Run a real penetration test from your browser and get a validated report the same day. No consultant to book, no quote to wait for, no card required for your first test.
Searching for a way to pentest your site usually ends in one of two places: a free scanner that emails you a list of maybes, or a consultancy that quotes R50 000 and a slot in six weeks. PentestMe is the third option: a full penetration test you start online in minutes, worked through the same phases a professional tester follows, with every finding graded by the strength of the evidence behind it.
Enter your domain, then verify control with a _pentestme TXT record or a file at /.well-known/pentestme-verification.txt. Testing anything you do not control is off the table, and a server-side scope guard enforces that on every request.
Recon, enumeration and vulnerability discovery run in parallel across your web application, tracked against the OWASP WSTG checklist, covering the OWASP Top 10, injection, authentication, access control and business logic.
Every finding carries its evidence tier: proven by safe exploitation, confirmed by observed behaviour, or flagged as potential and needing confirmation. You know which findings to action immediately and which to verify, instead of a flat list where everything looks equally urgent.
Executive summary, risk score, per-finding evidence, remediation steps and a retest path, mapped to CVSS and MITRE ATT&CK.
Plenty of tools will “pentest your website” free in thirty seconds. What they run is a vulnerability scan: a signature sweep that produces a list of potential issues, most of which turn out to be noise.
A scan hands you a flat list of possible issues. This works through a methodology, chains related weaknesses, safely proves what it can, and tells you plainly how strong the evidence is for everything else.
Automated vs manual pentestingTesting is designed for production.
Exploit validation confirms a vulnerability is real without destructive actions.
Anything more intrusive runs only behind explicit, per-engagement authorisation.
Throughput stays controlled so your site stays up while it is being tested.
Plans start at R3 449 a month for two pentests, against R50 000 to R150 000 for a single traditional engagement. Your first pentest is free, with no card required, so you can judge the report before you pay anything.
The same platform tests APIs, network infrastructure, cloud environments, email and VoIP, under one scope, from one place.
Yes. Your first pentest is a full assessment of one target with a validated report, no card required. If the report is useful, pick a monthly plan; if not, there is nothing to cancel.
Most complete the same day you start them. Larger scopes take longer, but you are never waiting weeks for a slot or a write-up.
No. For a standard web pentest everything runs from our platform against your public site. You add a DNS record or host a small file once, to prove the domain is yours.
A real test. Engagements follow the PTES phases and track coverage against the OWASP WSTG, and every finding carries an evidence grade, with the strongest proven by safe exploitation. A scan stops at "possible issue".
Reports are dated, evidence-backed, and mapped to PCI DSS, ISO 27001 and SOC 2, and stand as evidence toward POPIA.
Run a real, validated penetration test on your own site before you pay anything. No credit card.
Start your free pentest