domain: security
4787 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| docker-mailserver/docker-mailserver A production-ready, containerized fullstack mail server bundling Postfix (SMTP), Dovecot (IMAP/POP3), Rspamd, SpamAssassin, ClamAV, Fail2ba… | 79 | 18803 | active |
| Wasmtime Wasmtime is a standalone WebAssembly runtime built on the Cranelift code generator, usable both as a CLI and as an embeddable library. It s… | 95 | 18570 | stable |
| guillaumemeyer/watermarks-remover A privacy-first Python service plus agent skill that strips multi-vendor AI provenance marks (C2PA, EXIF/XMP metadata, invisible Unicode, a… | 79 | 18542 | active |
| fail2ban/fail2ban Fail2ban is a Python daemon that scans log files for repeated authentication failures and bans offending IP addresses by updating firewall … | 88 | 18479 | stable |
| ginuerzh/gost GOST (GO Simple Tunnel) is a Go-based tunneling and proxy tool supporting HTTP/HTTPS/HTTP2/SOCKS4/SOCKS5/Shadowsocks protocols plus QUIC, K… | 23 | 18190 | active |
| auth0/node-jsonwebtoken A Node.js library implementing JSON Web Tokens (JWT) per RFC 7519, supporting signing and verification with HMAC, RSA, and ECDSA algorithms… | 72 | 18189 | stable |
| tiann/KernelSU KernelSU is a kernel-based root solution for Android that runs inside the Linux kernel to grant root access. It provides stealthy, permissi… | 91 | 18014 | active |
| google/magika Magika is an AI-powered file content type detection tool that uses a small, highly optimized deep learning model to identify 200+ file type… | 88 | 17971 | stable |
| verdaccio/verdaccio Verdaccio is a lightweight, zero-config private npm proxy registry built in Node.js. It hosts private packages, proxies and caches upstream… | 99 | 17843 | active |
| slackhq/nebula Nebula is a scalable overlay networking tool (mesh VPN) built on the Noise Protocol Framework, using certificates and security groups for m… | 95 | 17658 | stable |
| ory/hydra Ory Hydra is an OpenID Certified OAuth 2.0 and OpenID Connect provider server written in Go, handling token issuance, client management, an… | 78 | 17498 | stable |
| justauth/JustAuth JustAuth is a small, comprehensive Java library for third-party OAuth2 authorization login. It integrates dozens of domestic and internatio… | 57 | 17496 | stable |
| projectdiscovery/katana Katana is a fast, configurable web crawling and spidering framework written in Go, supporting both standard HTTP-based and headless browser… | 94 | 17348 | active |
| cure53/DOMPurify DOMPurify is a fast, DOM-only XSS sanitizer for HTML, MathML and SVG that removes malicious markup while allowing safe content. It works in… | 99 | 17339 | stable |
| laramies/theHarvester theHarvester is a Python CLI tool that gathers open-source intelligence (emails, subdomains, hostnames, IPs, names, URLs, ASNs) about a dom… | 91 | 17202 | active |
| goproxy GoProxy is a high-performance, cross-platform proxy server written in Go supporting HTTP(S), SOCKS5, SS, WebSocket, TCP, UDP, and DNS proxy… | 94 | 17121 | active |
| zerotier/ZeroTierOne ZeroTier is a software-defined networking tool that creates secure virtual Ethernet networks spanning devices, VMs, containers, and clouds … | 84 | 17047 | stable |
| stascorp/rdpwrap RDP Wrapper Library is a Windows system library that enables Remote Desktop Host support and concurrent RDP sessions on editions that ship … | 23 | 16812 | stable |
| ZPhisher Zphisher is a beginner-friendly, automated phishing toolkit written in Bash with 30+ ready-made login page templates. It supports multiple … | 23 | 16700 | active |
| Wazuh Wazuh is a free, open source security platform that unifies XDR and SIEM capabilities for threat prevention, detection, and response across… | 98 | 16691 | stable |
| MatrixTM/MHDDoS MHDDoS is a Python 3 command-line DDoS attack script offering 57 flood methods across Layer 7 (HTTP) and Layer 4 (TCP/UDP), including bypas… | 74 | 16595 | active |
| ffuf/ffuf ffuf is a fast web fuzzer written in Go used for discovering directories, virtual hosts, and parameters by brute-forcing HTTP requests. It … | 97 | 16593 | stable |
| redox-os/redox Redox is a full-featured Unix-like operating system written in Rust with a microkernel architecture, inspired by seL4, MINIX, Plan 9, Linux… | 70 | 16532 | active |
| flipperdevices/flipperzero-firmware The official open-source firmware for the Flipper Zero, a portable multi-tool device for interacting with access control systems. It implem… | 81 | 16515 | active |
| jpillora/chisel Chisel is a fast TCP/UDP tunnel transported over HTTP and secured via SSH, shipped as a single Go executable containing both client and ser… | 87 | 16448 | active |
| Semgrep Semgrep is a fast, open-source static analysis tool that searches code, finds bugs, and enforces secure coding standards using rules that l… | 95 | 16409 | active |
| CISOfy/lynis Lynis is an open-source security auditing and hardening tool for UNIX-based systems including Linux, macOS, and BSD. It performs in-depth l… | 90 | 16239 | stable |
| javascript-obfuscator/javascript-obfuscator A powerful open-source JavaScript and Node.js obfuscator that transforms readable source code into hard-to-reverse-engineer output using id… | 99 | 16218 | active |
| angristan/openvpn-install A Bash script that installs and manages a self-hosted OpenVPN VPN server on many Linux distributions. It handles client certificate generat… | 76 | 16112 | active |
| fortra/impacket Impacket is a collection of Python classes for low-level programmatic access to network protocols, including full implementations of SMB1-3… | 83 | 16038 | active |
| Cryptomator Cryptomator is an open-source desktop and mobile application that provides transparent client-side encryption for files stored in any cloud… | 96 | 16018 | stable |
| winsiderss/systeminformer System Informer (formerly Process Hacker) is a free, open-source, multi-purpose Windows tool for monitoring system resources, debugging sof… | 67 | 15701 | active |
| zaproxy/zaproxy Zed Attack Proxy (ZAP) by Checkmarx is a free, open-source web application security scanner used for finding vulnerabilities in web apps du… | 78 | 15686 | stable |
| Konloch/bytecode-viewer Bytecode Viewer is a free, open-source Java and Android APK reverse engineering suite that bundles six Java decompilers, bytecode disassemb… | 73 | 15614 | active |
| Evilginx Evilginx is a standalone man-in-the-middle attack framework written in Go that proxies traffic between a victim's browser and a legitimate … | 62 | 15535 | active |
| gojue/ecapture eCapture is an eBPF-based CLI tool that captures SSL/TLS plaintext traffic without needing CA certificates, supporting OpenSSL, LibreSSL, B… | 96 | 15441 | active |
| cloudflare/cloudflared cloudflared is the command-line client and daemon for Cloudflare Tunnel, which creates outbound-only connections from your origin servers t… | 99 | 15395 | stable |
| FlareSolverr/FlareSolverr FlareSolverr is a proxy server that bypasses Cloudflare and DDoS-GUARD protection by solving browser challenges with Selenium and undetecte… | 95 | 15316 | active |
| passteque/gluetun Gluetun is a lightweight VPN client packaged as a thin Alpine Docker container, written in Go, supporting many VPN providers via OpenVPN or… | 94 | 15305 | active |
| supertokens/supertokens-core SuperTokens Core is the open-source HTTP service at the heart of the SuperTokens authentication platform, handling core auth logic and data… | 94 | 15282 | active |
| dogecoin/dogecoin Dogecoin Core is the reference full-node client and wallet for the Dogecoin cryptocurrency, adapted from Bitcoin Core. It lets anyone run a… | 66 | 15259 | active |
| trustedsec/social-engineer-toolkit The Social-Engineer Toolkit (SET) is an open-source Python-based penetration testing framework for authorized social-engineering assessment… | 70 | 15239 | active |
| txthinking/brook Brook is a cross-platform programmable network tool written in Go that provides encrypted proxy/VPN functionality with system-level network… | 65 | 15162 | active |
| GreyDGL/PentestGPT PentestGPT is an AI-powered penetration testing agent framework that drives LLMs (Claude Code, Codex, or many providers in legacy mode) to … | 70 | 15091 | active |
| owasp-amass/amass OWASP Amass is a Go-based framework for in-depth attack surface mapping and external asset discovery using OSINT gathering and active recon… | 81 | 15047 | active |
| NVIDIA/SkillSpector SkillSpector is a security scanner for AI agent skills used by Claude Code, Codex CLI, Gemini CLI, and MCP-based agents. It detects vulnera… | 81 | 15011 | active |
| HunxByts/GhostTrack GhostTrack is a Python-based OSINT CLI tool for gathering information about IP addresses, phone numbers, and usernames across social media.… | 30 | 14943 | active |
| duplicati/duplicati Duplicati is a free, open-source backup client that stores encrypted, incremental, compressed backups on cloud storage services and remote … | 93 | 14939 | active |
| oauth2-proxy/oauth2-proxy OAuth2 Proxy is a reverse proxy and middleware that adds OAuth2/OIDC authentication in front of web applications, supporting providers like… | 99 | 14877 | stable |
| zitadel/zitadel ZITADEL is an open-source identity and access management (IAM) platform providing authentication and authorization out of the box, includin… | 95 | 14864 | active |
| guofei9987/blind_watermark A Python library for embedding and extracting blind (invisible) watermarks in images using DWT-DCT-SVD transforms, with watermark recovery … | 56 | 14706 | stable |
| amnezia-vpn/amnezia-client Amnezia VPN is an open-source, cross-platform VPN client (desktop and mobile) that can automatically deploy a self-hosted VPN server on you… | 95 | 14705 | active |
| prowler-cloud/prowler Prowler is an open-source cloud security platform that performs security best-practice assessments, audits, continuous monitoring, hardenin… | 95 | 14687 | active |
| maurosoria/dirsearch dirsearch is an advanced web path scanner that brute-forces directories and files on web servers using wordlists. It is a Python CLI tool w… | 87 | 14662 | active |
| crowdsecurity/crowdsec CrowdSec is an open-source, crowdsourced security engine that analyzes logs and HTTP requests to detect malicious behavior and block offend… | 89 | 14655 | stable |
| logto-io/logto Logto is an open-source identity and access management (IAM) infrastructure for SaaS and AI applications, built on OIDC, OAuth 2.1, and SAM… | 98 | 14468 | active |
| moonD4rk/HackBrowserData HackBrowserData is a self-contained Go CLI that extracts and decrypts browser data (passwords, cookies, history, bookmarks, credit cards, d… | 91 | 14458 | active |
| shadow1ng/fscan Fscan is a comprehensive intranet scanning tool written in Go that automates host discovery, port scanning, service identification, weak-pa… | 95 | 14450 | active |
| OpenVPN/openvpn OpenVPN is an open-source VPN daemon that creates secure point-to-point or site-to-site TLS-encrypted tunnels over the network. It is a mat… | 98 | 14442 | stable |
| bytebase/bytebase Bytebase is an open-source database governance platform that acts as a control plane between users (humans and AI agents) and databases, co… | 98 | 14419 | active |
| projectdiscovery/subfinder Subfinder is a fast, passive subdomain discovery tool written in Go that enumerates valid subdomains for target domains using online passiv… | 95 | 14315 | active |
| megadose/holehe Holehe is an OSINT tool that checks whether an email address is registered on 120+ sites (Twitter, Instagram, Snapchat, etc.) by abusing th… | 32 | 14278 | active |
| casdoor/casdoor Casdoor is an open-source, self-hosted Identity and Access Management (IAM) and single sign-on (SSO) platform with a web UI, written in Go.… | 95 | 14276 | active |
| ReFirmLabs/binwalk Binwalk is a fast firmware analysis tool rewritten in Rust that identifies and optionally extracts files and data embedded inside other fil… | 66 | 14276 | active |
| gophish/gophish Gophish is an open-source phishing framework for running phishing simulations and security awareness training. It provides a web UI and RES… | 23 | 14152 | stable |
| Datalux/Osintgram Osintgram is a Python-based OSINT tool for Instagram that provides an interactive shell to collect and analyze information about Instagram … | 40 | 14147 | active |
| cert-manager/cert-manager cert-manager is a Kubernetes controller that adds Certificate and Issuer resource types to clusters and automates obtaining, renewing, and … | 98 | 14052 | stable |
| OJ/gobuster Gobuster is a fast, multi-threaded brute-forcing tool written in Go for enumerating web directories/files, DNS subdomains, virtual hosts, c… | 80 | 14038 | active |
| evilsocket/opensnitch OpenSnitch is a GNU/Linux interactive application firewall inspired by Little Snitch, intercepting and filtering outbound connections per a… | 79 | 14009 | active |
| kopia/kopia Kopia is a fast, open-source backup and restore tool that creates encrypted, compressed, and deduplicated snapshots of files and directorie… | 96 | 13968 | stable |
| OpenNHP/opennhp OpenNHP is a lightweight, cryptography-powered open-source toolkit written in Go that implements the Cloud Security Alliance's Network-infr… | 94 | 13918 | active |
| libsodium libsodium is a modern, portable, easy-to-use C library for cryptographic operations, forked from NaCl with a compatible but extended API. I… | 83 | 13916 | stable |
| ory/kratos Ory Kratos is a headless, API-first identity and user management server written in Go that centralizes login, registration, account recover… | 81 | 13849 | stable |
| wanghongenpin/proxypin ProxyPin is a free, open-source HTTP(S) traffic capture application built with Flutter, supporting Windows, Mac, Linux, Android, and iOS. I… | 90 | 13825 | active |
| juice-shop/juice-shop OWASP Juice Shop is an intentionally insecure web application written in Node.js, Express, and Angular that covers vulnerabilities from the… | 94 | 13726 | active |
| Bitwarden Bitwarden's server backend providing the APIs, database, and infrastructure behind the Bitwarden password manager. It can be self-hosted vi… | 95 | 13674 | active |
| pwntools Pwntools is a Python CTF framework and exploit development library designed for rapid prototyping of binary exploits. It provides utilities… | 74 | 13660 | active |
| borgbackup/borg BorgBackup (Borg) is a deduplicating backup program with optional compression and authenticated encryption. It stores data as content-defin… | 89 | 13654 | active |
| safing/portmaster Portmaster is a free and open-source application firewall and privacy suite for Windows and Linux desktops. It intercepts all network traff… | 95 | 13612 | active |
| DNSCrypt/dnscrypt-proxy dnscrypt-proxy is a flexible local DNS proxy that encrypts and authenticates DNS traffic using DNSCrypt v2, DNS-over-HTTPS, Anonymized DNS,… | 93 | 13600 | stable |
| digininja/DVWA Damn Vulnerable Web Application (DVWA) is a PHP/MariaDB web application intentionally riddled with common web vulnerabilities at multiple d… | 70 | 13551 | active |
| openwall/john John the Ripper jumbo is an open-source offline password cracker supporting hundreds of hash and cipher types, from Unix and Windows passwo… | 75 | 13543 | active |
| sshuttle/sshuttle sshuttle is a transparent proxy server that works as a poor man's VPN, forwarding traffic over SSH without requiring admin access on the re… | 79 | 13530 | stable |
| SoftEther VPN SoftEther VPN is an open-source, cross-platform, multi-protocol VPN server and client software written in C. It supports SSL-VPN, OpenVPN, … | 70 | 13503 | active |
| nmap/nmap Nmap is the industry-standard open-source network scanner for host discovery, port scanning, service/version detection, and OS fingerprinti… | 77 | 13465 | stable |
| awslabs/git-secrets git-secrets is a command-line tool that scans git commits, commit messages, and merge histories for secrets and credentials, rejecting comm… | 51 | 13380 | stable |
| mailcow/mailcow-dockerized mailcow: dockerized is a full-featured, self-hosted mail server suite delivered as a set of Docker containers, bundling Postfix, Dovecot, S… | 98 | 13330 | stable |
| threat9/routersploit RouterSploit is an open-source exploitation framework dedicated to embedded devices like routers, modeled after Metasploit. It provides mod… | 59 | 13223 | active |
| objective-see/LuLu LuLu is a free, open-source macOS firewall that monitors and blocks unknown outgoing network connections. It uses a system extension and ne… | 97 | 13103 | active |
| keeweb/keeweb KeeWeb is a free, cross-platform password manager compatible with KeePass kdbx database files, available as a desktop app (Electron) or a b… | 77 | 12986 | active |
| beemdevelopment/Aegis Aegis Authenticator is a free, open-source Android app for managing two-factor authentication (2FA) tokens. It stores HOTP/TOTP tokens in a… | 82 | 12974 | stable |
| mozilla-firefox/firefox Firefox is Mozilla's free and open-source web browser built on the Gecko engine, available for desktop and mobile platforms. It emphasizes … | 68 | 12971 | active |
| mvt-project/mvt Mobile Verification Toolkit (MVT) is a Python command-line toolkit for conducting forensic analysis of Android and iOS devices to detect tr… | 94 | 12967 | active |
| spatie/laravel-permission A Laravel package that lets you associate users (and other Eloquent models) with roles and permissions stored in the database. Permissions … | 96 | 12964 | stable |
| anchore/grype Grype is an open-source vulnerability scanner for container images, filesystems, and SBOMs, written in Go by Anchore. It identifies known C… | 98 | 12789 | active |
| elastic/beats Elastic Beats is a family of lightweight data shippers written in Go that collect logs, metrics, network packets, audit data, and uptime si… | 95 | 12640 | active |
| google/oss-fuzz OSS-Fuzz is Google's free continuous fuzzing service for open source software, combining fuzzing engines like libFuzzer, AFL++, and Honggfu… | 77 | 12594 | active |
| jopohl/urh Universal Radio Hacker (URH) is a complete open-source suite for investigating wireless protocols, with native support for many common Soft… | 10 | 12569 | active |
| secdev/scapy Scapy is a powerful Python-based interactive packet manipulation program and library that can forge, decode, send, capture, and match packe… | 75 | 12501 | stable |
| Atomic Red Team Atomic Red Team is a library of small, portable detection tests mapped to the MITRE ATT&CK framework, letting security teams validate their… | 77 | 12457 | active |