Pentest-Tools.com pricing teardown
https://pentest-tools.com/pricingPentest-Tools.com presents a clean, well-structured three-tier pricing page targeting security professionals with a usage-based (assets per scan cycle) model. The page is thorough — featuring a detailed comparison table, a free tier, add-ons, and a custom enterprise tier — but the asset-count slider adds complexity to the entry experience and the price jumps between tiers are modest (~47-48% increments), which may undercut the perceived value gap. Overall it's a strong self-serve page with good trust signals and objection handling, held back slightly by visual hierarchy issues and the absence of a clearly badged recommended plan.
Tier structure
NetSec
$95/mo (monthly) or $79/mo (annual)
WebNetSec
$140/mo (monthly) or $116/mo (annual)
Pentest Suite
$190/mo (monthly) or $158/mo (annual)
Value metric
flat-rate per tier with scalable asset quota (5–500+ assets per scan cycle)
How limits scale
Escalation logic
Tiers escalate from network-only scanning (NetSec) to adding full web/API DAST (WebNetSec) to adding exploitation tools and pentest reporting (Pentest Suite), each building on the previous. Price jumps are ~47% from NetSec to WebNetSec and ~36% from WebNetSec to Pentest Suite — smaller than the 2-3x ideal, which may reduce urgency to upgrade.
Psychological anchors
- Highlighted/featured plan — WebNetSec is visually highlighted (distinct button color per screenshot) as the implied recommended plan, though no explicit 'Most Popular' badge is present — a missed opportunity to strengthen the decoy effect.
- Annual discount toggle — Monthly/Yearly toggle at the top with 'Pay only 10 mos.' framing — equivalent to ~17% discount — shown prominently above the plan cards.
- Strikethrough/savings callout — Annual prices show the original monthly price struck through (e.g., $95 → $79) with 'Save 2 months' label, reinforcing the annual value proposition.
- Free tier as entry anchor — A Free Edition with a 7-day trial CTA anchors the bottom of the plan section, lowering the barrier to entry and creating an upgrade path from zero cost.
- Enterprise/custom plan anchor — A 'Custom plans' section for enterprise-level needs is shown below the main tiers, making the $190 Pentest Suite feel affordable by comparison.
- Marketplace trust signals — 'Or buy via AWS or Azure' appears under each plan CTA, adding procurement credibility and reducing friction for enterprise buyers with cloud budgets.
- Social proof / authority — Deloitte Fast 500, SC Awards, Gartner Peer Insights, G2 badges, and '2000+ security teams in 119+ countries' are displayed, reinforcing trust before the comparison table.
- Competitor displacement framing — Headline positions the product as 'a powerful alternative to Nessus, Qualys, Acunetix, Nexpose, or Invicti' — anchoring perceived value against expensive enterprise tools.
What this page is optimizing for
This page is primarily optimized for self-serve conversion: prices are fully transparent, asset-count sliders allow instant customization, CTAs say 'Select [Plan]' with direct signup flow, and a 7-day trial plus 10-day money-back guarantee reduce purchase risk. A secondary goal is expansion revenue, evidenced by the flexible asset scaling, add-on upsells (internal scanning, branded reports), and FAQ content that explicitly explains how to grow usage without switching plans.
Red flags
- No explicit 'Most Popular' or 'Recommended' badge on WebNetSec despite it being visually highlighted — the decoy/anchor effect is weakened without clear social proof labeling.
- Asset-count slider on each plan card adds decision complexity at the top of the funnel; visitors must configure before seeing a final price, which can increase drop-off.
- Price increments between tiers (~47% and ~36%) are smaller than the 2-3x ideal, making the upgrade value proposition feel incremental rather than transformational.
- All three paid tiers share the same '5–500+' asset range, so the only differentiation is feature set — this makes tier selection harder for buyers who think primarily in terms of scale.
- Internal network scanning and branded reports are add-ons across all tiers rather than tier differentiators, which fragments the pricing logic and may confuse buyers about true plan costs.
- The detailed comparison table is very long (50+ rows), which risks overwhelming buyers rather than helping them decide quickly — a summarized 'top 5 differences' callout is missing.
- No live chat or instant demo CTA visible on the pricing page itself, which is a missed conversion opportunity for mid-market buyers who are close to deciding.
Best-practices scorecard
What works · 5
- Visible prices — All three tier prices are publicly displayed for both monthly and annual billing, with the asset-count slider making the model transparent.
- Annual discount offered — Monthly/Yearly toggle with 'Pay only 10 mos.' framing and strikethrough pricing clearly communicates the ~17% annual savings.
- FAQ or objection handling — An extensive FAQ section addresses assets, billing, scaling, cancellation, data security, and AI features — well above average for objection handling.
- Trust signals present — Multiple trust signals are present: Deloitte awards, SC Awards, Gartner Peer Insights, G2, ISO27001 audit badge, and '2000+ teams in 119 countries' social proof.
- Clear CTAs per tier — Each tier has a distinct 'Select [Plan Name]' CTA button plus secondary 'Or buy via AWS or Azure' options, with a 'Continue with the Free Edition' fallback CTA.
Half measures · 3
- Clear recommended tier — WebNetSec appears visually highlighted in the screenshot but lacks an explicit 'Most Popular' or 'Recommended' badge to reinforce the choice.
- Value metric matches usage — Assets-per-scan-cycle is a logical metric for security teams, but the identical asset range across all paid tiers means the metric doesn't drive tier selection — only feature set does.
- Tier differences are scannable — The detailed comparison table is comprehensive but very long; the top-of-page 'What's included' bullets help, but a concise visual diff between tiers is absent.