The scanner that tells you when it isn't sure.
Most security tools are confident about everything and specific about nothing. This one states its confidence on every finding, publishes what it cannot do, and proves your fix held — at a price that does not start with a sales call.
Six things you can check for yourself.
Every finding says how sure it is
Confirmed, strong indication, potential, informational — on all of them. A red badge with no confidence behind it is a guess with styling, and it is why security teams learn to ignore their own dashboards.
Confidence sits beside severity on every row, in the product and in every export.
The limitations are published, in writing
No SOC 2. No third-party penetration test. Compliance mappings are context, not audit evidence. Findings can be wrong. All of it is on the site before you sign up, not discovered afterwards.
Read them on the home page and in the Security Policy — same detail as the capabilities.
Fixes are verified, not assumed
Every finding is fingerprinted and tracked across scans. Fix something and the next scan confirms it held. Close something that quietly comes back and it is counted as a regression rather than a new discovery.
New, persisting, fixed and regressed counts on every scan.
Your code calls models — that is scanned too
Prompts built from request input, agents wired to shells, and the packages models like to invent. AI usage is read with the same severity-and-confidence discipline as a missing header.
Runs on every repository scan, on the free tier included.
Passive until you prove you own it
External checks are the requests a browser already makes. Anything beyond that stays locked until you verify the domain by DNS record or hosted file. Authorisation is recorded per scan, not per account.
Deep checks are unavailable until verification completes.
The free tier is the whole engine
One domain and one repository, with every check the paid plans run. The limit is scope, never quality — there is no reduced ruleset waiting behind a card.
Same scanner, same rules, same reports.
Against the shape of the market.
We do not name competitors. Their prices and features change, and a security company publishing a claim about a rival that quietly goes out of date has spent credibility it needs elsewhere. What follows is the pattern you will find shopping around — check it yourself.
| Webcuris | Typical alternative | |
|---|---|---|
| Entry price | Free, then $39/mo | Commonly $99–$199/mo |
| Billed yearly | $33.25/mo effective | Often annual contract only |
| Free tier | Full engine, 1 domain + 1 repo | Usually a time-limited trial |
| Confidence on each finding | Yes — four levels | Rarely stated |
| Limitations published | Yes, before sign-up | Seldom published at all |
| Fix verification across scans | Yes, with regression counts | Varies |
| AI / LLM usage scanning | Included on every plan | Usually an add-on, if offered |
| Hallucinated-dependency check | Yes | Rare |
| Talk to sales before trying it | Never — sign up and scan | Often required |
| Export and delete your data | Self-service, no request queue | Varies |
About the price band. $99–$199 a month is what comparable website-and-code scanning tiers commonly list publicly; it is a description of the category, not a quote from any one vendor, and some cost considerably more. Prices move — check the current figure wherever you are comparing. The Webcuris column is the published price on our own pricing page, and every capability in it is running today.
When you should pick something else.
A page that only argues for itself is a page you should not trust. These are the cases where another tool is genuinely the better answer.
Read the full limitations →You need an audited certification today. We hold no SOC 2 or ISO 27001, and mappings to those frameworks are context rather than evidence.
You need SSO or SCIM. Accounts are local to the deployment; there is no identity-provider integration yet.
You need a human penetration test. This is automated scanning — it finds classes of problem a tester would, and it does not think like one.
You need agent-based runtime protection. This reads what you publish and what you ship; it does not sit inside your running processes.
Keep reading
Where most people go next
Decide from a real result, not a brochure.
Scan a domain you own on the free tier and read the findings yourself. No card, no call.