Best Security Scanning tools by public signals

These picks are computed from scored public evidence. Use the openness column in the ranking to separate OSI-approved, source-available, open-core, proprietary, and unverified-license tools.

Use Case Rankings

Ordered by ToolVitals score, then health, shipping, confidence, GitHub stars, and name.

#ToolHealthShippingOpennessStarsScoreStatus
01Akto
Open-source API security platform for discovery, posture, and CI/CD testing.
9898OSI-approved OSS1.5k98Active
02Kubescape
Kubescape is an open-source Kubernetes security platform for your IDE, CI/CD pipelines, and clusters. It includes risk analysis, security, compliance, and misconfiguration scanning, saving Kubernetes users and administrators precious time, effort, and resources.
9897OSI-approved OSS11.7k98Active
03DefectDojo
Open-Source Unified Vulnerability Management, DevSecOps & ASPM
9897OSI-approved OSS4.9k98Active
04Snyk
Developer-first security platform
9897OSI-approved OSS5.7k97Active
05Prowler
Prowler is the world’s most widely used open-source cloud security platform that automates security and compliance across any cloud environment.
9797OSI-approved OSS14.8k97Active
06MegaLinter
🦙 MegaLinter analyzes 50 languages, 22 formats, 21 tooling formats, excessive copy-pastes, spelling mistakes and security issues in your repository sources with a GitHub Action, other CI tools or locally.
9797OSI-approved OSS2.6k97Active
07OWASP Noir
Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.
9797OSI-approved OSS1.4k97Active
08Strix
Open-source AI hackers to find and fix your app’s vulnerabilities.
9796OSI-approved OSS62.1k97Active
09OSV.dev
Open source vulnerability DB and triage service.
9796OSI-approved OSS2.9k97Active
10Dalfox
🌙🦊 Dalfox is a powerful open-source XSS scanner and utility focused on automation.
9796OSI-approved OSS5.3k96Active
11Nuclei
Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.
9695OSI-approved OSS31.2k96Active
12Prosopo CAPTCHA
Privacy-focused CAPTCHA and bot defense platform.
9596OSI-approved OSS29996Active
13Trivy
Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more
9694OSI-approved OSS37.9k95Active
14lopper
measure dependency waste and attack surface before it ships
9395OSI-approved OSS293Active
15FoxGuard
Security scanner as fast as a linter with TUI triage.
9291OSI-approved OSS29492Active
16Faraday
Open Source Vulnerability Management Platform
9193OSI-approved OSS6.7k92Active
17OpenA2A
Open-source security tools for AI agents.
9191OSI-approved OSS2091Active
18sqlmap
Automatic SQL injection and database takeover tool
8993OSI-approved OSS38.4k91Active
19Copacetic
🧵 CLI tool for directly patching container images!
9186OSI-approved OSS1.7k89Active
20OpenAnt
Open-source LLM-based vulnerability discovery product for defenders.
8985OSI-approved OSS74887Active
21powerpipe
Powerpipe: Dashboards for DevOps. Visualize cloud configurations. Assess security posture against a massive library of benchmarks. Build custom dashboards with code.
8885OSI-approved OSS52287Active
22Nettacker
Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management
8982OSI-approved OSS5.6k86Active
23Pentest AI
Autonomous pentesting AI with MCP server and Python agents.
8488OSI-approved OSS1.7k86Active
24Presidio
An open-source framework for detecting, redacting, masking, and anonymizing sensitive data (PII) across text, images, and structured data. Supports NLP, pattern matching, and customizable pipelines.
8776OSI-approved OSS10.9k83Active
25Web-Check
🕵️‍♂️ All-in-one OSINT tool for analysing any website
8679OSI-approved OSS34.8k83Active
26vulnerability-spoiler-alert
A monitoring hub that watches popular open-source repositories and uses AI to detect when commits ar
8085OSI-approved OSS16082Active
27Lynis
Lynis - Security auditing tool for Linux, macOS, and UNIX-based systems. Assists with compliance testing (HIPAA/ISO27001/PCI DSS) and system hardening. Agentless, and installation optional.
8070OSI-approved OSS16.3k76Active
28Steampipe
Zero-ETL, infinite possibilities. Live query APIs, code & more with SQL. No DB required.
7867OSI-approved OSS8k73Active
29PayloadsAllTheThings
A list of useful payloads and bypass for Web Application Security and Pentest/CTF
6954OSI-approved OSS80.9k63Warning
30Pentagi
Fully autonomous AI Agents system capable of performing complex penetration testing tasks
6944OSI-approved OSS24.4k59Warning
31Xingrin
Open-source attack surface management and authorized security automation platform for asset discovery, service probing, scan orchestration, and security result management.
5938OSI-approved OSS65950Warning
32ExtensionShield
Chrome extension risk scanner — scan Chrome Web Store links or CRX/ZIP builds and generate evidence-based security/privacy reports. Open-core.
5739OSI-approved OSS10350Warning
33Gitleaks
Find secrets with Gitleaks 🔑
5324OSI-approved OSS29.3k41Warning
34Dokuru
Agent-based Docker security audit platform with CIS benchmark compliance and remediation.
4428OSI-approved OSS838Critical
35AgentFence
Open-source platform for testing AI agent security.
3713OSI-approved OSS6128Critical
36Redlyne
Detect and patch vulnerabilities in AI-generated Python code.
3515OSI-approved OSS3927Critical
37Lodestar Forge
Open-source infrastructure management platform crafted for red team engagements.
230OSI-approved OSS10914Critical
38CloudRec
CloudRec is an open source multi-cloud security posture management (CSPM) platform designed to help organizations improve the security of their cloud environments.
205OSI-approved OSS19214Critical
39Deepfence ThreatMapper
Open source cloud native application protection platform.
172OSI-approved OSS5.3k11Critical

Not Scored

Tracked for context, but excluded from rankings because comparable open/source-visible evidence is unavailable.

Atlas CSMP

Open-source cloud security posture management tool for AWS infrastructure.

ToolVitals does not score proprietary or unknown-license tools because their public source evidence is not comparable to open/source-visible projects.

Caido

🚀 Caido releases, wiki and roadmap

ToolVitals does not score proprietary or unknown-license tools because their public source evidence is not comparable to open/source-visible projects.

CNSpec

Cloud-native security platform for protecting build and runtime environments.

ToolVitals does not score proprietary or unknown-license tools because their public source evidence is not comparable to open/source-visible projects.

LunaTrace

Dependency vulnerability scanner and SBOM inventory.

ToolVitals does not score proprietary or unknown-license tools because their public source evidence is not comparable to open/source-visible projects.

Mixeway

Repository containing source code of MixewayFlow service that is Swiss army knife for DevSecOps Teams

ToolVitals does not score proprietary or unknown-license tools because their public source evidence is not comparable to open/source-visible projects.

OSINT UI

Professional open source intelligence platform.

ToolVitals does not score proprietary or unknown-license tools because their public source evidence is not comparable to open/source-visible projects.

RFSec-ToolKit

RFSec-ToolKit is a collection of Radio Frequency Communication Protocol Hacktools.无线通信协议相关的工具集,可借助SDR硬件+相关工具对无线通信进行研究。Collect with ♥ by HackSmith

ToolVitals does not score proprietary or unknown-license tools because their public source evidence is not comparable to open/source-visible projects.

SecScore

Security scoring engine for CI/CD pipelines.

ToolVitals does not score proprietary or unknown-license tools because their public source evidence is not comparable to open/source-visible projects.