Pentest-Tools.com Pricing (2026)

Usage-based pricing anchored to asset count — you're paying per target (domains, IPs, hosts), not per seat. The value metric is attack surface size, which maps cleanly to how security teams actually think about scope.

From $95/mo 3 plans usage-based Free plan Free trial
NetSec
$95/mo
WebNetSec Popular
$140/mo
Pentest Suite
$190/mo
Verified Jul 26, 2026 Official pricing page
Screenshot of Pentest-Tools.com's pricing page showing its plans and prices
Their pricing page, captured Jul 26, 2026

Keep up with your competitors, without the manual work.

Outmano tracks pricing, features, roadmaps and reviews across your market, then sends one weekly brief: what changed, and what it means for you.

Try Outmano free »

NetSec

$95/mo $79/mo annual
  • Network scanning (discover 17,000+ CVEs)
  • Cloud scanning (AWS, Azure, GCP vulnerabilities)
  • Password auditing
  • Reconnaissance tools
  • Limited web & API scanning
  • Open ports & services discovery
  • Subdomain & domain discovery
  • Virtual host discovery
  • URL fuzzing
  • Technology & WAF fingerprinting
  • Google hacking & indexed leaks
  • Network vulnerability scanning (detect 17,000+ CVEs)
  • Password auditing & bruteforcing
  • Kubernetes container scanning
  • Scheduled scans
  • Automated scan flows with Pentest Robots
  • AI-enriched vulnerability descriptions
  • Add & edit automated and manual findings
  • Editable finding templates
  • Wordlists (defaults & custom)
  • Scan diff alerts (vulnerabilities, port scanning, subdomains)
  • Custom notifications
  • Continuous attack surface monitoring for specific assets
  • Scan results exports (PDF, HTML, CSV, XLSX)
  • Aggregated exports from multiple scans
  • Exportable attack surface map (CSV, JSON)
  • API access
  • Webhook alerts
  • MCP server
  • Workflow integrations (email, Jira, Microsoft Teams, Slack, Discord, etc.)
  • Cloud integrations (import targets from AWS)
  • Compliance & risk management integrations (Vanta, Nucleus Security)
  • Unlimited team members

WebNetSec

Popular
$140/mo $116/mo annual
  • DAST scanning (beyond OWASP Top 10)
  • Authenticated web scans
  • API scanning (REST, GraphQL)
  • WordPress, Drupal, Sharepoint, Joomla scanning
  • Open ports & services discovery
  • Subdomain & domain discovery
  • Virtual host discovery
  • URL fuzzing
  • Technology & WAF fingerprinting
  • Google hacking & indexed leaks
  • Network vulnerability scanning (detect 17,000+ CVEs)
  • CMS scanning (Wordpress, Drupal, Joomla, Sharepoint)
  • Cloud scanning (AWS, Azure, GCP vulnerabilities)
  • Password auditing & bruteforcing
  • Kubernetes container scanning
  • Authenticated web app scans (incl. AI-assisted authentication)
  • ML Classifier (AI false positive reduction)
  • Flowmapper (hidden attack surface discovery for web apps)
  • Scheduled scans
  • Automated scan flows with Pentest Robots
  • AI-enriched vulnerability descriptions
  • Add & edit automated and manual findings
  • Editable finding templates
  • Wordlists (defaults & custom)
  • Scan diff alerts (vulnerabilities, port scanning, subdomains)
  • Custom notifications
  • Continuous attack surface monitoring for specific assets
  • Scan results exports (PDF, HTML, CSV, XLSX)
  • Aggregated exports from multiple scans
  • Exportable attack surface map (CSV, JSON)
  • API access
  • Webhook alerts
  • MCP server
  • Workflow integrations (email, Jira, Microsoft Teams, Slack, Discord, etc.)
  • Cloud integrations (import targets from AWS)
  • Compliance & risk management integrations (Vanta, Nucleus Security)
  • Unlimited team members

Pentest Suite

$190/mo $158/mo annual
  • Automatic CVE exploiter (Sniper)
  • SQL Injection & XSS exploiters
  • Pentest report generator (Word DOCX, Google Doc)
  • Import findings from Burp Suite and others
  • Open ports & services discovery
  • Subdomain & domain discovery
  • Virtual host discovery
  • URL fuzzing
  • Technology & WAF fingerprinting
  • Google hacking & indexed leaks
  • Network vulnerability scanning (detect 17,000+ CVEs)
  • DAST scanning (beyond OWASP Top 10)
  • API scanning (REST, GraphQL)
  • CMS scanning (Wordpress, Drupal, Joomla, Sharepoint)
  • Cloud scanning (AWS, Azure, GCP vulnerabilities)
  • Password auditing & bruteforcing
  • Kubernetes container scanning
  • Authenticated web app scans (incl. AI-assisted authentication)
  • ML Classifier (AI false positive reduction)
  • Flowmapper (hidden attack surface discovery for web apps)
  • Handlers (cookies, keystrokes, HTML content, source IPs, etc.)
  • Proof-of-exploitation capture
  • Scheduled scans
  • Automated scan flows with Pentest Robots
  • AI-enriched vulnerability descriptions
  • Add & edit automated and manual findings
  • Editable finding templates
  • Import findings from Burp Suite
  • Wordlists (defaults & custom)
  • Scan diff alerts (vulnerabilities, port scanning, subdomains)
  • Custom notifications
  • Continuous attack surface monitoring for specific assets
  • Scan results exports (PDF, HTML, CSV, XLSX)
  • Aggregated exports from multiple scans
  • Exportable attack surface map (CSV, JSON)
  • Pentest report generator (editable DOCX, Google Doc)
  • API access
  • Webhook alerts
  • MCP server
  • Workflow integrations (email, Jira, Microsoft Teams, Slack, Discord, etc.)
  • Cloud integrations (import targets from AWS)
  • Compliance & risk management integrations (Vanta, Nucleus Security)
  • Unlimited team members

AI Pricing Analysis

Pricing Model

Usage-based pricing anchored to asset count — you're paying per target (domains, IPs, hosts), not per seat. The value metric is attack surface size, which maps cleanly to how security teams actually think about scope.

Tier Strategy

NetSec is for teams that only care about network/infrastructure exposure; WebNetSec adds web app scanning for teams running both; Pentest Suite is the full toolkit for consultants or internal teams running comprehensive engagements. The upgrade trigger is almost always scope — the moment you need web app coverage or branded client reports, you're moving up.

Competitive Positioning

They're positioned as a mid-market alternative to enterprise platforms like Rapid7 or Tenable — meaningfully cheaper, but more capable than lightweight tools like Shodan or basic vuln scanners. The AWS/Azure Marketplace availability signals they're targeting security-conscious teams already living in cloud procurement workflows.

Growth Lever

Asset count is the primary expansion driver — the slider goes to 500+ and price scales with it, so growing attack surfaces mean growing contracts. Branded reports and internal network scanning as paid add-ons are smart upsells for pentest consultancies who need to look polished in front of clients or reach behind the firewall.

Pentest-Tools.com Pricing FAQ

How much does Pentest-Tools.com cost?
Paid plans start at $95/mo, going up to $190/mo for larger teams. You can get started on the free plan before committing.
Is there a free plan?
Yes. The "Free" plan is free forever, not just a trial. It's enough to evaluate the product before upgrading.
Can I try it before paying?
Yes — there's a free trial that lasts 7 days.
How does the pricing work?
Usage-based pricing anchored to asset count — you're paying per target (domains, IPs, hosts), not per seat. The value metric is attack surface size, which maps cleanly to how security teams actually think about scope.
Is there a discount for annual billing?
Yes — you save up to 17% if you pay annually instead of month-to-month. They also mention: "Pay only 10 months when billed yearly (save 2 months)."
Which plan makes sense for me?
NetSec is for teams that only care about network/infrastructure exposure; WebNetSec adds web app scanning for teams running both; Pentest Suite is the full toolkit for consultants or internal teams running comprehensive engagements. The upgrade trigger is almost always scope — the moment you need web app coverage or branded client reports, you're moving up.

Set it up once. Stay ahead all year.

Add the competitors you care about and Outmano does the watching — then hands you a weekly action plan with what to do next.

Start tracking free »