A platform dedicated to providing unbiased reviews of newly launched applications, analyzing everything from their features to their full potential.
info@scoutforge.net© 2026 Scoutforge. All rights reserved.
A platform dedicated to providing unbiased reviews of newly launched applications, analyzing everything from their features to their full potential.
info@scoutforge.net© 2026 Scoutforge. All rights reserved.
A platform dedicated to providing unbiased reviews of newly launched applications, analyzing everything from their features to their full potential.
info@scoutforge.net© 2026 Scoutforge. All rights reserved.
Cycling through all six. Tap any point to stop.
Measured on six things
Instant external security scan of your own IP via curl co...
Brand-new Product Hunt launch with modest ~100 upvotes. No reviews, no GitHub, no community presence yet. Early trajectory only.
qsa.sh is a refreshingly simple security tool that lets you run a full external port and vulnerability scan on your own public IP with a single curl command. No installation, no agents, no account required. Under the hood, it chains together naabu, nmap with vulners, and nuclei to check for open ports, service versions, TLS posture, and known CVEs—all streamed live to your terminal in about 30 seconds. The Free tier covers the top 1,000 ports and ~2,000 nuclei templates; Full ($5/mo) expands to all 65,535 ports; Deep ($7 one-time) runs the entire nuclei template set (~10,500) for a thorough 13–16 minute scan with a full emailed report. I love how it gives you an outside-in perspective of your own host without any setup hassle. Just run curl qsa.sh or curl https://qsa.sh (encrypted) and watch the results pour in. It's perfect for quick security assessments, but remember—you can only scan your own IP, and known CGNAT, carrier, proxy, VPN, and Tor addresses are blocked. The ephemeral n...
Drawn from the product itself, not from a survey.
Demographic
Sysadmins and DevOps engineers
Pain points
Need quick, agentless external vulnerability checks on personal or lab IPs
Primary needs
Instant scan, no install, live terminal output
Demographic
Security researchers and penetration testers
Pain points
Want to verify tool output or get a fast outside-in perspective on own IP
Primary needs
Comprehensive CVE checks, multiple scan depths, no stored results
Demographic
Freelancers and small business IT managers
Pain points
Limited budget for security tools, need a free or low-cost scan option
Primary needs
Cost-effective, easy to use, immediate actionable findings
Written by AI from measured evidence, scored out of 100.
qsa.sh delivers exactly what it promises: a zero-friction external scan of your own public IP using well-known open-source tools. The experience is fast, transparent, and refreshingly free of accounts or installs. Limitations around target scope and carrier networks are honest and well documented. The product is still extremely young, so polish and community signals remain light.
One-command external scan with zero setup. Clear consent gate and tier comparison table. Limited to own IP only and blocks common CGNAT/carrier ranges.
Clean terminal-first aesthetic with strong code-block focus and consistent dark theme. Hero feels cramped and navigation is generic with low-contrast elements.
Perfect Lighthouse 100/100 on both mobile and desktop. Minimal assets and fast LCP keep the landing page snappy.
Strong header hygiene (CSP, secure cookies, frame protection) but missing HSTS and email auth records. No third-party compliance attestations published.
Automated score 100/100 with one minor label mismatch. Responsive dark theme works well; no dedicated accessibility statement or language options.
Brand-new Product Hunt launch with modest ~100 upvotes. No reviews, no GitHub, no community presence yet. Early trajectory only.
qsa.sh leans hard into terminal minimalism. The hero puts the curl command front and center, which matches the product's entire value prop. Navigation is functional but unremarkable, and the body text below the fold gets dense quickly. On the usability side, the one-command experience is genuinely delightful—no accounts, no agents, instant feedback. The hard limits (own IP only, CGNAT blocks, 15-second consent window) are clearly communicated and feel like deliberate safety choices rather than afterthoughts. Pricing comparison on its own page removes guesswork.
Performance is excellent; Lighthouse hands it perfect scores on both mobile and desktop thanks to tiny assets and a static-first approach. Security headers are mostly solid (CSP, secure cookies, proper referrer policy) but the absence of HSTS and SPF/DMARC keeps it from feeling enterprise-grade. No public audits or bug-bounty program appear on the site or in search results, which is typical for a solo or tiny-team side project at this stage.
Accessibility scores top marks in automated testing with only one minor label issue. The dark theme maintains good contrast and the layout is responsive. Growth is the weakest dimension: the product launched on Product Hunt in the last week of July 2026 and has collected roughly 100 upvotes with almost no other footprint—no GitHub repo, no independent reviews, and only a couple of Reddit launch posts. At this age that is normal, but it also means the traction story is still just beginning.
Conclusion
If you need a quick outside-in check on a VPS or lab box you control, qsa.sh is worth a curl right now. Just remember it only ever scans the IP you connect from.
Named competitors, point by point. Nobody paid to appear here or to be left out.
| Installation required | None (curl only) | Local install required | None (web service) | Local install required |
|---|---|---|---|---|
| Target scope | Own public IP only | Any IP (with permission) | Any indexed device | Any target (local run) |
| Live terminal output | Yes, streamed | Yes, local CLI | No (web dashboard) | Yes, local CLI |
| Pricing model | Free tier + $5/mo or $7 one-time | Free / open source | Free tier + paid plans | Free / open source |
Nmap
Traditional network scanning tool requiring local installation and manual setup.
Shodan
Internet-connected device search engine; provides external perspective but not live scans of your IP.
Nuclei
Fast vulnerability scanner; qsa.sh uses it but does so remotely via curl without local install.
Comparing options? See qsa.sh alternatives, scored side by side
What the review was written against. A verdict with no sources is an opinion.
Sidenty is a professional digital identity protection ser...
A native macOS process explorer and advanced monitor that...
Real-device browser automation for AI agents
Native macOS SSH, SFTP & RDP client with a Keychain-backe...
Password manager with no email, no account, no tracking. ...
Reveal No Caller ID, unknown numbers, and private callers...
A zero-config AI-powered vulnerability scanner automating...
A security solution that integrates VPN access with identity platforms to reduce network vulnerabilities and protect against zero-day exploits.
CyberSafe Pro is a completely offline password manager that stores your credentials securely on your device using military-grade encryption.
Advanced parental control software for Windows & Android
An encrypted digital legacy service that securely deliver...
AuditReady è una piattaforma per gestire conformità, controlli, responsabilità ed evidenze in un unico ambiente, con supporto per GDPR, NIS2, DORA, ISO 27001, AI Act e Modello 231.
A platform dedicated to providing unbiased reviews of newly launched applications, analyzing everything from their features to their full potential.
info@scoutforge.net© 2026 Scoutforge. All rights reserved.