Choosing a security scanning tool is difficult because the category spans API discovery, Kubernetes posture, cloud compliance, code, and vulnerability testing rather than one common workflow. This September 2026 snapshot uses the supplied ToolVitals scores, health signals, shipping signals, descriptions, openness labels, and license labels to make the comparison more concrete.
It ranks open/source-visible tools only by ToolVitals score descending, then by health and shipping for equal composite scores. GitHub stars are context only, not a ranking input, so popularity does not override the ToolVitals ordering.
Rankings
| Rank | Tool | Openness | License | Health | Shipping | GitHub Stars | Score | Status |
|---|---|---|---|---|---|---|---|---|
| 1 | Akto | OSI-approved OSS | MIT | 98 | 98 | 1513 | 98 | 🟢 Excellent |
| 2 | Kubescape | OSI-approved OSS | Apache-2.0 | 98 | 98 | 11723 | 98 | 🟢 Excellent |
| 3 | Prowler | OSI-approved OSS | Apache-2.0 | 98 | 97 | 14770 | 97 | 🟢 Excellent |
| 4 | Snyk | OSI-approved OSS | Apache-2.0 | 98 | 97 | 5657 | 97 | 🟢 Excellent |
| 5 | DefectDojo | OSI-approved OSS | BSD-3-Clause | 97 | 97 | 4930 | 97 | 🟢 Excellent |
| 6 | MegaLinter | OSI-approved OSS | AGPL-3.0 | 97 | 97 | 2580 | 97 | 🟢 Excellent |
| 7 | OWASP Noir | OSI-approved OSS | MIT | 97 | 97 | 1423 | 97 | 🟢 Excellent |
| 8 | Dalfox | OSI-approved OSS | MIT | 97 | 96 | 5287 | 97 | 🟢 Excellent |
| 9 | OSV.dev | OSI-approved OSS | Apache-2.0 | 97 | 96 | 2917 | 97 | 🟢 Excellent |
| 10 | Strix | OSI-approved OSS | Apache-2.0 | 97 | 96 | 61393 | 97 | 🟢 Excellent |
| 11 | Prosopo CAPTCHA | OSI-approved OSS | Apache-2.0 | 96 | 96 | 298 | 96 | 🟢 Excellent |
| 12 | Nuclei | OSI-approved OSS | MIT | 96 | 95 | 31077 | 96 | 🟢 Excellent |
| 13 | Trivy | OSI-approved OSS | Apache-2.0 | 96 | 94 | 37842 | 95 | 🟢 Excellent |
| 14 | lopper | OSI-approved OSS | MIT | 93 | 94 | 2 | 93 | 🟢 Excellent |
| 15 | Faraday | OSI-approved OSS | GPL-3.0 | 92 | 94 | 6713 | 93 | 🟢 Excellent |
| 16 | OpenA2A | OSI-approved OSS | Apache-2.0 | 91 | 92 | 20 | 92 | 🟢 Excellent |
| 17 | sqlmap | OSI-approved OSS | GPL-2.0 | 90 | 94 | 38385 | 91 | 🟢 Excellent |
| 18 | Copacetic | OSI-approved OSS | Apache-2.0 | 91 | 87 | 1703 | 89 | 🟢 Excellent |
| 19 | FoxGuard | OSI-approved OSS | MIT | 90 | 88 | 294 | 89 | 🟢 Excellent |
| 20 | OpenAnt | OSI-approved OSS | Apache-2.0 | 90 | 85 | 747 | 88 | 🟢 Excellent |
| 21 | powerpipe | OSI-approved OSS | AGPL-3.0 | 88 | 85 | 522 | 87 | 🟢 Excellent |
| 22 | Web-Check | OSI-approved OSS | MIT | 87 | 86 | 34714 | 87 | 🟢 Excellent |
| 23 | Nettacker | OSI-approved OSS | Apache-2.0 | 89 | 82 | 5558 | 86 | 🟢 Excellent |
| 24 | Presidio | OSI-approved OSS | MIT | 89 | 81 | 10786 | 86 | 🟢 Excellent |
| 25 | Pentest AI | OSI-approved OSS | MIT | 84 | 88 | 1656 | 86 | 🟢 Excellent |
| 26 | vulnerability-spoiler-alert | OSI-approved OSS | MIT | 81 | 85 | 159 | 83 | 🟢 Excellent |
| 27 | Steampipe | OSI-approved OSS | AGPL-3.0 | 79 | 70 | 7950 | 75 | 🟢 Good |
| 28 | PayloadsAllTheThings | OSI-approved OSS | MIT | 73 | 58 | 80711 | 67 | 🟢 Good |
| 29 | Pentagi | OSI-approved OSS | MIT | 68 | 44 | 22625 | 58 | 🟡 Fair |
| 30 | Xingrin | OSI-approved OSS | MIT | 61 | 40 | 657 | 53 | 🟡 Fair |
| 31 | ExtensionShield | OSI-approved OSS | MIT | 58 | 39 | 102 | 50 | 🟡 Fair |
| 32 | Lynis | OSI-approved OSS | GPL-3.0 | 55 | 34 | 16303 | 47 | 🟡 Fair |
| 33 | Gitleaks | OSI-approved OSS | MIT | 54 | 25 | 29191 | 43 | 🟡 Fair |
| 34 | Dokuru | OSI-approved OSS | Apache-2.0 | 45 | 28 | 8 | 39 | 🔴 Needs Attention |
| 35 | AgentFence | OSI-approved OSS | MIT | 38 | 13 | 61 | 28 | 🔴 Needs Attention |
| 36 | Redlyne | OSI-approved OSS | Apache-2.0 | 37 | 15 | 39 | 28 | 🔴 Needs Attention |
| 37 | CloudRec | OSI-approved OSS | Apache-2.0 | 29 | 15 | 192 | 24 | 🔴 Needs Attention |
| 38 | Lodestar Forge | OSI-approved OSS | GPL-3.0 | 24 | 0 | 109 | 14 | 🔴 Needs Attention |
| 39 | Deepfence ThreatMapper | OSI-approved OSS | Apache-2.0 | 18 | 2 | 5321 | 12 | 🔴 Needs Attention |
| 40 | Agentic Radar | OSI-approved OSS | Apache-2.0 | 5 | 0 | 1048 | 3 | 🔴 Needs Attention |
| 41 | CodeAnalysis | OSI-approved OSS | GPL-2.0 | 4 | 0 | 1845 | 2 | 🔴 Needs Attention |
| 42 | NodeJSSCAN | OSI-approved OSS | GPL-3.0 | 3 | 0 | 2574 | 2 | 🔴 Needs Attention |
| 43 | Metlo | OSI-approved OSS | MIT | 2 | 0 | 1784 | 1 | 🔴 Needs Attention |
| 44 | OpenClarity | OSI-approved OSS | Apache-2.0 | 0 | 0 | 1460 | 0 | 🔴 Needs Attention |
| 45 | VMC | OSI-approved OSS | Apache-2.0 | 0 | 0 | 93 | 0 | 🔴 Needs Attention |
Top 3 Highlights
Akto is the highest-ranked tool in this snapshot, with a ToolVitals score of 98, health score of 98, and shipping score of 98. Its supplied description focuses on API security across discovery, posture, and CI/CD testing. It carries the openness label OSI-approved OSS and the license label MIT; its 1,513 GitHub stars are context only.
Kubescape ranks second with a ToolVitals score of 98, health score of 98, and shipping score of 98. Its supplied description covers Kubernetes security in IDEs, CI/CD pipelines, and clusters, including risk analysis, security, compliance, and misconfiguration scanning. It carries the openness label OSI-approved OSS and the license label Apache-2.0; its 11,723 GitHub stars are context only.
Prowler ranks third with a ToolVitals score of 97, a health score of 98, and a shipping score of 97. Its supplied description presents it as a cloud security platform that automates security and compliance across any cloud environment. It carries the openness label OSI-approved OSS and the license label Apache-2.0; its 14,770 GitHub stars are context only.
Want to see the full health, license, shipping, and confidence details for every tool in Security Scanning? Browse all Security Scanning Tools →