Security & Compliance
Security Scanning
Vulnerability scanning, SAST, dependency scanning, and security testing.
Best Security Scanning tools by public signals
These picks are computed from scored public evidence. Use the openness column in the ranking to separate OSI-approved, source-available, open-core, proprietary, and unverified-license tools.
Use Case Rankings
Ordered by ToolVitals score, health, shipping, confidence, and then adoption as a tie-breaker.
| # | Tool | Health | Shipping | Openness | Stars | Score | Status |
|---|---|---|---|---|---|---|---|
| 01 | CNSpec Cloud-native security platform for protecting build and runtime environments. | 93 | 100 | License unknown | 438 | 97 | Active |
| 02 | DefectDojo Open-Source Unified Vulnerability Management, DevSecOps & ASPM | 93 | 100 | OSI-approved OSS | 4.9k | 97 | Active |
| 03 | Snyk Developer-first security platform | 91 | 95 | OSI-approved OSS | 5.6k | 95 | Active |
| 04 | Kubescape Kubescape is an open-source Kubernetes security platform for your IDE, CI/CD pipelines, and clusters. It includes risk analysis, security, compliance, and misconfiguration scanning, saving Kubernetes users and administrators precious time, effort, and resources. | 93 | 95 | OSI-approved OSS | 11.6k | 94 | Active |
| 05 | Prosopo CAPTCHA Privacy-focused CAPTCHA and bot defense platform. | 90 | 95 | OSI-approved OSS | 297 | 94 | Active |
| 06 | Faraday Open Source Vulnerability Management Platform | 81 | 90 | OSI-approved OSS | 6.7k | 89 | Active |
| 07 | FoxGuard Security scanner as fast as a linter with TUI triage. | 78 | 90 | OSI-approved OSS | 279 | 88 | Active |
| 08 | Trivy Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more | 87 | 75 | OSI-approved OSS | 37.1k | 85 | Active |
| 09 | OpenA2A Open-source security tools for AI agents. | 77 | 76 | OSI-approved OSS | 20 | 83 | Active |
| 10 | Web-Check 🕵️♂️ All-in-one OSINT tool for analysing any website | 84 | 61 | OSI-approved OSS | 34.3k | 78 | Active |
| 11 | Copacetic 🧵 CLI tool for directly patching container images! | 85 | 53 | OSI-approved OSS | 1.7k | 77 | Warning |
| 12 | Steampipe Zero-ETL, infinite possibilities. Live query APIs, code & more with SQL. No DB required. | 76 | 48 | OSI-approved OSS | 7.9k | 73 | Warning |
| 13 | OpenAnt Open-source LLM-based vulnerability discovery product for defenders. | 68 | 61 | OSI-approved OSS | 699 | 71 | Warning |
| 14 | Lynis Lynis - Security auditing tool for Linux, macOS, and UNIX-based systems. Assists with compliance testing (HIPAA/ISO27001/PCI DSS) and system hardening. Agentless, and installation optional. | 73 | 42 | OSI-approved OSS | 16.1k | 69 | Warning |
| 15 | vulnerability-spoiler-alert A monitoring hub that watches popular open-source repositories and uses AI to detect when commits ar | 62 | 63 | OSI-approved OSS | 145 | 68 | Warning |
| 16 | Nettacker Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management | 74 | 38 | OSI-approved OSS | 5.5k | 67 | Warning |
| 17 | Caido 🚀 Caido releases, wiki and roadmap | 70 | 36 | License unknown | 2.5k | 67 | Warning |
| 18 | powerpipe Powerpipe: Dashboards for DevOps. Visualize cloud configurations. Assess security posture against a massive library of benchmarks. Build custom dashboards with code. | 67 | 42 | OSI-approved OSS | 515 | 67 | Warning |
| 19 | Dokuru Agent-based Docker security audit platform with CIS benchmark compliance and remediation. | 59 | 60 | OSI-approved OSS | 8 | 67 | Warning |
| 20 | ExtensionShield Chrome extension risk scanner — scan Chrome Web Store links or CRX/ZIP builds and generate evidence-based security/privacy reports. Open-core. | 58 | 49 | OSI-approved OSS | 96 | 64 | Warning |
| 21 | Secutils Open source security toolbox for engineers and researchers. | 57 | 44 | OSI-approved OSS | 101 | 62 | Warning |
| 22 | Gitleaks Find secrets with Gitleaks 🔑 | 65 | 28 | OSI-approved OSS | 28.4k | 61 | Warning |
| 23 | Redlyne Detect and patch vulnerabilities in AI-generated Python code. | 63 | 30 | OSI-approved OSS | 40 | 60 | Warning |
| 24 | SecScore Security scoring engine for CI/CD pipelines. | 54 | 34 | License unknown | 8 | 58 | Warning |
| 25 | CloudRec CloudRec is an open source multi-cloud security posture management (CSPM) platform designed to help organizations improve the security of their cloud environments. | 51 | 27 | OSI-approved OSS | 189 | 54 | Warning |
| 26 | Deepfence ThreatMapper Open source cloud native application protection platform. | 44 | 10 | OSI-approved OSS | 5.3k | 45 | Critical |
| 27 | VMC Open source vulnerability management platform. | 41 | 11 | OSI-approved OSS | 93 | 41 | Critical |
| 28 | Lodestar Forge Open-source infrastructure management platform crafted for red team engagements. | 41 | 0 | OSI-approved OSS | 109 | 38 | Critical |
| 29 | Atlas CSMP Open-source cloud security posture management tool for AWS infrastructure. | 28 | 0 | License unknown | 1 | 34 | Critical |
| 30 | RFSec-ToolKit RFSec-ToolKit is a collection of Radio Frequency Communication Protocol Hacktools.无线通信协议相关的工具集,可借助SDR硬件+相关工具对无线通信进行研究。Collect with ♥ by HackSmith | 31 | 0 | License unknown | 1.7k | 33 | Critical |
| 31 | OSINT UI Professional open source intelligence platform. | 26 | 0 | License unknown | 23 | 33 | Critical |
| 32 | CodeAnalysis Static code analysis platform. | 32 | 0 | OSI-approved OSS | 1.8k | 32 | Critical |
| 33 | NodeJSSCAN Static security scanner for Node.js applications. | 31 | 0 | OSI-approved OSS | 2.6k | 32 | Critical |
| 34 | OpenClarity Open-source platform for cloud-native security and observability. | 26 | 0 | OSI-approved OSS | 1.5k | 31 | Critical |
| 35 | AgentFence Open-source platform for testing AI agent security. | 26 | 0 | OSI-approved OSS | 59 | 28 | Critical |
Evidence Watch
Tracked tools with useful public signals but no verdict score yet.
Agentic Radar
Security scanner for LLM agent workflows.
97 confidenceAkto
Open-source API security platform for discovery, posture, and CI/CD testing.
100 confidenceDalfox
🌙🦊 Dalfox is a powerful open-source XSS scanner and utility focused on automation.
90 confidencelopper
measure dependency waste and attack surface before it ships
82 confidenceLunaTrace
Dependency vulnerability scanner and SBOM inventory.
73 confidenceMegaLinter
🦙 MegaLinter analyzes 50 languages, 22 formats, 21 tooling formats, excessive copy-pastes, spelling mistakes and security issues in your repository sources with a GitHub Action, other CI tools or locally.
94 confidenceMetlo
Metlo is an open-source API security platform.
76 confidenceMixeway
Repository containing source code of MixewayFlow service that is Swiss army knife for DevSecOps Teams
72 confidenceNuclei
Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.
100 confidenceOSV.dev
Open source vulnerability DB and triage service.
99 confidenceOWASP Noir
Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.
98 confidencePayloadsAllTheThings
A list of useful payloads and bypass for Web Application Security and Pentest/CTF
86 confidencePentagi
Fully autonomous AI Agents system capable of performing complex penetration testing tasks
89 confidencePentest AI
Autonomous pentesting AI with MCP server and Python agents.
98 confidencePresidio
An open-source framework for detecting, redacting, masking, and anonymizing sensitive data (PII) across text, images, and structured data. Supports NLP, pattern matching, and customizable pipelines.
100 confidenceProwler
Prowler is the world’s most widely used open-source cloud security platform that automates security and compliance across any cloud environment.
100 confidencesqlmap
Automatic SQL injection and database takeover tool
98 confidenceStrix
Open-source AI hackers to find and fix your app’s vulnerabilities.
98 confidenceXingrin
Open-source attack surface management and authorized security automation platform for asset discovery, service probing, scan orchestration, and security result management.
71 confidence