Pricing

The facts are free. The work is paid.

Every score, and every risk we hold about a tool you name, is free forever. People and agents alike. Right now 3,611 of the things we measure are abandoned or deprecated. What costs money is the work: your toolbox watched over time, or the answer assembled on demand.

Free $0/forever

Every fact we hold. A finding is never paywalled: what the scan found is free, including the fix. This product exists to stop you installing something dangerous. Charging for that would make it worse at its own job.

  • The risk scan in full. Which CVE or GHSA, its severity, the version that fixes it, the exact command a package runs at install time, everything it can reach on your machine. The detail, not the count.
  • The whole Index. Every tashan score and instruction-depth grade, filed by the job it is for.
  • doctor, on your machine. Your own config, no account, nothing uploaded.
  • Badges and the agent endpoints. Ask about any tool by name. No key, no quota.
Browse the Index ›

no account · no key · no quota

tashan Pro $6/mo

The work, done for you. Free tells you what is true today. Pro adds the history behind each row, so a number has a direction and not just a value, and names the replacement for anything dead.

$ tashan doctor # with Pro: score history and the named replacement
  • A new advisory against something you run
  • An install script that appeared or changed
  • A permission surface that widened
  • A project stopping — deprecated, archived, abandoned
  • A maintainer count falling to one
  • The replacement, named — where a measured one exists, not just "this is dead"
$6 monthly ›

Annual: $50/yr — two months free

7 days free, then $6/mo · cancel any time in your account

And if the buyer is an agent

per call · no account

Your agent does not want a subscription. It turns up once, needs an answer, and can pay for it by itself.

Which is also why we are on our own paid board, at $0.00 until somebody does.

What an alert actually says

What changed, why it matters, what to do about it. A warning that only says "something changed" is one you learn to ignore, so we do not send those.

! @acme/db-mcp — install script added in 2.1.0
  runs: node ./scripts/post.js — it did not in 2.0.4, which is what you installed
  → pin 2.0.4, or switch to pg-mcp (scores 78, no install script)

The scan is not what Pro sells. Every finding is free, in full, for everyone — which CVE, its severity, the version that fixes it, the exact install command. Pro sells time: the whole series behind a row, so today’s number has a direction and not just a value.

Building on tashan? Asking is free: every score, every risk we hold about a tool you name, for people and agents alike, no key and no quota. The assembled answers are priced: the kit with versions pinned, the advisory detail and the fix, the history behind a row. A licence covers them, or an agent pays per call with x402 — no account, fractions of a cent. Swap one base URL ›
The ranking guarantee. Commercial relationships never influence task fit, measurements, findings, rankings or editorial recommendations. It is asserted in code — tests/test_firewall.py fails the build if the scorer reads anything but public-signal columns. Everything above is sold on time, never on position.

Questions

What am I paying for today?

Being told the day something you already run changes.

  • Gains an advisory
  • Starts executing code at install time
  • Widens what it can reach
  • Loses its maintainers, or is abandoned
  • The named replacement, when it is time to move

The score series is included. A trend needs about a month to mean anything; that clock restarted on 30 July after a recalibration.

Why isn't this free like everything else?

Because a change can only be seen once — on the day it happens.

Every measurement on the Index is a snapshot anyone could recompute from public sources. A change is not: it exists only because we recorded yesterday.

How do I sign in?

No key to copy. Run tashan login — it prints a short code and opens your browser to approve. The same flow as gh auth login.

Stored in ~/.config/tashan/key, so a new terminal needs nothing. Your config is never uploaded — the CLI reads local files and asks us only about capability names.

Do I get an account?

Yes. Plan, renewal date, activated machines, licence key and invoices.

tashan account opens it already signed in — no password to make. doctor prints Pro · licence active on every run.

How many machines?

As many as you use. Run tashan login on each.

Each registers under its hostname, so your account lists what is active. tashan logout hands a slot back.

Can a publisher pay to rank higher?

No. Nothing purchasable moves a score, rank or listing.

Enforced, not promised: tests/test_firewall.py fails the build if the scorer reads anything but public-signal columns.

Team or company use?

The data API is live and free — see for hosts. Org-wide auditing of your own internal skills and servers is not built yet; tell us what you need and it shapes what gets built.

‹ Back to the Index