Ross ROSS = Recommend OSS · open-source software intelligence for agents

infobyte/faraday

Open Source Vulnerability Management Platform observed · 2026-08-28

github.com/infobyte/faraday · homepage · Python · GPL-3.0 (copyleft) observed · 2026-08-28

Health v2 · maintenance only

98/100

  • Activity 98
  • Release rhythm 98
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 28
  • age_days: 4684
  • days_rel: 13
  • days_push: 13
  • n_releases_24m: 24

Full methodology

Adoption not part of the score

6695 stars · 1067 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

Faraday is an open-source vulnerability management platform that aggregates, normalizes, and deduplicates findings from over 90 security tools (Nmap, Nessus, Burp, Metasploit, ZAP, etc.) into a centralized, multiuser web dashboard. It supports deployment via Docker, PyPI, or native packages and integrates into CI/CD pipelines for continuous scanning.

Use cases

  • centralize vulnerability scan results from multiple security tools
  • manage pentest findings across a security team
  • track and prioritize CVEs and remediation efforts
  • integrate vulnerability scanning into CI/CD pipelines
  • run and aggregate nmap, nessus, and burp scans in one place
  • build a self-hosted vulnerability management dashboard
  • automate continuous scanning and reporting for security teams

When to choose

  • you need to aggregate and deduplicate findings from many different security scanners
  • your security team collaborates on pentests and needs shared, multiuser tracking
  • you want a self-hosted alternative to commercial vulnerability management platforms
  • you need to embed vulnerability scanning into CI/CD pipelines

When to avoid

  • you only need a single scanner rather than a management layer over many tools
  • you want a lightweight SaaS with zero infrastructure to maintain
  • your team has no capacity to operate a server with PostgreSQL and Docker

Facets

application · maturity active

vulnerability-scanning security monitoring analytics workflow-automation api-framework security penetration-testing developer-tools self-hosted python cli vulnerability-management pentesting devsecops scanner-aggregation multiuser cve-tracking nessus nmap burpsuite ci-cd-integration devops linux docker web-server

7 sources

Member repositories

RepositoryRoleHealth v2
infobyte/faradaymain98

For agents

markdown · JSON · MCP: product_card(name="infobyte/faraday")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem