function: vulnerability-scanning
447 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| WyAtu/Perun Perun is a Python-based network asset vulnerability scanner and scanning framework designed for penetration testers and red teams, primaril… | 32 | 1051 | abandoned |
| utkusen/leviathan Leviathan is a Python-based mass audit toolkit that combines masscan, ncrack, and DSSS to discover services, brute-force credentials, detec… | 10 | 1041 | abandoned |
| MicrosoftEdge/static-code-scan A deprecated Node.js static code scanner from Microsoft Edge (formerly modern.IE) that analyzes a URL's HTML, CSS, and JavaScript for issue… | 10 | 1038 | abandoned |
| AndroidVTS/android-vts An on-device Android app that scans a device for known vulnerabilities such as kernel and framework bugs (e.g., Towelroot, Master Keys). It… | 23 | 1034 | abandoned |
| usestrix/strix Strix is an open-source AI penetration testing tool that deploys autonomous agents to find, validate, and fix application vulnerabilities. … | 84 | 58564 | active |
| promptfoo/promptfoo Promptfoo is an open-source CLI and library for evaluating and red-teaming LLM applications, prompts, agents, and RAG pipelines. It support… | 92 | 24603 | active |
| Wazuh Wazuh is a free, open source security platform that unifies XDR and SIEM capabilities for threat prevention, detection, and response across… | 98 | 16691 | stable |
| Semgrep Semgrep is a fast, open-source static analysis tool that searches code, finds bugs, and enforces secure coding standards using rules that l… | 95 | 16409 | active |
| google/oss-fuzz OSS-Fuzz is Google's free continuous fuzzing service for open source software, combining fuzzing engines like libFuzzer, AFL++, and Honggfu… | 77 | 12594 | active |
| 0x4m4/hexstrike-ai HexStrike AI is an MCP server that bridges LLM agents (Claude, GPT, Copilot) with 150+ cybersecurity tools for autonomous penetration testi… | 61 | 11381 | active |
| six2dez/reconftw reconFTW is an open-source (MIT) automated reconnaissance framework written in Shell that orchestrates 80+ security tools to perform full r… | 86 | 8025 | active |
| simplifaisoul/osiris OSIRIS is an open-source, real-time global intelligence (OSINT) dashboard that aggregates live flight tracking, maritime, CCTV, seismic, fi… | 58 | 7992 | active |
| superagent-ai/superagent Superagent is an open-source SDK and platform for securing AI applications and agents, offering runtime guardrails that block prompt inject… | 78 | 6719 | active |
| google/syzkaller syzkaller is an unsupervised coverage-guided kernel fuzzer originally built for the Linux kernel and now supporting FreeBSD, Fuchsia, gViso… | 77 | 6309 | active |
| aidlearning/AidLearning-FrameWork AidLux (originally AidLearning) is an AIoT development platform that runs a native Ubuntu Linux environment with GUI, deep learning tooling… | 70 | 5797 | active |
| gadievron/raptor RAPTOR is an autonomous offensive/defensive security research framework built on top of Claude Code, chaining static analysis, binary analy… | 66 | 3672 | active |
| crytic/echidna Echidna is a Haskell-based fuzzer for Ethereum smart contracts that performs property-based testing by generating sequences of contract cal… | 89 | 3170 | active |
| microsoft/restler-fuzzer RESTler is the first stateful REST API fuzzing tool, automatically testing cloud services through their REST APIs to find security and reli… | 71 | 2939 | active |
| google/osv.dev OSV (Open Source Vulnerabilities) is Google's open, distributed vulnerability database and triage service that aggregates security advisori… | 84 | 2901 | stable |
| sheeki03/tirith Tirith is a Rust-based terminal security tool that intercepts shell commands, pasted content, and files to block threats like homograph URL… | 78 | 2683 | active |
| cve-search/cve-search cve-search is a tool-set that imports CVE and CPE data into a local MongoDB to enable fast, private searching of known software vulnerabili… | 84 | 2642 | active |
| MegaManSec/SSH-Snake SSH-Snake is a self-propagating, file-less bash script that automatically discovers SSH private keys on a system, attempts to connect to re… | 10 | 2342 | active |
| lz520520/railgun Railgun is a GUI-based penetration testing tool that automates common tasks from manual pentesting experience. It integrates port scanning,… | 35 | 2289 | active |
| learnhouse/learnhouse LearnHouse is a next-generation open-source learning management system (LMS) for creating, sharing, and selling educational content. It com… | 99 | 2203 | active |
| nsonaniya2010/SubDomainizer SubDomainizer is a Python CLI tool that discovers hidden subdomains and secrets in webpages, external JavaScript files, GitHub, and local f… | 66 | 1886 | active |
| metlo-labs/metlo Metlo is an open-source API security platform that inventories API endpoints, detects malicious traffic in real time, and can automatically… | 38 | 1783 | active |
| quentinhardy/odat ODAT (Oracle Database Attacking Tool) is an open-source Python penetration testing tool for assessing the security of remote Oracle Databas… | 57 | 1776 | active |
| project-copacetic/copacetic Copa (Project Copacetic) is a Go CLI tool built on BuildKit that directly patches OS package vulnerabilities in container images without re… | 91 | 1700 | active |
| Pentest AI pentest-ai is an MIT-licensed local CLI and MCP server that turns Claude Code (or any LLM) into an offensive security assistant, pairing 50… | 80 | 1629 | active |
| guacsec/guac GUAC (Graph for Understanding Artifact Composition) is an OpenSSF incubating project that ingests software security metadata such as SBOMs,… | 90 | 1534 | active |
| akto-api-security/akto Akto is an open-source API and AI security platform that discovers and inventories APIs, AI agents, MCP servers, and LLM usage, then contin… | 94 | 1505 | active |
| Jackalope Jackalope is a customizable, coverage-guided fuzzer for black-box binaries built on the TinyInst instrumentation library by Google Project … | 77 | 1380 | active |
| ION28/BLUESPAWN BLUESPAWN is an open-source active defense and endpoint detection and response (EDR) tool for Windows. It helps blue teams detect, identify… | 69 | 1334 | active |
| stackrox/stackrox StackRox is a Kubernetes security platform that performs risk analysis of container environments, delivers visibility and runtime alerts, a… | 95 | 1306 | active |
| adminsyspro/proxcenter-ui ProxCenter is a self-hosted, open-core datacenter management platform that acts as a centralized control plane for Proxmox VE clusters and … | 83 | 1293 | active |
| CodeIntelligenceTesting/jazzer Jazzer is a coverage-guided, in-process fuzz testing engine for the JVM, based on libFuzzer. It integrates with JUnit 5 and build tools lik… | 86 | 1254 | active |
| BehiSecc/VibeSec-Skill VibeSec-Skill is an AI skill (prompt/instruction pack) that teaches LLM coding assistants like Claude Code, Cursor, Codex, Copilot, and Ant… | 46 | 1220 | active |
| Quitten/Autorize Autorize is a Burp Suite extension, written in Jython, that automatically detects authorization and authentication enforcement flaws in web… | 56 | 1169 | active |
| fuzzland/ityfuzz ItyFuzz is a blazing-fast bytecode-level hybrid fuzzer for EVM and MoveVM smart contracts that combines symbolic (concolic) execution with … | 55 | 1108 | active |
| GamehunterKaan/AutoPWN-Suite AutoPWN Suite is a Python-based automated vulnerability scanning and exploitation framework that wraps nmap for host discovery, version-bas… | 94 | 1094 | active |
| w-digital-scanner/w12scan w12scan is a self-hosted network asset discovery engine that aggregates scan results into a searchable web interface backed by Elasticsearc… | 23 | 1331 | maintenance |
| yhy0/github-cve-monitor A Python application that monitors GitHub every few minutes for newly published CVEs, security tool updates, and activity on watched reposi… | 32 | 1195 | maintenance |
| sh4hin/Androl4b AndroL4b is an Ubuntu MATE-based virtual machine preloaded with Android security, reverse engineering, and malware analysis tools such as R… | 32 | 1166 | maintenance |
| Abacus-Group-RTO/legion Legion is an open-source, semi-automated network penetration testing framework with a graphical interface, forked from Sparta. It orchestra… | 10 | 1057 | maintenance |
| quentinhardy/msdat MSDAT is an open-source Python penetration testing tool for remotely testing the security of Microsoft SQL Server databases. It supports cr… | 32 | 1016 | maintenance |
| aliasrobotics/cai Cybersecurity AI (CAI) is an open-source Python framework of specialized AI agents for offensive security tasks such as penetration testing… | 10 | 9810 | abandoned |
| yahoo/gryffin Gryffin is a large-scale web security scanning platform written in Go, built on a publisher-subscriber architecture for horizontal scaling.… | 10 | 2052 | abandoned |
← prev page 5 / 5