instead of padding the list.

It checks your fix. Validate-Fix is a separate, narrowly scoped run that replays the original exploit against the patched app. A finding is closed because the attack stopped working, not because someone changed a status. We wrote more about how to validate a security fix.

The bug that shows the difference

Take a simple invoicing app. You are signed in as Acme Ltd and open your invoice at /api/invoices/1043. Change the number to 1044 and, if the server forgets to check ownership, you get Globex Inc's invoice instead.

To a scanner, that second response is perfect: status 200, valid JSON, normal size and speed, no error and no known signature. The only thing wrong with it is whose data it contains, and a scanner has no idea who it is or what belongs to whom.

Same requests, different question. The scanner judges each response alone; Vulnix knows whose data should come back.

Vulnix catches it because it is signed in as Account A, knows which invoices Account A owns, and confirms with a second account that invoice 1044 really belongs to someone else. That last step turns a suspicion into proof.

This class of bug, broken access control, is the number one risk in OWASP's 2025 Top 10, a ranking built from data on more than 2.8 million applications. When OWASP explained in 2017 why these flaws are so common, part of its answer was a "lack of automated detection." It is the most important bug class on the web, and it is the one a scanner is built to miss.

So why does it cost like a scanner?

Because the expensive part of a traditional pentest is people's time, and that is the part Vulnix automates.

  • No tester days. A human engagement is priced by the days a consultant spends on your app. An agent does that exploration itself, so a run costs compute, not a week of someone's calendar.
  • No sales cycle. There are no scoping calls, statements of work or annual contracts. You sign up, verify you own the domain or connect the repository, and start a run.
  • You pay per action. Each paid plan includes monthly credits, and each action has a flat price: a quick blackbox run uses 25 credits, a deep run 100, a whitebox code run 150, and a pull request review 15. The $99 Starter plan covers five deep runs a month.

What you do not get at that price is a human's judgment on your business rules or a multi-week engagement on a high-stakes system. Plenty of teams keep a human pentest once a year for that, and use Vulnix to test every release in between.

Where a scanner is still the right tool

Vulnix is not a replacement for every scanner, and it would be misleading to say so.

  • Breadth. If you need to check 400 servers for one vulnerable version, a network scanner does it in minutes.
  • Dependencies. Knowing which packages in which repositories have published advisories is a software composition analysis job.
  • New CVEs. When a critical advisory drops, template scanners like Nuclei often have a check out within days.
  • Compliance. Some standards name scans directly. PCI DSS, for example, requires quarterly external scans by an approved scanning vendor.

A scanner tells you what might be wrong across everything you own. Vulnix tells you what an attacker can actually do to the app you ship. Most teams with real customers need both answers. For the longer argument about coverage and proof, read AI penetration testing vs. vulnerability scanning.

Four questions to ask any tool that claims to pentest

Pricing pages blur the line between scanners and pentests, ours included. These questions sort any product into the right category, whatever it costs:

  1. Can it test as a signed-in user, and as two different users? Without that, it cannot find access-control bugs.
  2. Does every finding come with a working exploit? A request, a response and an impact, not a confidence score.
  3. Can it replay the exploit after a fix? Otherwise "fixed" means "someone said so."
  4. Can you see what it tried? A trace of the agent's steps is how you trust, and audit, an automated tester.

A scanner will answer no to most of them. A pentest, human or AI, should answer yes to all four.

Frequently asked questions

Is Vulnix a vulnerability scanner?

No. Vulnix is an AI penetration testing platform. A scanner runs known checks and reports what might be vulnerable. Vulnix's agent signs in as your test users, decides what to try from the app's responses, attempts real attacks and reports only the findings it exploited, with the request, response and impact as evidence.

Why is Vulnix cheaper than a penetration test?

Most of a traditional pentest's price is a consultant's time. Vulnix's agent does the exploration and exploitation itself, it is self-serve with no sales process, and you pay a flat number of credits per run. Plans start at $99 a month for 500 credits, and a deep run uses 100.

Does Vulnix replace my vulnerability scanner?

Not entirely. Keep a scanner for broad, repeatable checks such as outdated software across many servers, vulnerable dependencies and compliance scans. Use Vulnix for what an attacker can actually do inside your application, including access-control and multi-step bugs that scanners miss.

What is the difference between a quick run and a deep run?

A quick run is a faster, lighter pass and uses 25 credits. A deep run is the most thorough pass Vulnix makes and uses 100 credits. Both test the live app and report only proven findings.

Can Vulnix test pages behind a login?

Yes. You save a test user's login URL, username and password, or custom headers such as an API token, once per target. Every run against that target can then test the app as that user. Credentials are encrypted and only available inside the run that needs them.

Sources