Skip to content
qsa.sh logo

Instant external security scan of your own IP from your terminal

Visit Website
Tracked since2026
0 reviews tracked

The Bottom Line

Entry price

Free plan available, paid tiers above

Biggest pro

Zero installation – just run curl; no agent or software to deploy.

Biggest con

IPv4 only – IPv6 connections are refused.

TL;DR - qsa.sh

  • Run curl qsa.sh from your terminal to instantly scan your public IP for open ports, services, and vulnerabilities using open-source tools.
  • Results stream live and are never stored; you get a full external perspective without installing any software on your host.
  • Three tiers: free (top 1,000 ports), Full subscription (all ports, async), and Deep one-time (full nuclei set with emailed report).
Pricing: Free plan available
Best for: Growing teams

What is qsa.sh?

Editorial review
qsa.sh is a tool that performs an external port and vulnerability scan of your own public IP address, executed directly from your terminal with a single curl command. It uses open-source industry-standard tools—naabu for port discovery, nmap with the vulners script for service and CVE fingerprinting, and nuclei for exposure checks—all running from remote scanner nodes to give you an outside-in view of your host's internet-facing security posture. Scans are streamed live to your terminal, results are ephemeral (never stored), and the process is transparent: you see exactly what tools are run and can inspect the output in real time. The product is designed with strict safety constraints: it only scans the IP address from which the request originates, and it refuses to scan known CGNAT, mobile-carrier, proxy, VPN, or Tor addresses, as well as IPv6 origins. Each scan begins with a 15-second warning window during which you can abort, serving as a consent gate. Three tiers are available: a free tier scanning the top 1,000 TCP ports with a curated set of nuclei checks, a Full subscription ($5/month) covering all 65,535 ports with async delivery, and a Deep one-time scan ($7) that runs the full nuclei template set and emails the report. Paid access uses one-time tokens without requiring an account.

Pros & Cons

Pros

  • Zero installation – just run curl; no agent or software to deploy.
  • Transparent and auditable – uses only public open-source tools, no black box.
  • Strictly limited to scanning your own IP, with consent gate and opt-out for operators.

Cons

  • IPv4 only – IPv6 connections are refused.
  • Free scan limited to one per 24 hours and only top 1,000 ports; Full and Deep require payment.

Key Features

Scans only your own connecting public IP – no target field, cannot be pointed at others.Uses naabu, nmap + vulners, and nuclei – all open source, transparent toolchain.Live terminal streaming of results as they are found (ports, services, versions, CVEs).No data stored; results ephemeral, only rate-limit counters retained temporarily.15-second pre-scan consent window with Ctrl-C abort option.Opt-out mechanism for IPs/ranges you control – permanently excluded from all scans.Paid tiers use one-time tokens with no account needed; reports delivered async or emailed.Refuses known CGNAT, mobile-carrier, proxy, VPN, Tor, and IPv6 origins.

Pricing Plans

Free

$0 / mo or Free

  • Top 1,000 TCP ports
  • -sV --script vulners
  • ~2,000 curated vuln checks
  • Ports, versions & top 3 findings
  • Nothing stored
  • 1 scan per 24h per IP
  • Live terminal stream
  • ~30 seconds typical time

Full Pro

$5 / mo

  • All 65,535 TCP ports
  • -sV --script vulners
  • ~2,000 curated vuln checks, all ports
  • Full list + remediation
  • Single-read or 24h Redis · no DB
  • 1 scan per hour per IP
  • Async — returns when ready
  • ~2–12 minutes typical time

Deep

$7 / scan

  • All 65,535 TCP ports
  • -sV --script vulners
  • ~10,500 full set + custom vuln checks
  • Full list + remediation, emailed
  • Emailed · single-read or 24h Redis · no DB
  • Unlimited scans per IP
  • Async — emailed report
  • ~13–16 minutes typical time

How qsa.sh's pricing compares

At $5/mo, qsa.sh is mid-range of its 6 direct competitors ($3.33 to $277.08/mo across the set).

$3.33
$3.75
qsa.sh
$5
$25
$249.17
$277.08

Entry paid plan, monthly.

Reviews

Improve Your Thinking Patterns Using ChatGPT cover
$99Free with your review

Review qsa.sh, get a free AI guide

Share your experience and we will send you Improve Your Thinking Patterns Using ChatGPT, free.

Write a review

Best qsa.sh Alternatives

Top alternatives based on features, pricing, and user needs.

View full list →

Most buyers shortlist 2 or 3 tools before committing. Pull a side-by-side comparison or browse the full alternatives shortlist below.

Explore More

qsa.sh FAQ

Can I use qsa.sh to scan someone else's IP address?

No. qsa.sh only ever scans the public IP from which your request originates. There is no field to enter a target, and known CGNAT, mobile-carrier, proxy, VPN, Tor, and IPv6 origins are refused outright.

What happens if my internet connection uses Carrier-Grade NAT (CGNAT)?

CGNAT and mobile-carrier ranges are blocked by default because no single user can be authorized for a shared gateway. The scan will not run, and the service returns a refusal message.

How long does a free scan typically take?

A free scan usually completes in about 30 seconds, scanning the top 1,000 TCP ports with nmap service detection and ~2,000 curated nuclei checks. Scan time can vary based on network latency, open ports, and matching checks.

What open-source tools does qsa.sh actually run?

It runs naabu 2.6.1 for port discovery, nmap 7.93 with the vulners script for service and CVE fingerprinting, and nuclei 3.3.9 with the public nuclei-templates – all open source, no proprietary software.

Can I permanently stop qsa.sh from scanning an IP I control?

Yes. You can request an opt-out for any IP or CIDR range you control via the contact form. Once added, the range is refused before any scan packet is sent, and the exclusion applies to all tiers.

How are paid Full and Deep scan results delivered?

Full scans are delivered asynchronously – you receive a one-time token and fetch the result when ready (results auto-purge after 24 hours). Deep scans email a report and a single-read results link that expires after first access or 24 hours.

What prevents me from bypassing the IP restriction by using a VPN or proxy?

qsa.sh uses best-effort reputation data to detect and refuse connections from known proxies, VPNs, and Tor relays, because those anonymizers hide the true origin IP. Only connections from direct, non-anonymized IPs are allowed.

Is qsa.sh considered a vulnerability scanner that could be abused?

qsa.sh is designed as a self-scanning tool with multiple safety layers: it only scans the connecting IP, requires explicit consent via the 15-second window, refuses shared/anonymized origins, and provides an opt-out mechanism for operators. It never authenticates or attempts exploitation.

Source: qsa.sh