Ross ROSS = Recommend OSS · open-source software intelligence for agents

prowler-cloud/prowler

Prowler is the world’s most widely used open-source cloud security platform that automates security and compliance across any cloud environment. observed · 2026-08-28

github.com/prowler-cloud/prowler · homepage · Python · Apache-2.0 (permissive) observed · 2026-08-28

Health v2 · maintenance only

95/100

  • Activity 99
  • Release rhythm 86
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 4.0
  • age_days: 3661
  • days_rel: 15
  • days_push: 7
  • n_releases_24m: 115

Full methodology

Adoption not part of the score

14687 stars · 2334 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

Prowler is an open-source cloud security platform that performs security best-practice assessments, audits, continuous monitoring, hardening, and forensics readiness across AWS, Azure, GCP, Kubernetes, and other providers. It ships as a CLI scanner and a self-hostable web app/API, with hundreds of checks mapped to compliance frameworks like CIS, NIST, PCI-DSS, GDPR, and HIPAA.

Use cases

  • audit my AWS account against CIS benchmarks
  • scan cloud accounts for security misconfigurations
  • monitor cloud compliance with GDPR and PCI-DSS continuously
  • run security best practice assessments on Azure and GCP
  • generate compliance evidence for audits
  • harden cloud IAM configurations
  • prepare for incident response and forensics readiness

When to choose

  • you need multi-cloud security posture management (CSPM) without licensing costs
  • you want automated compliance mapping to CIS, NIST, HIPAA, SOC2 and custom frameworks
  • you prefer a CLI-first or self-hosted scanning tool
  • you need continuous monitoring with integrations into your existing workflow

When to avoid

  • you need runtime workload or container vulnerability scanning rather than cloud configuration auditing
  • you want a fully managed SaaS with enterprise support and are fine paying for it
  • your environment is entirely on-premises with no cloud providers

Facets

cli-tool · maturity active

security vulnerability-scanning monitoring developer-tools security cloud-computing legal python cli self-hosted cross-platform cspm cloud-security compliance-auditing cis-benchmark aws azure gcp devsecops forensics hardening devops docker

6 sources

Member repositories

RepositoryRoleHealth v2
prowler-cloud/prowlermain95

For agents

markdown · JSON · MCP: product_card(name="prowler-cloud/prowler")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem