Security scanning tools cover a wide spread of jobs: cloud compliance, Kubernetes posture, secrets detection, vulnerability discovery, API security, and network access controls. This June 2026 view uses the supplied ToolVitals dataset, including health score, shipping score, ToolVitals score, GitHub stars, openness_label, license_label, pricing scope, and status for each ranked tool.

The ranking includes open/source-visible tools only and is ordered by ToolVitals score first, with GitHub stars used as the secondary popularity signal when scores are close. Labels are kept literal: tools marked OSI-approved OSS are described that way, and each license_label is stated as supplied rather than broadened into a generic open-source claim.

Rankings

RankToolOpennessLicenseHealthShippingGitHub StarsScoreStatus
1NetBirdOSI-approved OSSAGPL-3.010010025806100🟢 Excellent
2ProwlerOSI-approved OSSApache-2.010010013955100🟢 Excellent
3SnykOSI-approved OSSApache-2.09394557395🟢 Excellent
4KubescapeOSI-approved OSSApache-2.093951147094🟢 Excellent
5StrixOSI-approved OSSApache-2.092782587589🟢 Excellent
6TrivyOSI-approved OSSApache-2.085783617885🟢 Excellent
7GravitlOSI-approved OSSApache-2.077651160579🟢 Good
8GitleaksOSI-approved OSSMIT72452760270🟢 Good
9SecutilsOSI-approved OSSAGPL-3.0626310070🟢 Good
10vulnerability-spoiler-alertOSI-approved OSSMIT646313969🟢 Good
11RedlyneOSI-approved OSSApache-2.058493764🟢 Good
12Deepfence ThreatMapperOSI-approved OSSApache-2.06316527756🟡 Fair
13OpenClarityOSI-approved OSSApache-2.0510146142🟡 Fair
14MatanoOSI-approved OSSApache-2.0270167633🔴 Needs Attention
15MetloOSI-approved OSSMIT310177831🔴 Needs Attention

Top 3 Highlights

NetBird ranks first with a ToolVitals score of 100, health score of 100, and shipping score of 100. It is listed as OSI-approved OSS under AGPL-3.0, has pricing_scope none, and has 25,806 GitHub stars. Its description positions it as a zero-configuration mesh VPN for business, so it stands out in this security scanning set as a high-scoring network security option rather than a narrow vulnerability scanner.

Prowler also scores 100 across ToolVitals score, health score, and shipping score, but ranks second behind NetBird on the GitHub star tie-breaker with 13,955 stars. It is OSI-approved OSS under Apache-2.0 with pricing_scope none. The supplied description is broad for cloud security: it automates security and compliance across cloud environments.

Snyk ranks third with a ToolVitals score of 95, health score of 93, and shipping score of 94. It is listed as OSI-approved OSS under Apache-2.0, but its pricing_scope is hosted_cloud, which separates it from the no-pricing-scope tools above it. Its dataset description is concise: a developer-first security platform.

Want to see the full details, pricing, and trend data for every tool in Security Scanning? Browse all Security Scanning Tools →