Cheap penetration test: when the PDF is just a scanner
Sub-$1,000 full pentest quotes are usually a scanner PDF. Here is how a cheap penetration test differs from a human pass on auth and APIs.
A cheap penetration test ad is honest about one thing: it is cheap.
It is rarely honest about the work. Unlimited apps, 24-hour turnaround, and a “certificate” for $399 is a scanner with a mail merge.
Short answer: If the quote is under $1,000 and promises a full pentest, assume tool output. A human web application security review of one app is $2,400.
What a scanner is good for
Noise you already know: outdated libraries, missing headers, default pages. Fine as a first pass on a staging box you control.
What it misses
A signed-in user reading another organization’s invoice. A reset flow that issues the same token twice. An export that ignores role. That is why the sample report is written like a person was in the app.
Same offer on pricing.
FAQ
Why are some penetration tests under $1,000? +
Because they are mostly automated scans with a cover page. A human authenticated pass costs more time.
Is cheap always bad? +
A cheap scan can still find missing headers. It will not reliably find an IDOR on a multi-tenant API.
What does a human review cost here? +
$2,400 per application, $1,200 to start, 48 hours after access, one free retest.