Pentest-Tools.com review: which of its three products do you need?
By The PenTest Index · Offers and terms checked October 9, 2026 · We read the published pages and one sample report. We did not buy or run a test.
Our Pentest-Tools.com review comes down to three separate purchases. For scanning you run yourself, WebNetSec ($140 a month for 5 assets) is the first plan that scans web apps behind a login. If a person must do the testing, that is a separate managed service from $3,400. The AI pentest is still early access. Annual plans are non-refundable.
Here are the three side by side.
| Self-run scanning plans | AI Pentests | Managed pentest | |
|---|---|---|---|
| Who does the work | You or your team | Software the company calls Specter. You set the scope. | Pentest-Tools.com's own testers (company-stated) |
| Published price | $95, $140 or $190 a month with 5 assets | None published. Shown before each run. | $3,400 fixed (black box). From $3,400 + $900 per user role (gray box). |
| Can you buy it today? | Yes, online | Only if early access is turned on for your account | By request. A written offer follows. |
| What you get | Scan results you can export. A report builder on the top plan. | A PDF report of confirmed findings and an activity log | A written report from the testers |
| The catch | It is software. Nobody is hired to test you. | The company says it does not replace a manual pentest | No published retest window or count |
Everything in this table is what Pentest-Tools.com publishes about itself. Sources and dates are at the bottom.
Pentest-Tools.com review: the short verdict
Pentest-Tools.com is a real company with clear public pricing. The risk is buying the wrong one of its three products.
You want to scan your own systems. A self-run plan fits. Pick WebNetSec if you need to scan a web app behind a login or scan an API. Count your assets first, and start on monthly billing so the refund window applies.
Someone outside your company will rely on the report. A customer, an auditor, a security team. That does not by itself rule out a scanning plan. Ask the person what they will accept; if they require human testing, look at the managed service and get the scope, the retest terms and the report date in writing.
You are curious about the AI pentest. Access must be enabled for your account, there is no public price, and the company itself says it does not replace a manual test.
It may not fit if you need a published retest window before you book, or you need a contract under your own country's law. The published platform terms are under Romanian law.
Already know you want the scanner?
See plans and prices on Pentest-Tools.com
Is Pentest-Tools.com a vulnerability scanner or a penetration test?
It is both, depending on which product you buy. The name does not tell you.
A vulnerability scan is software checking your systems for known weaknesses. A penetration test (pentest) is a scoped job where someone tries to break in and shows how far they got. An AI pentest is software that makes its own decisions about what to try next, without a person steering each step.
Think of it like tools and tradespeople. The scanning plans rent you the tools. The managed service sends someone to do the work. The AI pentest is a machine that does part of the job on its own, and the company is careful about what it claims for it. Its own page answers the question "Can AI Pentests replace a manual pentest?" with "No." It also says the AI "should not be considered complete business logic testing." (AI Pentests page, checked October 9, 2026)
The top scanning plan is called Pentest Suite. It adds tools that try to exploit what the scanner finds, and a report builder. It is still software you operate. Buying it does not hire a tester.
How much does Pentest-Tools.com cost?
For 5 assets with no add-ons, the scanning plans cost $95, $140 or $190 a month, or $946, $1,394 or $1,892 for a year paid up front. Tax is extra where it applies.
The three scanning plans
| Plan | Paid monthly | Paid yearly, up front | What it adds |
|---|---|---|---|
| NetSec | $95 a month | $946 a year | Network, cloud and password checks, plus discovery tools. Web and API scanning is limited. No web app scans behind a login. |
| WebNetSec | $140 a month | $1,394 a year | Full web app scanning, scans behind a login, API scanning (REST and GraphQL), WordPress and Drupal scanners. Joomla and SharePoint scanners were removed as standalone tools from the product interface on October 6, 2026; scheduled and API-triggered scans keep running until November 17, 2026. (Changelog) |
| Pentest Suite | $190 a month | $1,892 a year | Exploit tools, an editable report builder (Word or Google Doc), 2 years of history instead of 1, priority support |
Prices are for 5 assets, before tax and add-ons, as shown on the pricing page and the plan configurator on October 9, 2026. They are the company's published prices, not quotes we collected.
A few things the table does not show:
- Every paid plan includes unlimited scans on your assets, unlimited team members and access to the platform's API.
- Two add-ons cost extra: scanning inside a private network, and reports with your own branding. The terms say add-ons are charged as a percentage on top of the plan. The add-on documentation lists an extra 20% for private-network scanning and 25% for branding, or 45% for both.
- The yearly price is one payment. The configurator shows WebNetSec as "$116/month, paid yearly." You pay $1,394 on day one, not $116 a month.
Here is what yearly billing saves against twelve monthly payments at today's rate:
| Plan | 12 monthly payments | One yearly payment | Difference |
|---|---|---|---|
| NetSec | $1,140 | $946 | $194 |
| WebNetSec | $1,680 | $1,394 | $286 |
| Pentest Suite | $2,280 | $1,892 | $388 |
That saving comes with a condition. Read the refund section before you take it.
What counts as an asset?
Each hostname, each subdomain and each IP address is one asset. Pages under the same hostname do not count again, and scanning the same asset ten times in a month still counts once.
Say a made-up company has example.com, app.example.com, api.example.com, staging.example.com and four office IP addresses. That is 8 assets. Plans come in sizes of 5, 10, 15, 20, 25, 50 and up to 500, so if it scans all eight in the same monthly cycle, it needs the 10-asset size. The prices above are for 5. The plan configurator shows the price for each size.
The count resets every month, even on a yearly plan.
Is there a free version?
Yes. The Free Edition covers 5 assets a month with 2 scans running at once, keeps 90 days of history and needs no credit card. Its scans are limited and it leaves out the exploit tools and scans behind a login. It is free to use, but it is not open source. (Free Edition page, checked October 9, 2026)
The company also advertises a free trial of the paid product. Check which features the trial turns on before you judge a paid plan by it.
The managed pentest
This is a separate service with its own price list:
| Offer | Published price | What is tested | Stated timing |
|---|---|---|---|
| Black box | $3,400, listed as a fixed price | Your web app as an outsider with no login would see it | 3 working days, best effort. Report on day 4. |
| Gray box | From $3,400 + $900 per user role | The outsider view plus logged-in users | 4 or more working days, best effort. Report "when ready." |
Source: web app penetration testing page, checked October 9, 2026.
For a gray-box test with two user roles, the formula gives $3,400 + (2 × $900) = $5,200. With three roles it gives $6,100. Those are starting amounts from a published formula. They are not quotes, and they do not establish the full price for your app/API scope or the retest terms.
The AI pentest
There is no public price. The company says each AI pentest is priced per run and you see the price before it starts. Access is "enabled per account," so you may need to ask for it. (AI Pentests docs, checked October 9, 2026)
Can you get a refund from Pentest-Tools.com?
Only on your first monthly payment, and only if you ask within 10 days. Yearly plans are non-refundable.
This is easy to miss, because three of the company's pages say it three ways:
| Where | What it says |
|---|---|
| Pricing page, question on cancelling | "There is a 10 day money-back guarantee since your first payment." It sits in a section that talks about both monthly and annual plans. |
| Terms and Conditions, articles 3.9 to 3.11 | New customers only. First month only. Payments for annual subscriptions are excluded and "non-refundable." |
| Refund help article | You must cancel your license before asking. Once the refund is processed, your account is closed and its data is permanently deleted. |
All three were checked on October 9, 2026. The terms carry the most weight, and they are the strictest.
One more detail. When we read the pricing page, each plan's "Select" button linked to the yearly option.
So here is our advice. If you want a way out, start on monthly billing. Run it against your real systems in the first 10 days. Export anything you want to keep before you ask for a refund. Move to yearly later if it earns its place.
Three other terms are worth knowing:
- Plans renew on their own at the current rate until you cancel. Renewals are not refunded.
- You can cancel any time and keep access to the end of the period you paid for.
- If you move down a plan, the change starts next cycle and you get no credit for the current one.
Does a Pentest-Tools.com subscription include a manual pentest?
No. The subscription is software access. A test done by people is ordered separately, with its own written offer and its own terms.
That matters for the refund too. The 10-day rule is for subscriptions. A managed test is covered by whatever the written offer says.
A worked example
Say you run a small software company. You have one web app and the API behind it. A customer wants a pentest done by people, covering two user roles. You will not hand over source code. Your developers need about six weeks to fix things, so you want to first request a manual retest 45 days after you get the findings.
This is based on the example purchase we use across the site. Our method explains it.
Our finding: ask for a gray-box quote, and treat $5,200 as the floor. Four things are still open.
| What you need | What the published terms show | Finding |
|---|---|---|
| People doing the testing, two logged-in roles | Gray box covers logged-in users at $900 per role | Supported, as a starting amount of $5,200 |
| The same need, black-box offer | Black box tests as an outsider only | Mismatch. Rule this one out. |
| The API tested too | API testing is listed as its own service. The web app formula does not confirm whether it is included. | Unresolved |
| No source code | The services page asks for your scope and, for gray box, test logins. It does not mention code. | Unresolved until it is in writing |
| Manual retest first requested on day 45 | "A free re-testing phase" is advertised. No deadline or number of rounds is given. | Unresolved |
| A full price | The formula gives a web-app starting price plus a charge per role | Unresolved |
"Supported" here means the published terms cover that one need. It says nothing about how good the testing is.
Send this before you agree to anything:
Please quote a managed gray-box test of one web application and its API, covering two user roles. We can provide test accounts and API documentation, but no source code. Please include what is tested and what is excluded, the full itemized price, the start date and the date we receive the final report. Is a manual retest included if we first ask for it 45 days after the findings? If so, what is the deadline to ask, how many rounds are included, and do we get an updated report? Please also send a recent redacted sample report from this service.
A quote request is not permission to test. Testing needs separate written authorization that names the exact systems and activities.
If the answers suit you:
Request a managed web app pentest from Pentest-Tools.com
Where Pentest-Tools.com's own pages disagree
We found four places where the company's pages differ in detail or scope; these are not all contradictions. None is alarming. Each is a question to settle in writing.
| Topic | One page says | Another page says | Ask this |
|---|---|---|---|
| Managed test price | Web app page: black box is a "Fixed price" of $3,400 | Services page: priced on complexity, "not a flat fee" | "Is $3,400 the full price for my app, or the starting point?" |
| How long it takes | Web app page: 3 working days, report on day 4 (black box). 4 or more days (gray box). | Services page: "detailed engagements" typically take 7 to 10 business days | "What date will I have the final report?" |
| Checking fixes | Web app page: nothing stated | Services page: a free re-testing phase, done by hand, with an updated report | "How many retests, and how long do I have to ask?" |
| Report acceptance: human services versus AI | Services page: asked if its tests satisfy SOC 2, ISO 27001 and PCI DSS, it answers "Yes" | AI Pentests page: acceptance "always depends on your auditor, customer, jurisdiction" | Ask your auditor, not the vendor |
Sources: web app pentest page, services page and AI Pentests page, all checked October 9, 2026.
Will a Pentest-Tools.com report satisfy a customer or auditor?
That is up to the person who asked for it. The vendor cannot decide it, and neither can we.
What we can tell you is what one sample shows. The company publishes a sample scanner report. We read it on October 9, 2026. It runs 38 pages and is titled "Website Vulnerability Scanner Report." It lists findings with evidence and fixes, and it shows the scan settings. One of those settings reads "Authentication: False." So this sample was scanned without logging in. It shows you what scanner output looks like. It does not show a test of logged-in users, and it is not a report from the managed service or the AI pentest.
Before you buy, send your customer or auditor one question:
Will you accept this type of testing and a report like this sample for the systems in our scope? If not, what is missing: the testing method, who does it, the dates, or proof that fixes were checked?
Their answer picks the product for you. If a scan is fine, a subscription may be all you need. If they want people doing the testing, you are looking at the managed service or another provider.
If you are not yet sure what to ask for, our checklist walks through it: what needs testing, what to ask the person who wants the report, and what to send each provider. You can copy or print it. It asks for no contact details and it does not pick a provider for you.
When does the AI pentest make sense?
When you want a deeper look at one web app than a scan gives you, you can get early access, and nobody is requiring a person to do the testing.
A few practical points from the company's own documentation, checked October 9, 2026:
- A run can take up to 48 hours.
- CAPTCHA and similar challenges must be turned off on the path being tested.
- It makes real requests and tries real exploits, so the company recommends a staging copy over your live site.
- If you stop a run early, you keep the partial results but cannot generate the report.
- The AI models behind it are hosted in the US. The company says your data is not used to train them.
Read about AI Pentests on Pentest-Tools.com
Is Pentest-Tools.com legit and safe to pay?
Yes. It is a registered company with public prices, public terms and documentation you can read before you spend anything.
- Who you are paying. The legal name is PENTESTTOOLS S.A., based in Bucharest, Romania. Payments run through FastSpring, a payment processor.
- The contract. The platform terms apply Romanian law and specify the courts of Bucharest. For the platform products, the liability cap is the product fees paid in the 12 months before the event, with exceptions for death or injury caused by negligence, fraud, and liability that cannot legally be limited.
- Your data. Since August 4, 2026, new customers choose US or European hosting at signup, and that choice is fixed. Existing customers stay in Europe for now. (Data storage article)
- Permission. You must be authorized to scan every target. The terms let the company ask for proof and suspend accounts that cannot give it.
- Credentials. The company says it holds ISO/IEC 27001 certification and is accredited as a cybersecurity auditor by Romania's national cyber security directorate. We did not check either with the issuer.
Source for the first, second and fourth points: Terms and Conditions, checked October 9, 2026.
What users say
On G2, Pentest-Tools.com shows 4.8 out of 5 from 109 reviews. G2's page data was dated September 28, 2026, and the profile is managed by the vendor. Reviewers tend to like the automation and the reports. The complaints G2 highlights are limited report customization and slow scans. (G2 listing, checked October 9, 2026)
Those reviews are about the software. They tell you little about the managed pentest.
The question buyers ask in forums is a fair one. In one Reddit thread, a small development shop with a customer asking for scans and pentests wanted to know if it was a reputable service. Our answer: the company is real. Which of its products that customer would accept is the part to check.
What we did and did not do
We read the company's pricing page, plan configurator, terms, help articles, service pages, documentation and one sample report on October 9, 2026. We worked out the totals and compared the pages against each other. We did not buy a plan, run a scan or commission a test, so we cannot tell you how many problems its tools find. No payment from any provider decides what we list or what we say about it. See how we make money.
What if Pentest-Tools.com is not the right fit?
Then the right move depends on what did not fit.
| Your situation | Where to look |
|---|---|
| You only need a quick look now and then | The Free Edition |
| You have a security person who prefers hands-on tools | Burp Suite, or ZAP, which is free and open source. We did not compare how well any of these find problems. |
| You already pay for a scanner or a compliance platform | Ask that provider the same report question first. You may not need to buy anything. |
| You need people doing the testing, with different retest or scope terms | Compare penetration testing companies |
If you came here looking for pentest tools in general, such as a list of scanners and hacking tools, this page is about one company. The table above is the closest we get.
Sources
All checked October 9, 2026. Prices and terms change, so confirm them on the provider's site before you pay.
| Source | What we used it for |
|---|---|
| Pricing page and plan configurator | Plan prices for 5 assets, plan features, asset rule, add-ons, refund wording |
| Terms and Conditions (last updated August 2025) | Refund limits, renewals, legal entity, governing law, liability cap, authorization |
| Refund help article (dated October 14, 2025) | Cancel-first rule, account closure and data deletion |
| Web app penetration testing page (updated August 19, 2026) | Managed test prices and timing |
| Services page (updated August 18, 2026) | Retesting, turnaround, who tests, compliance statements |
| AI Pentests page and docs | Early access, pricing model, limits |
| Free Edition page | Free plan limits |
| Data storage article (dated August 4, 2026) | Hosting regions |
| Sample scanner report | Report structure and scan settings |
| G2 listing | User rating and review themes |