Skip to content
qsa.sh logo

External port and vulnerability scans from your terminal

Visit Website
Tracked since2026

The Bottom Line

Entry price

Free plan available, paid tiers above

Biggest pro

Zero installation, just run curl; no agent or software to deploy.

Biggest con

IPv4 only, IPv6 connections are refused.

TL;DR - qsa.sh

  • Run curl qsa.sh from your terminal to instantly scan your public IP for open ports, services, and vulnerabilities using open-source tools.
  • Results stream live and are never stored; you get a full external perspective without installing any software on your host.
  • Three tiers: free (top 1,000 ports), Full subscription (all ports, async), and Deep one-time (full nuclei set with emailed report).
Pricing: Free plan available
Best for: Growing teams

What is qsa.sh?

Editorial review
qsa.sh is a tool that performs an external port and vulnerability scan of your own public IP address, executed directly from your terminal with a single curl command. It uses open-source industry-standard tools, naabu for port discovery, nmap with the vulners script for service and CVE fingerprinting, and nuclei for exposure checks, all running from remote scanner nodes to give you an outside-in view of your host's internet-facing security posture. Scans are streamed live to your terminal, results are ephemeral (never stored), and the process is transparent: you see exactly what tools are run and can inspect the output in real time. The product is designed with strict safety constraints: it only scans the IP address from which the request originates, and it refuses to scan known CGNAT, mobile-carrier, proxy, VPN, or Tor addresses, as well as IPv6 origins. Each scan begins with a 15-second warning window during which you can abort, serving as a consent gate. Three tiers are available: a free tier scanning the top 1,000 TCP ports with a curated set of nuclei checks, a Full subscription requiring a paid plan covering all 65,535 ports with async delivery, and a Deep one-time scan for a set fee that runs the full nuclei template set and emails the report. Paid access uses one-time tokens without requiring an account.

Pros & Cons

Pros

  • Zero installation, just run curl; no agent or software to deploy.
  • Transparent and auditable, uses only public open-source tools, no black box.
  • Strictly limited to scanning your own IP, with consent gate and opt-out for operators.

Cons

  • IPv4 only, IPv6 connections are refused.
  • Free scan limited to one per 24 hours and only top 1,000 ports; Full and Deep require payment.

Key Features

Scans only your own connecting public IP – no target field, cannot be pointed at others.Uses naabu, nmap + vulners, and nuclei – all open source, transparent toolchain.Live terminal streaming of results as they are found (ports, services, versions, CVEs).No data stored; results ephemeral, only rate-limit counters retained temporarily.15-second pre-scan consent window with Ctrl-C abort option.Opt-out mechanism for IPs/ranges you control – permanently excluded from all scans.Paid tiers use one-time tokens with no account needed; reports delivered async or emailed.Refuses known CGNAT, mobile-carrier, proxy, VPN, Tor, and IPv6 origins.

Pricing Plans

Pricing checked Sep 7, 2026

Free

$0 / mo or Free

  • Top 1,000 TCP ports
  • -sV --script vulners
  • ~2,000 curated vuln checks
  • Ports, versions & top 3 findings
  • Nothing stored
  • 1 scan per 24h per IP
  • Live terminal stream
  • ~30 seconds typical time

Full Pro

$5 / mo

  • All 65,535 TCP ports
  • -sV --script vulners
  • ~2,000 curated vuln checks, all ports
  • Full list + remediation
  • Single-read or 24h Redis · no DB
  • 1 scan per hour per IP
  • Async — returns when ready
  • ~2–12 minutes typical time

Deep

$7 / scan

  • All 65,535 TCP ports
  • -sV --script vulners
  • ~10,500 full set + custom vuln checks
  • Full list + remediation, emailed
  • Emailed · single-read or 24h Redis · no DB
  • Unlimited scans per IP
  • Async — emailed report
  • ~13–16 minutes typical time

Is qsa.sh worth the price?

85/100

The pricing is generous for casual use with a free tier that covers the top 1,000 ports, but the $5/mo Full Pro tier is a steal for continuous scanning of all ports, while $7/scan for Deep is steep for occasional use.

The Free and Full Pro tiers offer excellent value for individuals and small teams, but the Deep tier's per-scan cost adds up fast for frequent scanning. Best for developers and security enthusiasts who need quick, no-fuss IP scans without managing infrastructure.

How qsa.sh's pricing compares

At $5/mo, qsa.sh is mid-range of its 4 direct competitors ($0.83 to $500/mo across the set).

qsa.sh
$5
$500

Entry paid plan, monthly. Pricing checked Sep 7, 2026.

Reviews

Improve Your Thinking Patterns Using ChatGPT cover
$99Free with your review

Review qsa.sh, get a free AI guide

Share your experience and we will send you Improve Your Thinking Patterns Using ChatGPT, free.

Write a review

Best qsa.sh Alternatives

Top alternatives based on features, pricing, and user needs.

View full list →

Most buyers shortlist 2 or 3 tools before committing. Pull a side-by-side comparison or browse the full alternatives shortlist below.

Explore More

qsa.sh FAQ

How does qsa.sh help a developer quickly assess their public IP's security posture from the command line?

qsa.sh performs an external port and vulnerability scan of your own public IP address directly from your terminal with a single curl command. Scans are streamed live, showing you exactly which open ports and CVEs are exposed, using only open-source tools like naabu, nmap, and nuclei. This gives developers an immediate outside-in view of their internet-facing security without installing any software.

How does qsa.sh compare to Hacktron for scanning your own IP?

Unlike Hacktron, qsa.sh runs entirely from your terminal with a single curl command, requiring no installation or account for free scans. qsa.sh is limited to scanning only the IP from which the request originates and includes a consent gate, making it strictly self-service and transparent.

Does qsa.sh support scanning of IPv6 addresses or connections from proxies?

No, qsa.sh refuses to scan IPv6 origins, as well as known CGNAT, mobile-carrier, proxy, VPN, or Tor addresses. This is a safety constraint to ensure only direct public IPv4 scans are performed.

What kind of user benefits most from qsa.sh's ephemeral and transparent scanning workflow?

Individual developers, security engineers, and site reliability engineers who need a quick, agentless way to audit their own host's external attack surface from the command line benefit most. The transparent, real-time output and ephemeral results suit users who prefer auditable security checks without data storage.

How is qsa.sh priced?

qsa.sh offers a free tier that scans the top 1,000 TCP ports with curated nuclei checks once per 24 hours. A paid Full subscription covers all 65,535 ports with async delivery, and a Deep one-time scan runs the full nuclei template set and emails the report. Paid access uses one-time tokens without requiring an account.

Can qsa.sh scan all 65,535 TCP ports or only a subset?

The free tier scans only the top 1,000 TCP ports with a curated set of nuclei checks. Full 65,535 port scanning is available with the paid Full subscription or the Deep one-time scan.

How does qsa.sh ensure that only the requesting IP is scanned and prevent misuse?

The tool strictly scans only the IP address from which the curl request originates, and it refuses to scan known CGNAT, mobile-carrier, proxy, VPN, or Tor addresses. Each scan begins with a 15-second warning window during which you can abort, serving as a consent gate.

What tools does qsa.sh run under the hood during a scan?

qsa.sh uses naabu for port discovery, nmap with the vulners script for service and CVE fingerprinting, and nuclei for exposure checks. All tools are open-source and run from remote scanner nodes, with output streamed live to your terminal so you can inspect the process in real time.

Source: qsa.sh

Guides & Articles