head to head · open source

garak vs Dark-Moon

garak has 9,327 GitHub stars, 1,298 forks, 429 open issues and last shipped 6 days ago. Dark-Moon has 957 stars, 159 forks, 3 open issues and last shipped yesterday. garak leads on adoption by 875% (9,327 vs 957 stars). garak is written in Python under Apache-2.0; Dark-Moon is written in Python under GPL-3.0. garak has attracted 14% as many forks as stars, Dark-Moon 17%. Dark-Moon was the more recently maintained of the two, and both are self-hostable with no licence fee. The two share 1 topic tag (llm-security), so they are genuine substitutes rather than adjacent tools.

Two open source projects, one decision. Both are free and self-hostable — the differences are community size, license terms, language stack and release pace.

garak ★ 9.3K Dark-Moon ★ 957 category AI & Machine Learning

← all 20902 open source comparisons

Side by side

garak Dark-Moon
GitHub stars ★ 9.3K ★ 957
License Apache-2.0 GPL-3.0
Written in Python Python
Last push 2026-09-16 2026-09-21
Forks ⑂ 1.3K ⑂ 159
Self-hosting Yes Yes
Data ownership Your server Your server

pick garak if

  • You weight community size — 9.3K stars and counting
  • You want the Apache-2.0 license terms
  • Your stack matches Python
  • You value the larger contributor base for long-term maintenance

full garak profile →

pick Dark-Moon if

  • You want the Dark-Moon feature set and don't need the biggest community
  • You prefer the GPL-3.0 license terms
  • Your stack matches Python
  • You evaluated both and Dark-Moon fits your workflow better

full Dark-Moon profile →

About garak

garak is a free, Apache 2.0 command line vulnerability scanner for large language models that probes generative AI systems for hallucination, data leakage, prompt injection, misinformation, toxicity generation, and jailbreaks, and it is aimed at security engineers, red teamers, and AI developers who need to test the models they ship.

read the full garak overview →

About Dark-Moon

DarkMoon is a self hosted, GPL 3.0 autonomous AI penetration testing platform for security teams, red teams and AI security engineers who point it at infrastructure they are authorised to test and let a local or cloud model run the whole assessment unattended, returning a working exploit as proof for every finding.

read the full Dark-Moon overview →

More in AI & Machine Learning

OpenClaw ★ 390K Hermes Agent ★ 248K Ollama ★ 181K Dify ★ 157K Open WebUI ★ 153K langchain ★ 147K

Related comparisons

strix vs garak strix vs shannon strix vs skillspector strix vs ifixai strix vs codex-security strix vs ai-infra-guard strix vs giskard-oss strix vs agentic-bug-hunter openclaw vs hermes-agent openclaw vs opencode openclaw vs n8n openclaw vs open-webui openclaw vs comfyui openclaw vs odysseus openclaw vs lobechat openclaw vs anythingllm openclaw vs ollama ollama vs llama-cpp ollama vs vllm ollama vs odysseus ollama vs gpt4all ollama vs llama-index ollama vs localai open-webui vs gpt4all

More AI Security & Privacy projects

Compare either of these against the rest of the AI Security & Privacy field.

garak vs strix garak vs shannon garak vs SkillSpector garak vs iFixAi garak vs codex-security garak vs AI-Infra-Guard garak vs giskard-oss garak vs Agentic-Bug-Hunter garak vs nono garak vs CyberStrike garak vs AiSOC garak vs pentest-ai-agents

Frequently asked questions

Is garak or Dark-Moon more popular?

garak has 9,327 GitHub stars and Dark-Moon has 957. garak has the larger community by that measure.

Are garak and Dark-Moon free?

Both are open source. garak is licensed under Apache-2.0 and Dark-Moon under GPL-3.0. Neither carries a licence fee.

What is the difference between garak and Dark-Moon?

garak is written in Python and Dark-Moon in Python. The practical differences are community size, licence terms, language stack and release cadence — all compared in the table above.

Which should I choose, garak or Dark-Moon?

Choose garak if you want the larger community (9,327 stars) or its Apache-2.0 licence terms. Choose Dark-Moon if its feature set, stack or GPL-3.0 licence fits better. Both are self-hostable.