Network audit
Any scanner lists your devices. This one tells you what to fix.
DeviceShelf names every device on your network, then checks the things a device list leaves out: open ports, weak TLS, exposed shares, default logins. It runs on your machine, and the results stay there.
€59 once · no subscription · no account · 14-day money back
The first scan usually finds nothing alarming, and that is a good outcome. What people keep the app for is the part after that: the security report, and an alert when something new joins.
The device list is the floor, not the product
Every tool in this category can show you a list of IP addresses. That part has been free for twenty years, and if it is all you need, take a free one — we say so on our comparison page.
Free scanners
Angry IP Scanner sweeps fast and stops at an IP and port list, by design. Advanced IP Scanner is Windows only and built around RDP and shared folders.
Fing
Mobile-first and cloud-backed. It needs an account, and presence alerts sit behind the Premium subscription while per-device bandwidth needs their Fingbox hardware.
DeviceShelf
Identification, a security report, live bandwidth, alerts and a 24/7 server edition in one licence. Desktop and phone. No account, no telemetry.
What the security report actually checks
This is the part you are paying for. It runs against the devices on your own network and gives each one a risk score with the reasoning attached.
- TLS grading and certificate inspection
- SSH key fingerprinting
- Exposed SMB shares, enumerated
- Default-credential checks
- Risky services: Telnet, RDP, ADB, Docker API, Redis
- CVE hints from data bundled in the app
- UPnP model and serial, SNMP system info
- nmap-style HTTP enumeration of admin paths
Already using nmap, and it is free
Then you can already scan, and nothing here will beat nmap at scanning. What €59 buys is not the sweep. It is not maintaining your own TLS grading, SSH fingerprint diffing, share enumeration and CVE correlation as a private script collection, plus the parts nmap does not do at all: per-device bandwidth over time, a topology map from LLDP and CDP, presence alerts, and a syslog server.
If your evening is worth more than €59, that is the whole trade. If it is not, nmap is genuinely a fine answer and we would rather you used it than felt sold to.
One licence, every machine you own
The desktop app is the core, on macOS, Windows and Linux. The iOS and Android apps run the same scan engine for when you are standing in the room instead of sitting at the desk. The headless 24/7 server edition adds continuous monitoring, alerts and a web dashboard on Docker, .deb or as a Windows service. One €59 licence activates all of them, on every device that belongs to you.
Why you can believe the privacy part
Check it yourself
With the optional online features off, the app never connects to a DeviceShelf server on its own. Point a packet capture at it during a scan and you will see LAN traffic only. The privacy page explains exactly what to look for.
The licence works offline
Activation is an ed25519 signature checked on your machine. There is no licence server to call, so there is nothing to log about you.
Refunds are a sentence, not a form
Within 14 days, email [email protected] and say you want your money back. No reason needed, no questions asked.
Scan your own network and see
Seven days, every feature unlocked, no account and no card. If the report turns up nothing, you have lost two minutes and gained a map of your network.