Best Security Scanning tools by public signals

These picks are computed from scored public evidence. Use the openness column in the ranking to separate OSI-approved, source-available, open-core, proprietary, and unverified-license tools.

Use Case Rankings

Ordered by ToolVitals score, health, shipping, confidence, and then adoption as a tie-breaker.

#ToolHealthShippingOpennessStarsScoreStatus
01CNSpec
Cloud-native security platform for protecting build and runtime environments.
93100License unknown43897Active
02DefectDojo
Open-Source Unified Vulnerability Management, DevSecOps & ASPM
93100OSI-approved OSS4.9k97Active
03Snyk
Developer-first security platform
9195OSI-approved OSS5.6k95Active
04Kubescape
Kubescape is an open-source Kubernetes security platform for your IDE, CI/CD pipelines, and clusters. It includes risk analysis, security, compliance, and misconfiguration scanning, saving Kubernetes users and administrators precious time, effort, and resources.
9395OSI-approved OSS11.6k94Active
05Prosopo CAPTCHA
Privacy-focused CAPTCHA and bot defense platform.
9095OSI-approved OSS29794Active
06Faraday
Open Source Vulnerability Management Platform
8190OSI-approved OSS6.7k89Active
07FoxGuard
Security scanner as fast as a linter with TUI triage.
7890OSI-approved OSS27988Active
08Trivy
Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more
8775OSI-approved OSS37.1k85Active
09OpenA2A
Open-source security tools for AI agents.
7776OSI-approved OSS2083Active
10Web-Check
🕵️‍♂️ All-in-one OSINT tool for analysing any website
8461OSI-approved OSS34.3k78Active
11Copacetic
🧵 CLI tool for directly patching container images!
8553OSI-approved OSS1.7k77Warning
12Steampipe
Zero-ETL, infinite possibilities. Live query APIs, code & more with SQL. No DB required.
7648OSI-approved OSS7.9k73Warning
13OpenAnt
Open-source LLM-based vulnerability discovery product for defenders.
6861OSI-approved OSS69971Warning
14Lynis
Lynis - Security auditing tool for Linux, macOS, and UNIX-based systems. Assists with compliance testing (HIPAA/ISO27001/PCI DSS) and system hardening. Agentless, and installation optional.
7342OSI-approved OSS16.1k69Warning
15vulnerability-spoiler-alert
A monitoring hub that watches popular open-source repositories and uses AI to detect when commits ar
6263OSI-approved OSS14568Warning
16Nettacker
Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management
7438OSI-approved OSS5.5k67Warning
17Caido
🚀 Caido releases, wiki and roadmap
7036License unknown2.5k67Warning
18powerpipe
Powerpipe: Dashboards for DevOps. Visualize cloud configurations. Assess security posture against a massive library of benchmarks. Build custom dashboards with code.
6742OSI-approved OSS51567Warning
19Dokuru
Agent-based Docker security audit platform with CIS benchmark compliance and remediation.
5960OSI-approved OSS867Warning
20ExtensionShield
Chrome extension risk scanner — scan Chrome Web Store links or CRX/ZIP builds and generate evidence-based security/privacy reports. Open-core.
5849OSI-approved OSS9664Warning
21Secutils
Open source security toolbox for engineers and researchers.
5744OSI-approved OSS10162Warning
22Gitleaks
Find secrets with Gitleaks 🔑
6528OSI-approved OSS28.4k61Warning
23Redlyne
Detect and patch vulnerabilities in AI-generated Python code.
6330OSI-approved OSS4060Warning
24SecScore
Security scoring engine for CI/CD pipelines.
5434License unknown858Warning
25CloudRec
CloudRec is an open source multi-cloud security posture management (CSPM) platform designed to help organizations improve the security of their cloud environments.
5127OSI-approved OSS18954Warning
26Deepfence ThreatMapper
Open source cloud native application protection platform.
4410OSI-approved OSS5.3k45Critical
27VMC
Open source vulnerability management platform.
4111OSI-approved OSS9341Critical
28Lodestar Forge
Open-source infrastructure management platform crafted for red team engagements.
410OSI-approved OSS10938Critical
29Atlas CSMP
Open-source cloud security posture management tool for AWS infrastructure.
280License unknown134Critical
30RFSec-ToolKit
RFSec-ToolKit is a collection of Radio Frequency Communication Protocol Hacktools.无线通信协议相关的工具集,可借助SDR硬件+相关工具对无线通信进行研究。Collect with ♥ by HackSmith
310License unknown1.7k33Critical
31OSINT UI
Professional open source intelligence platform.
260License unknown2333Critical
32CodeAnalysis
Static code analysis platform.
320OSI-approved OSS1.8k32Critical
33NodeJSSCAN
Static security scanner for Node.js applications.
310OSI-approved OSS2.6k32Critical
34OpenClarity
Open-source platform for cloud-native security and observability.
260OSI-approved OSS1.5k31Critical
35AgentFence
Open-source platform for testing AI agent security.
260OSI-approved OSS5928Critical

Evidence Watch

Tracked tools with useful public signals but no verdict score yet.

Agentic Radar

Security scanner for LLM agent workflows.

97 confidence

Akto

Open-source API security platform for discovery, posture, and CI/CD testing.

100 confidence

Dalfox

🌙🦊 Dalfox is a powerful open-source XSS scanner and utility focused on automation.

90 confidence

lopper

measure dependency waste and attack surface before it ships

82 confidence

LunaTrace

Dependency vulnerability scanner and SBOM inventory.

73 confidence

MegaLinter

🦙 MegaLinter analyzes 50 languages, 22 formats, 21 tooling formats, excessive copy-pastes, spelling mistakes and security issues in your repository sources with a GitHub Action, other CI tools or locally.

94 confidence

Metlo

Metlo is an open-source API security platform.

76 confidence

Mixeway

Repository containing source code of MixewayFlow service that is Swiss army knife for DevSecOps Teams

72 confidence

Nuclei

Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.

100 confidence

OSV.dev

Open source vulnerability DB and triage service.

99 confidence

OWASP Noir

Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.

98 confidence

PayloadsAllTheThings

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

86 confidence

Pentagi

Fully autonomous AI Agents system capable of performing complex penetration testing tasks

89 confidence

Pentest AI

Autonomous pentesting AI with MCP server and Python agents.

98 confidence

Presidio

An open-source framework for detecting, redacting, masking, and anonymizing sensitive data (PII) across text, images, and structured data. Supports NLP, pattern matching, and customizable pipelines.

100 confidence

Prowler

Prowler is the world’s most widely used open-source cloud security platform that automates security and compliance across any cloud environment.

100 confidence

sqlmap

Automatic SQL injection and database takeover tool

98 confidence

Strix

Open-source AI hackers to find and fix your app’s vulnerabilities.

98 confidence

Xingrin

Open-source attack surface management and authorized security automation platform for asset discovery, service probing, scan orchestration, and security result management.

71 confidence