# tirrenotechnologies/tirreno

tirreno is a security framework. Event tracking, threat detection, and risk scoring for any product.

Repository: https://github.com/tirrenotechnologies/tirreno
Canonical: https://ross.abutalabs.com/products/tirreno
Homepage: https://www.tirreno.com
Language: PHP
License: AGPL-3.0
License Family: copyleft
Topics: fraud-detection, fraud-prevention, intelligence, antispam, fraud, bot-management, bot-detection, application-monitoring, log-analysis, user-monitoring, security-analytics, php-project, audit-trails, audit-logs, security-framework, runtime-security, cyber-security, php-scripts, cybersecurity-projects, banking
Last push: 2026-08-14T19:22:25+00:00

## Health v2 (maintenance only)
Score: 83/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 97, release rhythm 86, longevity 45
- inputs: {"age_days": 633, "days_push": 19, "days_rel": 18, "gap_med": 33.5, "n_releases_24m": 15}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1503, forks 179 (observed 2026-08-28T04:04:54.586288+00:00)

## What it is
tirreno is an open-source, self-hosted security framework written in PHP/PostgreSQL that provides event tracking, threat detection, and risk scoring for applications. It ingests events via SDKs and API, and offers a real-time dashboard, rule engine, review queue, and field audit trails to detect fraud, abuse, and account threats.

## Use cases
- detect account takeover and credential stuffing
- prevent payment fraud and promo abuse in e-commerce
- monitor insider threats and audit field changes
- detect bots and content spam
- score user risk and flag suspicious accounts for review
- add a security layer to self-hosted or legacy apps
- track multi-accounting and fake account registration

## When to choose
- you need self-hosted, data-sovereign fraud and abuse detection inside your application
- you want a quick-to-deploy security dashboard with preset rules for account threats
- you run a SaaS, marketplace, or fintech product needing risk scoring and review queues
- you need audit trails for compliance in air-gapped or internal apps

## When to avoid
- you need network-perimeter or infrastructure security like firewalls or SIEM replacement
- your stack cannot run PHP and PostgreSQL
- you require managed cloud hosting on the free community edition
- you need advanced features like SAML or SIEM feeds without a commercial license

## Facets
- artifact type: application
- maturity: active
- function: security, monitoring, analytics, logging, webhook, api-framework, self-hosted
- domain: security, web-development, fintech, e-commerce, self-hosted, analytics
- platform: php, self-hosted
- tags: fraud-detection, bot-detection, risk-scoring, threat-detection, account-takeover, audit-trail, antispam, rule-engine, user-monitoring, security-dashboard, docker, web-server, linux

## Member repositories
- tirrenotechnologies/tirreno (main) score 83

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:04:54.586288+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T04:32:50.794649+00:00, confidence not recorded.
  - readme: https://github.com/tirrenotechnologies/tirreno (fetched 2026-08-28T04:04:54.586288+00:00, sha fa6780dbb604)
  - homepage: https://www.tirreno.com (fetched 2026-08-29T11:37:43.905582+00:00, sha 8b4fa939c6d4)
  - site_page: https://www.tirreno.com/about (fetched 2026-08-29T11:37:43.917978+00:00, sha 84b1a1ab6357)
  - site_page: https://tirreno.com/devs (fetched 2026-08-29T11:37:43.914560+00:00, sha 142e0e26beca)
  - site_page: https://www.tirreno.com/pricing (fetched 2026-08-29T11:37:43.916209+00:00, sha 9806a41fd428)
- Data as of 2026-08-30T08:39:29.467469+00:00.
