Why Webcuris

The scanner that tells you when it isn't sure.

Most security tools are confident about everything and specific about nothing. This one states its confidence on every finding, publishes what it cannot do, and proves your fix held — at a price that does not start with a sales call.

What actually differs

Six things you can check for yourself.

01

Every finding says how sure it is

Confirmed, strong indication, potential, informational — on all of them. A red badge with no confidence behind it is a guess with styling, and it is why security teams learn to ignore their own dashboards.

Confidence sits beside severity on every row, in the product and in every export.

02

The limitations are published, in writing

No SOC 2. No third-party penetration test. Compliance mappings are context, not audit evidence. Findings can be wrong. All of it is on the site before you sign up, not discovered afterwards.

Read them on the home page and in the Security Policy — same detail as the capabilities.

03

Fixes are verified, not assumed

Every finding is fingerprinted and tracked across scans. Fix something and the next scan confirms it held. Close something that quietly comes back and it is counted as a regression rather than a new discovery.

New, persisting, fixed and regressed counts on every scan.

04

Your code calls models — that is scanned too

Prompts built from request input, agents wired to shells, and the packages models like to invent. AI usage is read with the same severity-and-confidence discipline as a missing header.

Runs on every repository scan, on the free tier included.

05

Passive until you prove you own it

External checks are the requests a browser already makes. Anything beyond that stays locked until you verify the domain by DNS record or hosted file. Authorisation is recorded per scan, not per account.

Deep checks are unavailable until verification completes.

06

The free tier is the whole engine

One domain and one repository, with every check the paid plans run. The limit is scope, never quality — there is no reduced ruleset waiting behind a card.

Same scanner, same rules, same reports.

Compare

Against the shape of the market.

We do not name competitors. Their prices and features change, and a security company publishing a claim about a rival that quietly goes out of date has spent credibility it needs elsewhere. What follows is the pattern you will find shopping around — check it yourself.

Webcuris compared with the typical pattern among alternative security scanning tools
 WebcurisTypical alternative
Entry priceFree, then $39/moCommonly $99–$199/mo
Billed yearly$33.25/mo effectiveOften annual contract only
Free tierFull engine, 1 domain + 1 repoUsually a time-limited trial
Confidence on each findingYes — four levelsRarely stated
Limitations publishedYes, before sign-upSeldom published at all
Fix verification across scansYes, with regression countsVaries
AI / LLM usage scanningIncluded on every planUsually an add-on, if offered
Hallucinated-dependency checkYesRare
Talk to sales before trying itNever — sign up and scanOften required
Export and delete your dataSelf-service, no request queueVaries

About the price band. $99–$199 a month is what comparable website-and-code scanning tiers commonly list publicly; it is a description of the category, not a quote from any one vendor, and some cost considerably more. Prices move — check the current figure wherever you are comparing. The Webcuris column is the published price on our own pricing page, and every capability in it is running today.

When you should pick something else.

A page that only argues for itself is a page you should not trust. These are the cases where another tool is genuinely the better answer.

Read the full limitations →

You need an audited certification today. We hold no SOC 2 or ISO 27001, and mappings to those frameworks are context rather than evidence.

You need SSO or SCIM. Accounts are local to the deployment; there is no identity-provider integration yet.

You need a human penetration test. This is automated scanning — it finds classes of problem a tester would, and it does not think like one.

You need agent-based runtime protection. This reads what you publish and what you ship; it does not sit inside your running processes.

Decide from a real result, not a brochure.

Scan a domain you own on the free tier and read the findings yourself. No card, no call.

Contact

Talk to us.

Questions about what the engine checks, whether it fits your estate, or what it deliberately refuses to do. A person reads every message.

  1. 01You writePlain form, no qualifying call, no obligation. The marketing checkbox is optional and unticked.
  2. 02A person reads itMessages land with the team, not a queue-bot. Nothing is auto-replied.
  3. 03You get an answerTo the address you gave — including “this product is not the right fit”, when that is the honest answer.
Reporting a vulnerability?
Read the disclosure policy first — it tells you what is in scope and what to expect.
New messagereplies go to your email

Personal addresses (gmail, outlook, and similar) are not accepted.

+91

0 / 4000