SVOSoftware Verification & Operations🏠Step by stepHow to measureQuoteOrderFree trialCVEs & creditsTalk about my scopePortuguΓͺs

Request your quote

Pick the track by where your system is. The price comes from the current table β€” measured, not estimated.

Start by where your system is:

CodeHost / Server

Source code β€” on your machine or on the server

Models 1 (code on your machine) and 2 (on the server where it runs). In both, the price comes from the measured size: you run a read-only meter, it writes a manifesto.json, and the quote comes out on that number.

Haven't measured yet? Measure first β€” a few minutes, and the guide has screenshots.

Already have the manifesto.json? Get the quote

The model
The level
What is ONE and what is Deep?

ONE β€” one agent searches and judges each finding against the code itself. Deep β€” several agents search in parallel and other agents judge, without having taken part in the discovery.

Deep reaches further and costs more β€” but it does not always deliver more. It pays off where there are boundaries: separate subsystems, client and server, a binary talking to the host, code talking to the database. In a flat system the gain is small. We measured both: with many boundaries Deep found 4.5Γ— more; in a flat folder, 1.23Γ—.

When in doubt, ask for both prices β€” it is the default here, it costs nothing and commits you to nothing. With both numbers in hand, and knowing your own system, the choice is yours. And if yours is one of the cases where Deep is not worth it, we will say so.

Only the manifesto β€” it carries file names and counts, never your code's content. Open and check it first; it is readable JSON.

Infrastructure β€” the server, not the code

No code is measured here β€” the price is from the table. Pick the model, the level and (for the whole server) the number of domains, and the value shows right away.

3 β€” Host: your application on a server that is not yours. Only it is in scope β€” the host stays out and is not mentioned in the report. Each domain is a full audit: price per domain.

4 β€” MultiHost: the server is yours and goes in whole β€” system, firewall, remote access, updates and every service, plus the applications. Host work is done once: price by domain band.

5 β€” Share: the public service seen from outside. Fixed price.

It appears in the report, in your scope form and in the name of the file you download β€” it is how you will recognise this audit among yours.

The model
The level
What is ONE and what is Deep?

ONE β€” one agent searches and judges each finding against the code itself. Deep β€” several agents search in parallel and other agents judge, without having taken part in the discovery.

Share is ONE level only. Host and MultiHost have both levels.

πŸ”‘ The access is yours, and stays yours. The audit runs on your machine, with the access you already use β€” we do not ask for and do not receive passwords or keys. What changes the reach is having a shell: with it the audit gets to cron, running processes and the effective PHP configuration; without it it still holds β€” files, permissions, .htaccess, versions, database β€”, but it does not reach those three, and the report says so plainly.

πŸ”‘ The access is yours, and stays yours. The audit runs inside your machine: you log in the way you already do and install Claude Code in your user's home β€” no sudo, no system packages, and the guide has the command to remove it afterwards. We do not ask for and do not receive passwords or keys.

⭐ With Share you prove the domain is yours before the audit starts β€” by publishing a file under /.well-known/ or a DNS TXT record. The value to publish comes in your kit, and you may remove it afterwards. If you have access to neither the DNS nor the site's server, talk to us before buying.

πŸ”Ž Every plugin and theme is compared against the official package, file by file. That is how a tampered plugin on the latest version shows up β€” the one that passes any check by version number. Also included: signs of planted files, permissions, how your account is isolated on the server, and credentials left in a public folder. πŸ”‘ Only here the access is ours β€” and it is our PUBLIC key. With WordPress the audit runs on our server: you paste the key we send into your hosting panel (Hostinger: Sites β†’ Advanced β†’ SSH Access β†’ SSH Keys), and you may revoke it whenever you want. The private key never leaves our enclave and we receive no password at all. ⚠️ The panel must provide a shell β€” SFTP alone will not do. The amount appears on its own line in the quote.

What you need to have before you order
  • A hosting panel that offers SSH access β€” and that gives a shell, not just SFTP. That is the gate: without a shell we cannot list plugins and versions, and the product does not run. (On Hostinger: Sites β†’ Advanced β†’ SSH Access.)
  • Being able to paste our public key into that panel. We send the key; you paste it, and you remove it whenever you want.
  • Host, user and port β€” the same panel screen shows all three once the key is in. ⚠️ The port is rarely 22 (in our test it was 65002).
  • The path to the site root (something like ~/domains/yoursite.com/public_html). A wrong path returns an empty collection β€” it has happened to us.

πŸ”΄ No passwords β€” neither FTP nor panel. Only the public key, which is yours to revoke.

The value appears on screen, from the current table β€” with the link to place the order. The same link goes to your e-mail; the order is only created when you confirm.

Already have a quote?

If you already got your quote number, the order page is where you confirm and pay.