Security scanning teams have to sort through tools that cover different jobs: vulnerability management, template-based scanning, endpoint discovery, container and cloud checks, API security, and supporting reference material. The ToolVitals data for July 2026 compares open/source-visible Security Scanning Tools using health score, shipping score, ToolVitals score, GitHub stars, licensing, and openness labels from the supplied ranked dataset.
This ranking includes open/source-visible tools only and orders them by ToolVitals score first, with GitHub stars used only as a secondary popularity signal for ties. The list is entirely OSI-approved OSS in this dataset, with license labels such as BSD-3-Clause, MIT, Apache-2.0, AGPL-3.0, and GPL-2.0 shown as supplied.
Rankings
| Rank | Tool | Openness | License | Health | Shipping | GitHub Stars | Score | Status |
|---|---|---|---|---|---|---|---|---|
| 1 | DefectDojo | OSI-approved OSS | BSD-3-Clause | 93 | 100 | 4815 | 97 | 🟢 Excellent |
| 2 | Nuclei | OSI-approved OSS | MIT | 92 | 78 | 29575 | 90 | 🟢 Excellent |
| 3 | OWASP Noir | OSI-approved OSS | MIT | 85 | 87 | 1349 | 89 | 🟢 Excellent |
| 4 | Trivy | OSI-approved OSS | Apache-2.0 | 89 | 78 | 36853 | 87 | 🟢 Excellent |
| 5 | Pentest AI | OSI-approved OSS | MIT | 86 | 81 | 1263 | 87 | 🟢 Excellent |
| 6 | OSV.dev | OSI-approved OSS | Apache-2.0 | 83 | 76 | 2802 | 85 | 🟢 Excellent |
| 7 | Copacetic | OSI-approved OSS | Apache-2.0 | 89 | 70 | 1672 | 84 | 🟢 Excellent |
| 8 | MegaLinter | OSI-approved OSS | AGPL-3.0 | 78 | 81 | 2526 | 83 | 🟢 Excellent |
| 9 | sqlmap | OSI-approved OSS | GPL-2.0 | 73 | 66 | 37848 | 76 | 🟢 Good |
| 10 | CloudRec | OSI-approved OSS | Apache-2.0 | 60 | 36 | 187 | 61 | 🟢 Good |
| 11 | PayloadsAllTheThings | OSI-approved OSS | MIT | 62 | 28 | 79038 | 59 | 🟡 Fair |
| 12 | VMC | OSI-approved OSS | Apache-2.0 | 36 | 11 | 93 | 39 | 🔴 Needs Attention |
| 13 | Metlo | OSI-approved OSS | MIT | 31 | 0 | 1778 | 31 | 🔴 Needs Attention |
Top 3 Highlights
DefectDojo ranks first with a ToolVitals score of 97, the highest score in the dataset, backed by a 100 shipping score and 93 health score. It is listed as OSI-approved OSS under BSD-3-Clause, has no pricing scope recorded, and has 4,815 GitHub stars. Its description points to unified vulnerability management, DevSecOps, and ASPM, so it stands out less as a single scanner and more as a central place to manage security findings.
Nuclei ranks second with a ToolVitals score of 90 and the strongest GitHub popularity signal among the top three, at 29,575 stars. It is OSI-approved OSS under MIT, with no pricing scope recorded. The supplied description emphasizes fast, customizable vulnerability scanning with a YAML-based DSL across applications, APIs, networks, DNS, and cloud configurations, which makes it one of the broader scanning engines in the ranked set.
OWASP Noir ranks third with a ToolVitals score of 89, a balanced 85 health score and 87 shipping score, and 1,349 GitHub stars. It is OSI-approved OSS under MIT, with no pricing scope recorded. Its focus is narrower than the top two: hunting endpoints in code, exposing shadow APIs, and mapping attack surface, which makes it especially relevant for teams trying to understand API exposure from source code.
Want to see the full details, pricing, and trend data for every tool in Security Scanning? Browse all Security Scanning Tools →