# aquasecurity/cloudsploit

Cloud Security Posture Management (CSPM)

Repository: https://github.com/aquasecurity/cloudsploit
Canonical: https://ross.abutalabs.com/products/cloudsploit
Homepage: https://cloud.aquasec.com/signup
Language: JavaScript
License: GPL-3.0
License Family: copyleft
Topics: aws, security, security-audit, cloud, azure, cspm, aqua, gcp, oci, oracle, alibaba
Last push: 2026-07-28T11:32:15+00:00

## Health v2 (maintenance only)
Score: 72/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 94, release rhythm 28, longevity 100
- inputs: {"age_days": 4083, "days_push": 36, "days_rel": 656, "gap_med": 52, "n_releases_24m": 2}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 3768, forks 750 (observed 2026-08-28T04:08:18.102674+00:00)

## What it is
CloudSploit by Aqua is an open-source Cloud Security Posture Management (CSPM) tool that scans cloud infrastructure accounts for misconfigurations and security risks. It supports AWS, Azure, GCP, Oracle Cloud Infrastructure, Alibaba Cloud, and GitHub, with compliance mapping for HIPAA, PCI, and CIS Benchmarks.

## Use cases
- audit my AWS account for security misconfigurations
- check Azure subscription against CIS benchmarks
- run PCI compliance scans on cloud infrastructure
- detect security risks in GCP projects
- scan multiple cloud accounts for posture issues
- generate compliance reports in CSV or JSON
- self-host a CSPM scanner for cloud accounts

## When to choose
- you need open-source, self-hosted cloud security posture scanning
- you want compliance mapping to HIPAA, PCI, or CIS benchmarks across multiple clouds
- you prefer a lightweight Node.js CLI or Docker-based scanner over a commercial CSPM platform

## When to avoid
- you need real-time runtime threat detection or container workload scanning
- you require a fully managed SaaS CSPM with dashboards and alerting
- you need scanning for on-premises or non-cloud infrastructure

## Facets
- artifact type: cli-tool
- maturity: active
- function: security, vulnerability-scanning, monitoring, cli, developer-tools
- domain: security, cloud-computing, infrastructure-as-code, legal
- platform: cli, cross-platform
- tags: cspm, cloud-security, security-audit, aws, azure, gcp, oracle-cloud, alibaba-cloud, compliance, cis-benchmarks, hipaa, pci, misconfiguration-detection, devops, nodejs, docker

## Member repositories
- aquasecurity/cloudsploit (main) score 72

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:08:18.102674+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-29T18:27:54.159849+00:00, confidence not recorded.
  - readme: https://github.com/aquasecurity/cloudsploit (fetched 2026-08-28T04:08:18.102674+00:00, sha 43634a5f00e3)
  - homepage: https://cloud.aquasec.com/signup (fetched 2026-08-29T09:22:55.605576+00:00, sha 5ea9d1751892)
- Data as of 2026-08-30T08:39:29.467469+00:00.
