Free
- 1 domain, no subdomains
- Weekly automatic check with an email report — free while Forge is in beta, with 30 days' notice before that changes
Security audits for shipped code

Hackers don't break down doors. They look for the gap.Forge closes the gap before they find it.
Your site gets checked weekly — no need to remember when you last scanned anything. Reports land in your inbox.
Autopilot it nowWe provide a purpose-built harness that already optimizes token spend — nothing is built from scratch per scan, and no dedicated memory-heavy server is needed. You pay a flat price, not the cost of running checks yourself.
Every issue comes with a concrete step to close it, not just a red flag. You don’t just learn it’s broken — you learn how to make it right.
Ship a new version, run a scan. Per-release audits on demand, so a hole never reaches your users.
You read a friendly UI. Your agent (Cursor, Copilot, Claude, OpenClaw) drives the same engine through API/MCP. One engine, two ways in.
Every check we run today, and every one on the way — grouped by what it looks at, with what each one needs to start.
All checks catalogDrop in your domain and verify ownership with a quick email or TXT record.
Passive checks (DNS, SSL, headers, SEO, OG) run instantly. Verified domains unlock active passes: crawling, forms, secret leaks, outdated components.
Every finding is a plain-English risk with a concrete fix, not tech noise.
Connect your agent through MCP/API to read reports and trigger scans, or run checks yourself in the UI before each release.
A weekly audit with an email report lands for every domain, no remembering required.
Yes. After registration you get one free domain, with a weekly automatic check and an email report — free while Forge is in beta, with 30 days' notice before that changes. Pro covers 3 domains with up to 3 subdomains for each domain, and Max adds a dedicated pentest server in your private network.
Yes. Forge exposes the same engine through API and MCP, so agents in Cursor, Copilot, Claude Desktop or OpenClaw can trigger scans and read reports. Humans read the UI, agents act through MCP.
No. Forge translates raw tech findings into plain language. Instead of "Missing Strict-Transport-Security header" you get "Your site allows unencrypted connections — here's how to turn on protection." Every finding ships as a simple risk plus concrete fix steps.
All checks are non-destructive. Passive checks read only publicly visible data — DNS, SSL, headers, meta tags — the same stuff anyone on the internet can see. Active checks (crawling, forms, secret-leak scanning) only run after you verify domain ownership. We scan, we don't attack.
Verification protects you. It makes sure active checks run only on your request as the real owner — not on someone else's whim. It's the gate that separates "reading what's public" from "probing deeper."
Passive checks read what your site already exposes — DNS, certificate, HTTP headers, SEO and social markup. They're available right away. Active checks go further — crawl pages, test forms, hunt secret leaks — and unlock after domain verification. Deeper verification, broader coverage.
For you. Forge is built for VibeCoders and developers without a security team. It closes the gap between "I quickly shipped something" and "this is built like a professional team would." Pros can hook into the same engine via API/MCP — but the UI speaks your language.