Security & Compliance
Security Scanning
Vulnerability scanning, SAST, dependency scanning, and security testing.
Best Security Scanning tools by public signals
These picks are computed from scored public evidence. Use the openness column in the ranking to separate OSI-approved, source-available, open-core, proprietary, and unverified-license tools.
Use Case Rankings
Ordered by ToolVitals score, health, shipping, confidence, and then adoption as a tie-breaker.
| # | Tool | Health | Shipping | Openness | Stars | Score | Status |
|---|---|---|---|---|---|---|---|
| 01 | Prowler Prowler is the world’s most widely used open-source cloud security platform that automates security and compliance across any cloud environment. | 100 | 100 | OSI-approved OSS | 14k | 100 | Active |
| 02 | NetBird Zero-configuration mesh VPN for business. | 100 | 100 | OSI-approved OSS | 25.9k | 100 | Active |
| 03 | Akto Open-source API security platform for discovery, posture, and CI/CD testing. | 98 | 100 | OSI-approved OSS | 1.5k | 99 | Active |
| 04 | DefectDojo Open-Source Unified Vulnerability Management, DevSecOps & ASPM | 93 | 100 | OSI-approved OSS | 4.8k | 97 | Active |
| 05 | CNSpec Cloud-native security platform for protecting build and runtime environments. | 93 | 100 | License unknown | 429 | 96 | Active |
| 06 | Snyk Developer-first security platform | 93 | 94 | OSI-approved OSS | 5.6k | 95 | Active |
| 07 | Kubescape Kubescape is an open-source Kubernetes security platform for your IDE, CI/CD pipelines, and clusters. It includes risk analysis, security, compliance, and misconfiguration scanning, saving Kubernetes users and administrators precious time, effort, and resources. | 93 | 95 | OSI-approved OSS | 11.5k | 94 | Active |
| 08 | Prosopo CAPTCHA Privacy-focused CAPTCHA and bot defense platform. | 90 | 90 | OSI-approved OSS | 295 | 93 | Active |
| 09 | Strix Open-source AI hackers to find and fix your app’s vulnerabilities. | 95 | 84 | OSI-approved OSS | 25.9k | 92 | Active |
| 10 | Nuclei Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations. | 91 | 83 | OSI-approved OSS | 29.1k | 91 | Active |
| 11 | Pentest AI Autonomous pentesting AI with MCP server and Python agents. | 86 | 93 | OSI-approved OSS | 767 | 91 | Active |
| 12 | Faraday Open Source Vulnerability Management Platform | 85 | 90 | OSI-approved OSS | 6.5k | 90 | Active |
| 13 | Panguard AI Open-source security platform for AI agents with skill audits and threat monitoring. | 82 | 92 | OSI-approved OSS | 48 | 90 | Active |
| 14 | Pipelock Open-source AI agent firewall for MCP security and egress control. | 81 | 95 | OSI-approved OSS | 707 | 90 | Active |
| 15 | FoxGuard Security scanner as fast as a linter with TUI triage. | 80 | 95 | OSI-approved OSS | 266 | 90 | Active |
| 16 | OWASP Noir Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface. | 85 | 84 | OSI-approved OSS | 1.3k | 88 | Active |
| 17 | OSV.dev Open source vulnerability DB and triage service. | 85 | 80 | OSI-approved OSS | 2.7k | 87 | Active |
| 18 | Copacetic 🧵 CLI tool for directly patching container images! | 89 | 76 | OSI-approved OSS | 1.6k | 86 | Active |
| 19 | Dalfox 🌙🦊 Dalfox is a powerful open-source XSS scanner and utility focused on automation. | 81 | 84 | OSI-approved OSS | 5.1k | 86 | Active |
| 20 | Sigillo Self-hostable secrets management platform and open-source Doppler alternative. | 76 | 87 | License unknown | 35 | 86 | Active |
| 21 | Trivy Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more | 85 | 78 | OSI-approved OSS | 36.4k | 85 | Active |
| 22 | OpenA2A Open-source security tools for AI agents. | 72 | 87 | OSI-approved OSS | 19 | 84 | Warning |
| 23 | Gravitl WireGuard virtual networking platform. | 81 | 72 | OSI-approved OSS | 11.6k | 83 | Active |
| 24 | Pentagi Fully autonomous AI Agents system capable of performing complex penetration testing tasks | 80 | 78 | OSI-approved OSS | 17.7k | 83 | Active |
| 25 | MegaLinter 🦙 MegaLinter analyzes 50 languages, 22 formats, 21 tooling formats, excessive copy-pastes, spelling mistakes and security issues in your repository sources with a GitHub Action, other CI tools or locally. | 78 | 78 | OSI-approved OSS | 2.5k | 82 | Active |
| 26 | Web-Check 🕵️♂️ All-in-one OSINT tool for analysing any website | 78 | 70 | OSI-approved OSS | 33.6k | 79 | Active |
| 27 | Dokuru Agent-based Docker security audit platform with CIS benchmark compliance and remediation. | 66 | 88 | License unknown | 9 | 79 | Warning |
| 28 | Presidio An open-source framework for detecting, redacting, masking, and anonymizing sensitive data (PII) across text, images, and structured data. Supports NLP, pattern matching, and customizable pipelines. | 83 | 53 | OSI-approved OSS | 8.6k | 78 | Warning |
| 29 | Steampipe Zero-ETL, infinite possibilities. Live query APIs, code & more with SQL. No DB required. | 81 | 52 | OSI-approved OSS | 7.8k | 76 | Warning |
| 30 | Clawmoat Open-source agent firewall to prevent data leaks and dangerous tool use. | 67 | 65 | OSI-approved OSS | 40 | 75 | Warning |
| 31 | Caido 🚀 Caido releases, wiki and roadmap | 79 | 42 | License unknown | 2.4k | 73 | Warning |
| 32 | powerpipe Powerpipe: Dashboards for DevOps. Visualize cloud configurations. Assess security posture against a massive library of benchmarks. Build custom dashboards with code. | 77 | 46 | OSI-approved OSS | 510 | 73 | Warning |
| 33 | CloudRec CloudRec is an open source multi-cloud security posture management (CSPM) platform designed to help organizations improve the security of their cloud environments. | 72 | 52 | OSI-approved OSS | 184 | 71 | Warning |
| 34 | Secutils Open source security toolbox for engineers and researchers. | 62 | 63 | OSI-approved OSS | 100 | 70 | Warning |
| 35 | vulnerability-spoiler-alert A monitoring hub that watches popular open-source repositories and uses AI to detect when commits ar | 64 | 63 | OSI-approved OSS | 139 | 69 | Warning |
| 36 | ExtensionShield Chrome extension risk scanner — scan Chrome Web Store links or CRX/ZIP builds and generate evidence-based security/privacy reports. Open-core. | 74 | 41 | OSI-approved OSS | 90 | 68 | Warning |
| 37 | Gitleaks Find secrets with Gitleaks 🔑 | 67 | 45 | OSI-approved OSS | 27.7k | 68 | Warning |
| 38 | Mixeway Repository containing source code of MixewayFlow service that is Swiss army knife for DevSecOps Teams | 65 | 48 | License unknown | 82 | 65 | Warning |
| 39 | Nettacker Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management | 74 | 30 | OSI-approved OSS | 5.2k | 64 | Warning |
| 40 | PayloadsAllTheThings A list of useful payloads and bypass for Web Application Security and Pentest/CTF | 73 | 14 | OSI-approved OSS | 78.4k | 59 | Warning |
| 41 | Redlyne Detect and patch vulnerabilities in AI-generated Python code. | 49 | 46 | OSI-approved OSS | 37 | 59 | Warning |
| 42 | Xingrin Open-source attack surface management and authorized security automation platform for asset discovery, service probing, scan orchestration, and security result management. | 68 | 25 | OSI-approved OSS | 566 | 58 | Warning |
| 43 | OpenAnt Open-source LLM-based vulnerability discovery product for defenders. | 68 | 21 | OSI-approved OSS | 592 | 58 | Warning |
| 44 | Deepfence ThreatMapper Open source cloud native application protection platform. | 58 | 16 | OSI-approved OSS | 5.3k | 54 | Warning |
| 45 | Lynis Lynis - Security auditing tool for Linux, macOS, and UNIX-based systems. Assists with compliance testing (HIPAA/ISO27001/PCI DSS) and system hardening. Agentless, and installation optional. | 51 | 35 | OSI-approved OSS | 15.8k | 54 | Warning |
| 46 | VMC Open source vulnerability management platform. | 49 | 39 | OSI-approved OSS | 93 | 54 | Critical |
| 47 | SecScore Security scoring engine for CI/CD pipelines. | 44 | 24 | License unknown | 8 | 51 | Critical |
| 48 | OpenClarity Open-source platform for cloud-native security and observability. | 51 | 0 | OSI-approved OSS | 1.5k | 42 | Warning |
| 49 | ShieldPilot Open-source security platform for AI coding agents. | 41 | 7 | OSI-approved OSS | 1 | 41 | Critical |
| 50 | Envy CLI Open-source CLI for secret injection and management. | 38 | 11 | License unknown | 7 | 41 | Critical |
| 51 | Atlas CSMP Open-source cloud security posture management tool for AWS infrastructure. | 33 | 0 | License unknown | 1 | 37 | Critical |
| 52 | RFSec-ToolKit RFSec-ToolKit is a collection of Radio Frequency Communication Protocol Hacktools.无线通信协议相关的工具集,可借助SDR硬件+相关工具对无线通信进行研究。Collect with ♥ by HackSmith | 31 | 0 | License unknown | 1.7k | 33 | Critical |
| 53 | Agentic Radar Security scanner for LLM agent workflows. | 28 | 0 | OSI-approved OSS | 978 | 33 | Critical |
| 54 | Matano Cloud-native security lake platform for threat hunting. | 27 | 0 | OSI-approved OSS | 1.7k | 33 | Critical |
| 55 | NodeJSSCAN Static security scanner for Node.js applications. | 31 | 0 | OSI-approved OSS | 2.6k | 32 | Critical |
| 56 | Metlo Metlo is an open-source API security platform. | 31 | 0 | OSI-approved OSS | 1.8k | 31 | Critical |
| 57 | Selefra Policy-as-code tool for analytics and auditing across cloud and SaaS environments. | 28 | 0 | OSI-approved OSS | 545 | 31 | Critical |
| 58 | CodeAnalysis Static code analysis platform. | 27 | 0 | OSI-approved OSS | 1.8k | 30 | Critical |
| 59 | OSINT UI Professional open source intelligence platform. | 26 | 0 | License unknown | 17 | 29 | Critical |
| 60 | AgentFence Open-source platform for testing AI agent security. | 26 | 0 | OSI-approved OSS | 55 | 28 | Critical |
Evidence Watch
Tracked tools with useful public signals but no verdict score yet.