function: cryptography
1245 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| Caligatio/jsSHA jsSHA is a pure TypeScript/JavaScript library implementing the complete SHA hash family (SHA-1, SHA-2, SHA-3, SHAKE, cSHAKE, KMAC) plus HMA… | 85 | 2263 | stable |
| google/boringssl BoringSSL is Google's fork of OpenSSL, serving as the TLS/SSL library in Chrome, Chromium, and Android. It is open source but explicitly no… | 99 | 2262 | active |
| matrix-org/matrix-rust-sdk A collection of Rust crates implementing the Matrix Client-Server SDK, handling low-level details like encryption, syncing, and room state.… | 95 | 2259 | active |
| mailpile/Mailpile Mailpile is a free, open-source, privacy-focused email client with built-in PGP encryption, a fast custom search engine, and tag-based orga… | 23 | 8822 | maintenance |
| RustCrypto/hashes A collection of cryptographic hash function implementations written in pure Rust, organized as separate crates built on the digest crate's … | 77 | 2258 | active |
| iText iText is a high-performance PDF library/SDK for Java and .NET that lets developers create, manipulate, inspect, sign, and secure PDF docume… | 93 | 2255 | stable |
| ARM-software/arm-trusted-firmware Trusted Firmware-A (TF-A) is a reference implementation of secure world software (EL3 firmware, trusted boot, and a small trusted runtime) … | 77 | 2251 | active |
| Foxboron/sbctl sbctl is a user-friendly Secure Boot key manager for Linux written in Go. It creates and enrolls UEFI Secure Boot keys, tracks files that n… | 72 | 2247 | active |
| irungentoo/toxcore Toxcore is the core C library implementing the Tox protocol, a fully encrypted, peer-to-peer, serverless communication platform for instant… | 32 | 8748 | maintenance |
| JasonXuDeveloper/JEngine JEngine is a Unity framework that enables runtime hot updates for games, letting developers push code, assets, and logic changes without re… | 79 | 2230 | active |
| srikanth-lingala/zip4j Zip4j is a comprehensive Java library for working with zip files and streams, offering a simple API for creating, extracting, updating, and… | 65 | 2225 | active |
| AbsInt/CompCert CompCert is a formally verified C compiler whose correctness is machine-checked with the Coq proof assistant, guaranteeing generated assemb… | 78 | 2215 | active |
| ghostunnel/ghostunnel Ghostunnel is a simple TLS proxy written in Go that adds mutual TLS authentication in front of (or behind) non-TLS backend services, in cli… | 99 | 2192 | active |
| ranisalt/node-argon2 Node.js bindings to the reference Argon2 password-hashing implementation, supporting Argon2i, Argon2d, and Argon2id. It provides a simple a… | 93 | 2182 | stable |
| risc0/risc0 RISC Zero is a zero-knowledge verifiable general computing platform built on zk-STARKs and a RISC-V-based zkVM. It lets developers prove th… | 94 | 2179 | active |
| kimci86/bkcrack bkcrack is a command-line tool that cracks legacy ZIP encryption (ZipCrypto/PKWARE) using Biham and Kocher's known plaintext attack. Given … | 73 | 2176 | active |
| a16z/helios Helios is a fast, trustless multichain light client for Ethereum written in Rust that turns an untrusted centralized RPC endpoint into a ve… | 85 | 2175 | active |
| safe-fndn/safe-smart-account Safe Smart Account is the set of audited Solidity smart contracts implementing Safe's multisig smart account (contract wallet) for Ethereum… | 69 | 2174 | active |
| BishopFox/unredacter Unredacter is an Electron-based desktop tool that demonstrates how pixelated redactions in images can be reversed by brute-force guessing t… | 32 | 8382 | maintenance |
| 0Chencc/CTFCrackTools CTFCrackTools X is a cross-platform desktop CTF toolkit built with Rust and Tauri, featuring a visual node-based workflow for composing enc… | 80 | 2146 | active |
| datatheorem/TrustKit TrustKit is an open-source Objective-C framework that simplifies deploying SSL public key pinning and reporting in iOS, macOS, tvOS, and wa… | 78 | 2138 | active |
| sgan81/apfs-fuse A read-only FUSE driver that mounts Apple File System (APFS) volumes on Linux. It supports FileVault-encrypted volumes, fusion drives, snap… | 32 | 2137 | active |
| phra/PEzor PEzor is an open-source shellcode and PE packer that wraps executables or raw shellcode into new binaries with evasion features like unhook… | 32 | 2129 | active |
| MinaProtocol/mina Mina is a layer-1 cryptocurrency protocol implemented in OCaml featuring a constant-sized (~22KB) blockchain built with recursive zero-know… | 95 | 2116 | active |
| smartwalle/alipay A Go SDK for integrating with the Alipay payment platform, supporting both public key certificate and plain public key signing/verification… | 75 | 2113 | active |
| paragonie/random_compat A PHP 5.x polyfill providing the random_bytes() and random_int() CSPRNG functions that were introduced in PHP 7. It fails with an exception… | 54 | 8154 | maintenance |
| sparrowwallet/sparrow Sparrow is a free, open-source desktop Bitcoin wallet application built in Java with a focus on security, privacy, and transparency. It sup… | 98 | 2106 | active |
| klauspost/reedsolomon A pure Go library implementing Reed-Solomon erasure coding with high performance (over 1GB/s per CPU core), including a Leopard implementat… | 94 | 2091 | active |
| Keats/jsonwebtoken A Rust library for creating and decoding JSON Web Tokens (JWTs) in a strongly typed way, supporting HS256/384/512, RS256/384/512, PS256/384… | 75 | 2089 | active |
| vvb2060/KeyAttestation An Android app for generating, parsing, and verifying Android key and ID attestation data. It performs self-testing locally with no network… | 43 | 2088 | active |
| rust-random/rand Rand is a set of Rust crates providing random number generation, including a standard RNG trait, fast pseudo-random and cryptographically-s… | 99 | 2068 | stable |
| CorentinTh/enclosed Enclosed is a minimalistic self-hostable web application for sharing end-to-end encrypted notes and file attachments. Notes are encrypted c… | 69 | 2066 | active |
| Leon406/ToolsFx ToolsFx is a cross-platform desktop cryptography toolbox built with Kotlin. It bundles encoding/decoding, hash and MAC computation, symmetr… | 73 | 2048 | active |
| mcu-tools/mcuboot MCUboot is a secure bootloader for 32-bit microcontrollers that defines common infrastructure for bootloaders and flash layout, enabling se… | 80 | 2045 | stable |
| kaikramer/keystore-explorer KeyStore Explorer is a free, open-source Java desktop application that provides a graphical interface replacing the keytool and jarsigner c… | 88 | 2042 | active |
| iden3/snarkjs A JavaScript and pure WebAssembly implementation of zkSNARK schemes including Groth16, PLONK, and FFLONK. It provides all tooling for gener… | 77 | 2036 | active |
| PlakarKorp/plakar Plakar is an open-source backup engine written in Go that creates encrypted, deduplicated, independently verifiable snapshots of files, dat… | 96 | 2032 | active |
| jkroepke/helm-secrets helm-secrets is a Helm plugin that transparently encrypts and decrypts Helm value files using sops, allowing secrets to be safely stored in… | 95 | 2025 | active |
| Tencent/soter TENCENT SOTER is a biometric authentication standard and platform for Android, developed by Tencent and used in WeChat fingerprint payment.… | 53 | 2025 | active |
| attr-encrypted/attr_encrypted A Ruby gem that generates attr_accessors which transparently encrypt and decrypt attributes on any Ruby class. It integrates with ActiveRec… | 46 | 2018 | active |
| holepunchto/hyperdrive Hyperdrive is a JavaScript library implementing a secure, real-time distributed file system built on Hypercore and Hyperbee. It provides a … | 82 | 2016 | active |
| RetroShare/RetroShare RetroShare is a free, open-source, cross-platform, decentralized Friend-to-Friend (F2F) communication platform built in C++ with Qt. It pro… | 67 | 2012 | active |
| EgeBalci/sgn SGN is a polymorphic binary encoder that encodes shellcode using an additive feedback loop similar to an LFSR, producing statically undetec… | 91 | 2003 | active |
| chris2511/xca XCA is a cross-platform desktop GUI application for creating and managing X.509 certificates, certificate requests, RSA/DSA/EC private keys… | 68 | 2003 | active |
| jstedfast/MimeKit MimeKit is a C#/.NET library for creating and parsing MIME email messages, with support for S/MIME, OpenPGP, DKIM, ARC, TNEF, and Unix mbox… | 76 | 2000 | stable |
| bcrypt-ruby/bcrypt-ruby bcrypt-ruby is a Ruby binding to the OpenBSD bcrypt() password hashing algorithm, provided as a gem with a native C extension. It lets deve… | 82 | 1994 | stable |
| not-an-aardvark/lucky-commit A Rust CLI tool that amends git commits with whitespace until the commit hash starts with a desired prefix (default '0000000'). It uses GPU… | 41 | 1985 | active |
| quickfix/quickfix QuickFIX is a free, open-source C++ implementation of the FIX (Financial Information eXchange) protocol, serving as a full-featured messagi… | 75 | 1982 | stable |
| GrapheneOS/hardened_malloc hardened_malloc is a security-focused general purpose memory allocator implementing the malloc API with extensive hardening against heap co… | 77 | 1975 | active |
| cossacklabs/themis Themis is a cross-platform, high-level cryptographic library providing ready-made building blocks for secure data storage, encrypted messag… | 76 | 1973 | stable |
| MichaelGrafnetter/DSInternals DSInternals is a PowerShell module and .NET framework for working with Active Directory internals, including offline NTDS.DIT database pars… | 92 | 1967 | active |
| openlibrecommunity/olcrtc olcRTC is an encrypted TCP-over-WebRTC tunnel written in Go that disguises traffic as ordinary video calls on whitelisted meeting services … | 58 | 1957 | active |
| guofei9987/text_blind_watermark A Python library that embeds invisible blind watermarks into plain text without changing its appearance or readability, using a password-pr… | 41 | 1956 | active |
| Apptainer Apptainer (formerly Singularity) is an open-source container platform designed for secure, portable, and reproducible containers on shared … | 93 | 1949 | active |
| petertodd/python-bitcoinlib A Python 3 library providing a low-level, ground-up interface to Bitcoin data structures and protocol internals, including transactions, sc… | 28 | 1948 | active |
| MetacoSA/NBitcoin NBitcoin is the most complete Bitcoin library for the .NET framework, implementing all relevant Bitcoin Improvement Proposals (BIPs) and pr… | 76 | 1941 | stable |
| vxunderground/VX-API VX-API is a C++ collection of functions implementing malicious functionality to aid in malware development, maintained by vx-underground. I… | 32 | 1938 | active |
| Aorimn/dislocker Dislocker is a FUSE-based driver and library that reads and writes Windows BitLocker-encrypted partitions (including BitLocker-To-Go) from … | 76 | 1929 | stable |
| OP-TEE/optee_os OP-TEE Trusted OS is the secure-world operating system implementation of the OP-TEE project, running on ARM TrustZone-enabled hardware. It … | 77 | 1927 | active |
| dchest/tweetnacl-js TweetNaCl.js is a JavaScript port of the TweetNaCl/NaCl cryptographic library, providing high-level APIs for secret-key and public-key auth… | 39 | 1921 | stable |
| xrpcommunity/XRP-community-wallet A non-custodial, open-source web wallet for XRP Ledger and EVM networks, built by the community. Keys and seed phrases are encrypted and st… | 75 | 1920 | active |
| dchapyshev/aspia Aspia is a free open-source remote desktop application with file transfer, remote terminal, system information, text chat, and video record… | 66 | 1920 | active |
| hackerschoice/gsocket Global Socket (gsocket) is a C-based toolkit that lets two machines behind NAT or firewalls establish secure, end-to-end encrypted TCP conn… | 67 | 1918 | active |
| starkware-libs/cairo Cairo is a Turing-complete programming language for writing provable programs, implemented as a compiler toolchain written in Rust. It comp… | 97 | 1902 | active |
| tgalal/yowsup Yowsup is a Python library that implements the WhatsApp protocol, enabling developers to build custom applications and clients that communi… | 23 | 7172 | maintenance |
| meganz/MEGAsync MEGA Desktop Application (MEGAsync) is an installable desktop client that automatically synchronizes folders between your computer and your… | 92 | 1890 | active |
| Sathvik-Rao/ClipCascade ClipCascade is a lightweight, open-source utility that automatically syncs the clipboard across multiple devices without any key press. It … | 75 | 1880 | active |
| Zokrates/ZoKrates ZoKrates is a toolbox for zkSNARKs on Ethereum, providing a high-level domain-specific language for writing verifiable off-chain programs a… | 23 | 1872 | active |
| cake-tech/cake_wallet Cake Wallet is an open-source, noncustodial multi-currency cryptocurrency wallet supporting Monero, Bitcoin, Ethereum, Litecoin, Solana, an… | 98 | 1871 | active |
| meganz/android The official MEGA Android client, a fully-featured mobile app for accessing MEGA's end-to-end encrypted cloud storage. It is a large Kotlin… | 93 | 1869 | active |
| sniptt-official/ots OTS is a Go CLI tool for sharing end-to-end encrypted secrets (API keys, passwords, signing secrets) via one-time URLs. Secrets are destroy… | 36 | 1845 | active |
| mailvelope/mailvelope Mailvelope is a browser extension for Chrome and Firefox that adds OpenPGP end-to-end email encryption to arbitrary webmail providers. It u… | 85 | 1838 | active |
| hacl-star/hacl-star HACL* is a formally verified cryptographic library written in F* (Low*) and compiled to efficient standalone C code, covering algorithms li… | 62 | 1837 | active |
| seedvault-app/seedvault Seedvault is an open-source backup application for the Android Open Source Project that backs up and restores app data, with encryption via… | 76 | 1835 | active |
| lavabit/magma Magma is an encrypted email server daemon written in C, providing SMTP, POP, IMAP, and HTTP protocol support along with a bundled webmail s… | 37 | 1830 | active |
| nilsteampassnet/TeamPass TeamPass is a free, self-hosted collaborative password manager written in PHP/MySQL, offering folder-level access control, AES-256-GCM auth… | 95 | 1823 | active |
| nix-community/lanzaboote Lanzaboote is Rust tooling that brings UEFI Secure Boot and Measured Boot support to NixOS. Its lzbt tool signs boot components, builds Uni… | 84 | 1818 | active |
| trezor/trezor-firmware The official open-source firmware monorepo for Trezor hardware wallets, containing firmware for Trezor One and Trezor T/Safe devices, a sta… | 77 | 1813 | active |
| deltachat/deltachat-android Delta Chat Android is the official Android client for Delta Chat, a decentralized private messenger that runs over email infrastructure usi… | 99 | 1811 | active |
| redsolution/xabber-android Xabber is an open-source XMPP (Jabber) chat client for Android, written in Java and licensed under GPLv3. It supports multiple accounts, en… | 51 | 1810 | active |
| core-lib/xjar XJar is a Java library and Maven-integrated tool that encrypts Spring Boot and plain JAR files (e.g., with AES) and provides a custom class… | 23 | 1807 | active |
| inference-labs-inc/inference-network Inference Network is a Proof of Inference system built on EigenLayer that provides trustless verification of AI inference results via Solid… | 49 | 1799 | active |
| libtom/libtomcrypt LibTomCrypt is a comprehensive, modular and portable cryptographic toolkit written in C, providing block ciphers, hash functions, chaining … | 66 | 1788 | stable |
| fulldecent/system-bus-radio A C program that transmits AM radio signals from computers and phones that lack radio transmitting hardware by generating precisely timed e… | 55 | 6697 | maintenance |
| dfinity/ic The source code for the Internet Computer blockchain protocol, including the replica software run by node providers. It implements consensu… | 95 | 1785 | active |
| x011/smtp-tunnel-proxy A Python-based covert tunneling tool that disguises TCP traffic as SMTP email sessions to evade Deep Packet Inspection firewalls. It expose… | 42 | 1782 | active |
| cs01/termpair TermPair is a Rust-based tool that lets you share and control a terminal from a browser with end-to-end encryption. A single static binary … | 80 | 1778 | active |
| andrivet/ADVobfuscator ADVobfuscator is a C++20 header-only library that obfuscates and encrypts strings and data blocks at compile time using metaprogramming, wi… | 73 | 1772 | active |
| etesync/server The Etebase (EteSync 2.0) server, a Django-based backend that lets you self-host end-to-end encrypted synchronization of contacts, calendar… | 32 | 1766 | stable |
| SpatiumPortae/portal Portal is a command-line file transfer utility for sending files and folders between any two computers. It uses PAKE2 end-to-end encryption… | 23 | 1766 | active |
| mpdavis/python-jose python-jose is a Python implementation of the JOSE (JavaScript Object Signing and Encryption) standards, including JWS, JWE, JWK, and JWT. … | 60 | 1756 | stable |
| markqvist/Sideband Sideband is an end-to-end encrypted, infrastructure-less LXMF messaging and LXST telephony client for Android, Linux, macOS and Windows, bu… | 96 | 1753 | active |
| orhun/gpg-tui gpg-tui is a terminal user interface for GnuPG written in Rust, built on tui-rs and GPGME bindings. It simplifies key management operations… | 81 | 1753 | active |
| 19MisterX98/SeedcrackerX SeedCrackerX is a Fabric mod for Minecraft that reverse-engineers the world seed of a server from in-game structural and terrain data. It i… | 84 | 1740 | active |
| wiire-a/pixiewps Pixiewps is a C command-line utility that brute-forces Wi-Fi Protected Setup (WPS) PINs offline, exploiting low- or non-entropy software im… | 57 | 1740 | active |
| sigalor/whatsapp-web-reveng A reverse-engineered description and Node.js re-implementation of the WhatsApp Web API, communicating over WebSockets with the same encrypt… | 32 | 6491 | maintenance |
| succinctlabs/sp1 SP1 is a zero-knowledge virtual machine (zkVM) that proves the correct execution of arbitrary programs compiled to RISC-V, written in Rust … | 93 | 1732 | active |
| Consensys/gnark gnark is a fast zk-SNARK library in Go offering a high-level API to define circuits, compile them to constraint systems, and generate/verif… | 91 | 1731 | active |
| xbrowsersync/app xBrowserSync is a free, privacy-focused tool for syncing browser data (bookmarks, settings, etc.) between different browsers and devices. T… | 68 | 1728 | active |
| theupdateframework/python-tuf Python reference implementation of The Update Framework (TUF), a CNCF-graduated specification for securing software update systems against … | 83 | 1724 | stable |