Security & Compliance
Security Scanning
Vulnerability scanning, SAST, dependency scanning, and security testing.
Best Security Scanning tools by public signals
These picks are computed from scored public evidence. Use the openness column in the ranking to separate OSI-approved, source-available, open-core, proprietary, and unverified-license tools.
Use Case Rankings
Ordered by ToolVitals score, then health, shipping, confidence, GitHub stars, and name.
| # | Tool | Health | Shipping | Openness | Stars | Score | Status |
|---|---|---|---|---|---|---|---|
| 01 | Akto Open-source API security platform for discovery, posture, and CI/CD testing. | 98 | 98 | OSI-approved OSS | 1.5k | 98 | Active |
| 02 | Kubescape Kubescape is an open-source Kubernetes security platform for your IDE, CI/CD pipelines, and clusters. It includes risk analysis, security, compliance, and misconfiguration scanning, saving Kubernetes users and administrators precious time, effort, and resources. | 98 | 97 | OSI-approved OSS | 11.7k | 98 | Active |
| 03 | DefectDojo Open-Source Unified Vulnerability Management, DevSecOps & ASPM | 98 | 97 | OSI-approved OSS | 4.9k | 98 | Active |
| 04 | Snyk Developer-first security platform | 98 | 97 | OSI-approved OSS | 5.7k | 97 | Active |
| 05 | Prowler Prowler is the world’s most widely used open-source cloud security platform that automates security and compliance across any cloud environment. | 97 | 97 | OSI-approved OSS | 14.8k | 97 | Active |
| 06 | MegaLinter 🦙 MegaLinter analyzes 50 languages, 22 formats, 21 tooling formats, excessive copy-pastes, spelling mistakes and security issues in your repository sources with a GitHub Action, other CI tools or locally. | 97 | 97 | OSI-approved OSS | 2.6k | 97 | Active |
| 07 | OWASP Noir Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface. | 97 | 97 | OSI-approved OSS | 1.4k | 97 | Active |
| 08 | Strix Open-source AI hackers to find and fix your app’s vulnerabilities. | 97 | 96 | OSI-approved OSS | 62.1k | 97 | Active |
| 09 | OSV.dev Open source vulnerability DB and triage service. | 97 | 96 | OSI-approved OSS | 2.9k | 97 | Active |
| 10 | Dalfox 🌙🦊 Dalfox is a powerful open-source XSS scanner and utility focused on automation. | 97 | 96 | OSI-approved OSS | 5.3k | 96 | Active |
| 11 | Nuclei Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations. | 96 | 95 | OSI-approved OSS | 31.2k | 96 | Active |
| 12 | Prosopo CAPTCHA Privacy-focused CAPTCHA and bot defense platform. | 95 | 96 | OSI-approved OSS | 299 | 96 | Active |
| 13 | Trivy Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more | 96 | 94 | OSI-approved OSS | 37.9k | 95 | Active |
| 14 | lopper measure dependency waste and attack surface before it ships | 93 | 95 | OSI-approved OSS | 2 | 93 | Active |
| 15 | FoxGuard Security scanner as fast as a linter with TUI triage. | 92 | 91 | OSI-approved OSS | 294 | 92 | Active |
| 16 | Faraday Open Source Vulnerability Management Platform | 91 | 93 | OSI-approved OSS | 6.7k | 92 | Active |
| 17 | OpenA2A Open-source security tools for AI agents. | 91 | 91 | OSI-approved OSS | 20 | 91 | Active |
| 18 | sqlmap Automatic SQL injection and database takeover tool | 89 | 93 | OSI-approved OSS | 38.4k | 91 | Active |
| 19 | Copacetic 🧵 CLI tool for directly patching container images! | 91 | 86 | OSI-approved OSS | 1.7k | 89 | Active |
| 20 | OpenAnt Open-source LLM-based vulnerability discovery product for defenders. | 89 | 85 | OSI-approved OSS | 748 | 87 | Active |
| 21 | powerpipe Powerpipe: Dashboards for DevOps. Visualize cloud configurations. Assess security posture against a massive library of benchmarks. Build custom dashboards with code. | 88 | 85 | OSI-approved OSS | 522 | 87 | Active |
| 22 | Nettacker Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management | 89 | 82 | OSI-approved OSS | 5.6k | 86 | Active |
| 23 | Pentest AI Autonomous pentesting AI with MCP server and Python agents. | 84 | 88 | OSI-approved OSS | 1.7k | 86 | Active |
| 24 | Presidio An open-source framework for detecting, redacting, masking, and anonymizing sensitive data (PII) across text, images, and structured data. Supports NLP, pattern matching, and customizable pipelines. | 87 | 76 | OSI-approved OSS | 10.9k | 83 | Active |
| 25 | Web-Check 🕵️♂️ All-in-one OSINT tool for analysing any website | 86 | 79 | OSI-approved OSS | 34.8k | 83 | Active |
| 26 | vulnerability-spoiler-alert A monitoring hub that watches popular open-source repositories and uses AI to detect when commits ar | 80 | 85 | OSI-approved OSS | 160 | 82 | Active |
| 27 | Lynis Lynis - Security auditing tool for Linux, macOS, and UNIX-based systems. Assists with compliance testing (HIPAA/ISO27001/PCI DSS) and system hardening. Agentless, and installation optional. | 80 | 70 | OSI-approved OSS | 16.3k | 76 | Active |
| 28 | Steampipe Zero-ETL, infinite possibilities. Live query APIs, code & more with SQL. No DB required. | 78 | 67 | OSI-approved OSS | 8k | 73 | Active |
| 29 | PayloadsAllTheThings A list of useful payloads and bypass for Web Application Security and Pentest/CTF | 69 | 54 | OSI-approved OSS | 80.9k | 63 | Warning |
| 30 | Pentagi Fully autonomous AI Agents system capable of performing complex penetration testing tasks | 69 | 44 | OSI-approved OSS | 24.4k | 59 | Warning |
| 31 | Xingrin Open-source attack surface management and authorized security automation platform for asset discovery, service probing, scan orchestration, and security result management. | 59 | 38 | OSI-approved OSS | 659 | 50 | Warning |
| 32 | ExtensionShield Chrome extension risk scanner — scan Chrome Web Store links or CRX/ZIP builds and generate evidence-based security/privacy reports. Open-core. | 57 | 39 | OSI-approved OSS | 103 | 50 | Warning |
| 33 | Gitleaks Find secrets with Gitleaks 🔑 | 53 | 24 | OSI-approved OSS | 29.3k | 41 | Warning |
| 34 | Dokuru Agent-based Docker security audit platform with CIS benchmark compliance and remediation. | 44 | 28 | OSI-approved OSS | 8 | 38 | Critical |
| 35 | AgentFence Open-source platform for testing AI agent security. | 37 | 13 | OSI-approved OSS | 61 | 28 | Critical |
| 36 | Redlyne Detect and patch vulnerabilities in AI-generated Python code. | 35 | 15 | OSI-approved OSS | 39 | 27 | Critical |
| 37 | Lodestar Forge Open-source infrastructure management platform crafted for red team engagements. | 23 | 0 | OSI-approved OSS | 109 | 14 | Critical |
| 38 | CloudRec CloudRec is an open source multi-cloud security posture management (CSPM) platform designed to help organizations improve the security of their cloud environments. | 20 | 5 | OSI-approved OSS | 192 | 14 | Critical |
| 39 | Deepfence ThreatMapper Open source cloud native application protection platform. | 17 | 2 | OSI-approved OSS | 5.3k | 11 | Critical |
Not Scored
Tracked for context, but excluded from rankings because comparable open/source-visible evidence is unavailable.
Atlas CSMP
Open-source cloud security posture management tool for AWS infrastructure.
ToolVitals does not score proprietary or unknown-license tools because their public source evidence is not comparable to open/source-visible projects.Caido
🚀 Caido releases, wiki and roadmap
ToolVitals does not score proprietary or unknown-license tools because their public source evidence is not comparable to open/source-visible projects.CNSpec
Cloud-native security platform for protecting build and runtime environments.
ToolVitals does not score proprietary or unknown-license tools because their public source evidence is not comparable to open/source-visible projects.LunaTrace
Dependency vulnerability scanner and SBOM inventory.
ToolVitals does not score proprietary or unknown-license tools because their public source evidence is not comparable to open/source-visible projects.Mixeway
Repository containing source code of MixewayFlow service that is Swiss army knife for DevSecOps Teams
ToolVitals does not score proprietary or unknown-license tools because their public source evidence is not comparable to open/source-visible projects.OSINT UI
Professional open source intelligence platform.
ToolVitals does not score proprietary or unknown-license tools because their public source evidence is not comparable to open/source-visible projects.RFSec-ToolKit
RFSec-ToolKit is a collection of Radio Frequency Communication Protocol Hacktools.无线通信协议相关的工具集,可借助SDR硬件+相关工具对无线通信进行研究。Collect with ♥ by HackSmith
ToolVitals does not score proprietary or unknown-license tools because their public source evidence is not comparable to open/source-visible projects.SecScore
Security scoring engine for CI/CD pipelines.
ToolVitals does not score proprietary or unknown-license tools because their public source evidence is not comparable to open/source-visible projects.