Ross ROSS = Recommend OSS · open-source software intelligence for agents

DefectDojo/django-DefectDojo

Open-Source Unified Vulnerability Management, DevSecOps & ASPM observed · 2026-08-28

github.com/DefectDojo/django-DefectDojo · homepage · HTML · BSD-3-Clause (permissive) observed · 2026-08-28

Health v2 · maintenance only

95/100

  • Activity 99
  • Release rhythm 87
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 6.0
  • age_days: 4213
  • days_rel: 9
  • days_push: 7
  • n_releases_24m: 117

Full methodology

Adoption not part of the score

4909 stars · 1940 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

DefectDojo is an open-source vulnerability management, DevSecOps, and ASPM platform built on Django. It aggregates findings from hundreds of security tools, deduplicates and triages vulnerabilities, tracks remediation, and generates reports.

Use cases

  • centralize vulnerability findings from multiple security scanners
  • deduplicate and triage security findings across tools
  • track remediation of application security vulnerabilities
  • generate security reports for penetration tests
  • build a DevSecOps pipeline with automated security tooling
  • manage application security posture across a portfolio
  • import and normalize scan reports from security tools

When to choose

  • you need a unified vulnerability management platform that aggregates results from many scanners
  • your security team spends too much time manually triaging and reporting findings
  • you want a self-hosted, open-source alternative to commercial ASPM tools
  • you need deduplication and metrics across repeated scans and engagements

When to avoid

  • you only need a single vulnerability scanner rather than a management layer
  • you want a lightweight CI-only security gate without a web platform
  • you cannot operate a Django application with a database and container infrastructure

Facets

application · maturity active

security monitoring analytics workflow-automation api-framework self-hosted security backend python self-hosted vulnerability-management devsecops aspm appsec vulnerability-deduplication security-orchestration django owasp penetration-testing-reports security-reporting devops automation docker kubernetes web-server linux

10 sources

Member repositories

RepositoryRoleHealth v2
DefectDojo/django-DefectDojomain95

For agents

markdown · JSON · MCP: product_card(name="DefectDojo/django-DefectDojo")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem