Security scanning covers different problems, from finding exposed APIs and XSS to organizing vulnerability findings, so the right tool depends on the work you need to do. This August 2026 snapshot uses supplied ToolVitals data and tool descriptions to make those differences easier to compare.

The ranking includes open/source-visible tools only. Tools are ordered by ToolVitals score descending, with health and shipping used to order equal composite scores; GitHub stars are context only and do not determine rank.

Rankings

Rank Tool Openness License Health Shipping GitHub Stars Score Status
1 Akto OSI-approved OSS MIT 100 100 1505 100 🟢 Excellent
2 Dalfox OSI-approved OSS MIT 100 100 5255 100 🟢 Excellent
3 DefectDojo OSI-approved OSS BSD-3-Clause 100 100 4908 100 🟢 Excellent
4 Kubescape OSI-approved OSS Apache-2.0 100 100 11687 100 🟢 Excellent
5 MegaLinter OSI-approved OSS AGPL-3.0 100 100 2569 100 🟢 Excellent
6 OSV.dev OSI-approved OSS Apache-2.0 100 100 2899 100 🟢 Excellent
7 OWASP Noir OSI-approved OSS MIT 100 100 1381 100 🟢 Excellent
8 Prowler OSI-approved OSS Apache-2.0 100 100 14675 100 🟢 Excellent
9 Snyk OSI-approved OSS Apache-2.0 100 100 5646 100 🟢 Excellent
10 Strix OSI-approved OSS Apache-2.0 100 100 58110 100 🟢 Excellent
11 Prosopo CAPTCHA OSI-approved OSS Apache-2.0 98 99 298 98 🟢 Excellent
12 Nuclei OSI-approved OSS MIT 98 97 30798 98 🟢 Excellent
13 Trivy OSI-approved OSS Apache-2.0 100 93 37608 97 🟢 Excellent
14 lopper OSI-approved OSS MIT 95 98 2 96 🟢 Excellent
15 FoxGuard OSI-approved OSS MIT 93 90 286 92 🟢 Excellent
16 sqlmap OSI-approved OSS GPL-2.0 89 97 38262 92 🟢 Excellent
17 Pentagi OSI-approved OSS MIT 89 91 22019 90 🟢 Excellent
18 OpenAnt OSI-approved OSS Apache-2.0 91 86 734 89 🟢 Excellent
19 Faraday OSI-approved OSS GPL-3.0 90 88 6694 89 🟢 Excellent
20 OpenA2A OSI-approved OSS Apache-2.0 88 91 19 89 🟢 Excellent
21 Web-Check OSI-approved OSS MIT 91 82 34595 87 🟢 Excellent
22 Presidio OSI-approved OSS MIT 90 83 10622 87 🟢 Excellent
23 vulnerability-spoiler-alert OSI-approved OSS MIT 87 88 156 87 🟢 Excellent
24 Pentest AI OSI-approved OSS MIT 87 84 1627 86 🟢 Excellent
25 Copacetic OSI-approved OSS Apache-2.0 87 77 1700 83 🟢 Excellent
26 powerpipe OSI-approved OSS AGPL-3.0 83 80 520 82 🟢 Excellent
27 Nettacker OSI-approved OSS Apache-2.0 88 70 5532 81 🟢 Excellent
28 Steampipe OSI-approved OSS AGPL-3.0 79 67 7933 74 🟢 Good
29 ExtensionShield OSI-approved OSS MIT 73 69 102 71 🟢 Good
30 PayloadsAllTheThings OSI-approved OSS MIT 66 49 80345 59 🟡 Fair
31 Lynis OSI-approved OSS GPL-3.0 62 47 16230 56 🟡 Fair
32 Dokuru OSI-approved OSS Apache-2.0 58 48 8 54 🟡 Fair
33 Gitleaks OSI-approved OSS MIT 56 27 28942 44 🟡 Fair
34 AgentFence OSI-approved OSS MIT 44 25 61 36 🔴 Needs Attention
35 Redlyne OSI-approved OSS Apache-2.0 33 18 40 27 🔴 Needs Attention
36 Xingrin OSI-approved OSS MIT 33 17 655 27 🔴 Needs Attention
37 CloudRec OSI-approved OSS Apache-2.0 22 12 190 18 🔴 Needs Attention
38 Lodestar Forge OSI-approved OSS GPL-3.0 20 0 109 12 🔴 Needs Attention
39 Deepfence ThreatMapper OSI-approved OSS Apache-2.0 13 2 5318 9 🔴 Needs Attention
40 Agentic Radar OSI-approved OSS Apache-2.0 2 0 1043 1 🔴 Needs Attention
41 CodeAnalysis OSI-approved OSS GPL-2.0 2 0 1842 1 🔴 Needs Attention
42 NodeJSSCAN OSI-approved OSS GPL-3.0 2 0 2570 1 🔴 Needs Attention
43 Metlo OSI-approved OSS MIT 0 0 1783 0 🔴 Needs Attention
44 OpenClarity OSI-approved OSS Apache-2.0 0 0 1460 0 🔴 Needs Attention
45 VMC OSI-approved OSS Apache-2.0 0 0 93 0 🔴 Needs Attention

Top 3 Highlights

Akto ranks first with a ToolVitals score of 100, a health score of 100, and a shipping score of 100. Its supplied description focuses on API discovery, security posture, and CI/CD testing. Akto is labeled OSI-approved OSS and uses the MIT license.

Dalfox ranks second with a ToolVitals score of 100, a health score of 100, and a shipping score of 100. Its supplied description identifies it as an XSS scanner and utility focused on automation. Dalfox is labeled OSI-approved OSS and uses the MIT license.

DefectDojo ranks third with a ToolVitals score of 100, a health score of 100, and a shipping score of 100. Its supplied description presents it as a unified vulnerability management, DevSecOps, and ASPM platform. DefectDojo is labeled OSI-approved OSS and uses the BSD-3-Clause license.

Want to see the full health, license, shipping, and confidence details for every tool in Security Scanning? Browse all Security Scanning Tools →