A full code audit costs $49 while the first 50 scans last, then $99, paid once per scan. That is the price before you wire for a micro-SaaS on Flippa, Acquire.com or TrustMRR, or before you pay an agency's final invoice. The free checks come first, so you never buy a report blind. No subscription, no call, no retainer, and the code is never executed.
| tier | price | what it finds | what it can't |
|---|---|---|---|
| Free URL check | $0 | One page fetched as the public sees it: exposed keys in page source and scripts, security headers, mixed content, SPF and DMARC, version disclosure, test-mode payment keys. Grade A to F in about a minute.Check a URL | Read source code, log in, or run active checks. It sees what a visitor sees. |
| Free repo preview | $0 | Connect GitHub read-only or upload a zip. The full scan runs; you see the grade and the count of critical findings before paying.Start a scan | Show you the file, the line, or the fix. That detail is the report. |
| Full code audit | $49$99 | Every finding with file and line, the exact code, a plain-English explanation, a first step you can paste into your AI coding tool, a PDF, and a list of what was and wasn't checked.Get the full report ($49, first 50 scans) | Test the live app, verify runtime behaviour, or certify anything. It reads the code; it never runs it. |
| Deep URL scan | $15 | For a live site without repo access. Active and wide checks, first-party scripts fetched and scanned, every finding explained with the fix.Start with the free check | See server-side code or the database. It is a scan of a URL, not of source. |
A source-level audit of the repository you connect or upload, for $49 while the first 50 scans last and $99 after. Deterministic tools locate every finding; the plain-English explanation is written afterwards and never invents one. Each finding carries the file, line and snippet, so a developer, a seller or an AI coding agent can go straight to it. The report also prints what was not checked.
our own data, not a vendor study
What the price buys, in numbers: in September 2026 we scanned 70 public Lovable apps with the same checks a paid report runs. 28 of them, 40%, had a critical or high problem in code their own team wrote, and 19 of the 33 with edge functions had an endpoint anyone could call. The raw numbers are published. Read the Lovable security report →
Two things are free and they answer different questions. The URL check looks at a live site from the outside: one page, fetched as a visitor would, graded on exposed keys, security headers, mixed content, email spoofing protection and payment configuration. No access needed, about a minute.
The repo preview looks at the inside. It runs the same scan as the paid audit and shows the grade and the critical count, with the detail withheld. If the count is zero, stop there; you have paid nothing.
Planned, not shipped. A paid scan with no critical findings will earn a badge for a listing, a data room or a client handover, linking to a page with the scan date, the commit covered and the checks run. It expires after 90 days or when the branch moves, so it never vouches for code it has not seen. Included with the full audit at no extra cost. Until it ships, forward the PDF.
You need a code audit at a moment, not on a schedule: before you ship, before you pay the final invoice, before you buy someone else's SaaS. A subscription would bill the months in between. Run it again on the next milestone or the next deal at the same one-time price.
The option buyers cite most is a freelance developer for a one-off review, $500 to $1,500 for a few hours of one person's attention, with nothing to forward to the seller afterwards. Agencies quote $5,000 to $50,000 for technical due diligence. Below that, a few solo engineers read AI-built repos by hand, from $49 with a two-day turnaround. Ascertify is $49 while the first 50 scans last, $99 after, with a report in minutes, because it reads the code and never runs it: no engineer hours, no scheduling, no scope call.
| option | price | turnaround | what you get | reads the code |
|---|---|---|---|---|
| Ascertify full code audit | $49 (first 50), $99 after | Minutes | Static scan, every finding pinned to file and line, PDF. | yes |
| Afterbuild Labs repo audit | $49 | 48 hours | One engineer reads AI-built repos by hand and writes a PDF. | yes |
| Consolices app audit | $499 | 48 hours | Senior engineer, written report and a video walkthrough. | yes |
| Freelance developer, one-off code review | $500 to $1,500 | Varies by developer | A human reads the repo once. Not repeatable, and no evidence trail to forward to the seller. Range from buyer threads, 2026. | yes |
| BuildScore full audit | $1,499 | 48 hours | Human analysts, code review plus revenue and churn checks. | yes |
| WebAcquisition micro-SaaS due diligence | $2,900+ | 7 business days | Financial and operational diligence. Does not review the code. | no |
| Agency technical due diligence | $5,000+ | 1 to 2 weeks | Bespoke engagement, scoped and quoted per deal. | yes |
Third-party prices as published on their own websites on 10 Sep 2026. The freelance range is what buyers report paying in public forum threads in 2026, not a published rate. None of these services is affiliated with Ascertify. Ascertify is a static scan, not a manual review or a penetration test; the sample report shows what it does and doesn't cover. A longer breakdown of technical due diligence costs is coming; until then the due diligence overview has the full cost table.
If there is nothing to worry about, that is worth knowing and it costs nothing. If there is, the full report is $49 while the first 50 scans last, $99 after.
Start a scan