Discover what's on your Wi-Fi — and what's actually risky.
Privacy-first network scanner for iOS. No accounts, no servers, no subscriptions. Find the devices on your network — Macs, PCs, phones, printers, smart TVs, routers, smart speakers and smart-home gear — see what each one is where it gives enough away, and unlock a single ranked view of every security finding with Pro.
Most network scanners hand you a wall of port numbers and walk away. NetScanPro explains them in plain language — and now goes a step further, telling you what's actually risky versus what's just good to know.
The ports that carry real risk get a security note with a severity tier and a specific action. Tap port 445 and SMB is flagged as a genuine risk, with the WannaCry context and what to do about it. Tap 3389 and RDP is called out as a frequent attack target, with Network Level Authentication and a strong password as the fix. RTSP explains that cameras left on default credentials are how cameras get hijacked; port 9100 explains that an open print port can be used to pull data from print queues. Not every port has a note — the ones that matter do. Port scanning is part of Pro.
Network printers, IP cameras, RDP, Telnet, MQTT, VNC — services that are harmless on your home Wi-Fi but a problem if your network is misconfigured. NetScanPro finds them, and flags the ones that carry real risk.
It's built for the curious — people who want to know what's actually running on their network, and what to do about it.
Scan every device on your network at once and see all your security findings in one place — grouped by service, ordered worst-first, color-coded by severity. Tap any finding to see exactly which devices are affected.
After a port scan, the Security Summary lists every device with an open web port, and each row opens that device in Safari with a tap. The same button appears on the device's own screen. What loads varies — some devices open straight to a router or camera login, others return an error page or a blank one. An open port proves the device answered, not that there's a page behind it. Port scanning is part of Pro.
Scans your Wi-Fi using four discovery methods in parallel — TCP probing, Bonjour/mDNS, SSDP/UPnP, and ICMP ping. Finds Macs, PCs, phones, printers, smart TVs, routers, smart speakers, and smart-home devices — with hostname, IP, and vendor and device details where available. Devices report clearer, better-quality names, over UPnP and over Bonjour — a friendly name now wins over a machine-generated one wherever both are broadcast.
NetScanPro doesn't just list IP addresses. It resolves device names, types, and manufacturers from what each device broadcasts over Bonjour and UPnP, and labels every result with a confidence level, so you can tell a confirmed identification from a best guess. Where a hardware address can be determined, it's shown with the manufacturer it belongs to, and each row says where the address came from — derived from the device's IPv6 link-local address, or read from what the device advertises. Neither route works for every device, so many rows carry no address at all, and a manufacturer is as far as it goes: the maker of the hardware, never an identification of the device itself. When one does turn up, it's matched against the complete IEEE manufacturer registry bundled inside the app, offline. The device you're scanning from reports its own hardware model. Devices that share nothing stay honestly unlabeled rather than mislabeled. All of it happens on your phone, with no cloud lookup.
Each Wi-Fi network keeps its own device list and scan history. Create networks manually and pin scans to a specific one, so two sites that look identical (same subnet, same gateway) never merge into one record. Move devices between networks to reorganize your catalog. Field tech or MSP? See how NetScanPro handles multi-site work →
Rename a device and the name stays with that device, even after your router hands its address to different hardware. When NetScanPro can't tell whether a device moved or was replaced, it asks you instead of guessing — and you have two weeks to undo an answer.
Scans 27 common TCP ports per device — including VNC (5900). Every one carries a plain-language explanation of what the service is, and the ones that matter for security — SMB, RDP, RTSP, Telnet, FTP, VNC, UPnP, raw printing, LPD, MQTT, POP3 and IMAP — add a severity-tiered note with a specific action to take, with SSH getting an informational one.
All scanning happens locally on your iPhone. No accounts, no analytics, no tracking, no servers. Your scan history stays on your phone, and the only traffic NetScanPro sends is the UPnP description request it makes directly to a device that answered on your own network — pinned to that device's address, redirects refused, cellular off. Nothing leaves your local network.
Pro unlocks for $9.99, once. No subscriptions, no upsells, no expiration. Pay through Apple, restore on any device signed into your Apple ID.
All scanning happens on your iPhone. NetScanPro never connects to remote servers, because there are no remote servers. The one exception proves the rule: when a device answers a UPnP query, the app fetches that device's own description page directly from it — locked to that device's address on your LAN, redirects refused, cellular disabled. There's no account to create, no email to hand over, no "free trial that requires sign-up."
No analytics SDKs. No crash reporters. No third-party trackers. Face ID locks the app by default — optional in Settings — so even your local scan history stays yours. Payment is handled by Apple — NetScanPro never sees your card details.
Restore Purchase brings your Pro entitlement to any device signed into your Apple ID.
Similar device discovery, but no subscriptions and no servers. Fewer bells and whistles — more privacy. NetScanPro doesn't phone home, doesn't require an account, and unlocks fully for a one-time $9.99. For a full side-by-side, see our comparison of the best private, no-subscription iPhone network scanners. We also compare NetScanPro with Fing point by point on AppMatchup, a site we run.
Yes — any standard home Wi-Fi. NetScanPro is designed for /24 IPv4 subnets and is IPv6-aware. Works on Wi-Fi 5, 6, 6E, and 7 routers from any vendor.
Yes. Each network keeps its own separate device list and scan history. You can create networks manually and pin a scan to a specific one, so two sites that share the same subnet and gateway stay separate instead of merging. Pro adds a PDF report per network you can hand off. And because nothing leaves your local network, scanning a client network doesn't send their data anywhere.
iOS requires that permission for any app that scans the local network. It's the same prompt Sonos, Hue, and AirPlay apps trigger. Explained in the App Store privacy disclosure.
Yes. NetScanPro browses for Matter devices specifically, alongside HomeKit, Hue and other smart-home services on standard mDNS, and identifies them by name, type, and manufacturer where they share enough to go on. Some legacy proprietary devices don't broadcast on standard mDNS at all — those may appear unlabeled rather than guessed at.
During a scan, NetScanPro reads the clues a device gives off: the name and services it broadcasts over Bonjour and UPnP, matched to a device type and manufacturer on the phone, with no cloud lookup. A hardware address can be determined for some devices too — either derived from the device's IPv6 link-local address or read from what the device advertises, and each row says which — then matched against the complete IEEE manufacturer registry bundled offline in the app. Some entries in that registry are administrative placeholders rather than manufacturers — blocks held by the IEEE Registration Authority itself, or marked private — and those are left unnamed instead of being shown as the maker. Neither route covers every device, and what it yields is the manufacturer, not the device. Each result gets a confidence level so a confirmed match reads differently from a best guess. A device that broadcasts nothing identifiable, common with privacy-focused phones and some smart-home gear, may stay unlabeled, which is honest rather than a wrong guess.
Where the device has a web port open, yes. After a port scan, the Security Summary shows a Web Interfaces list covering every device answering on 443, 8443, 80 or 8080, and tapping one opens it in Safari. The same button appears on that device's detail screen, with the full URL shown before you tap it. What loads is up to the device: a router login, a control panel, an error, or nothing useful.
No. There's nothing to sell. No scan history, no device list, no analytics — nothing leaves your local network. There's no server to leak from because there's no server.
Tap "Restore Purchase" inside NetScanPro on the new device. Your Pro entitlement follows your Apple ID, so any iPhone signed into the same account unlocks Pro automatically.
The name you gave a device stays with that device, not with the address. If NetScanPro can't tell whether a device moved to a new address or a different device took the old one, it asks you rather than guessing — and a confirmed answer can be undone for two weeks if you got it wrong.
Free to try with unlimited device discovery. Unlock Pro for $9.99 — once, never again.