head to head · open source

kong vs kics

kong has 44,147 GitHub stars, 5,210 forks, 200 open issues and last shipped 11 days ago. kics has 2,700 stars, 381 forks, 312 open issues and last shipped yesterday. kong leads on adoption by 1,535% (44,147 vs 2,700 stars). kong is written in Lua under Apache-2.0; kics is written in Open Policy Agent under Apache-2.0. kong has attracted 12% as many forks as stars, kics 14%. kics was the more recently maintained of the two, and both are self-hostable with no licence fee.

Two open source projects, one decision. Both are free and self-hostable — the differences are community size, license terms, language stack and release pace.

kong ★ 44K kics ★ 2.7K category Infrastructure & Operations

← all 8884 open source comparisons

Side by side

kong kics
GitHub stars ★ 44K ★ 2.7K
License Apache-2.0 Apache-2.0
Written in Lua Open Policy Agent
Last push 2026-09-07 2026-09-17
Forks ⑂ 5.2K ⑂ 381
Self-hosting Yes Yes
Data ownership Your server Your server

pick kong if

  • You weight community size — 44K stars and counting
  • You want the Apache-2.0 license terms
  • Your stack matches Lua
  • You value the larger contributor base for long-term maintenance

full kong profile →

pick kics if

  • You want the kics feature set and don't need the biggest community
  • You prefer the Apache-2.0 license terms
  • Your stack matches Open Policy Agent
  • You evaluated both and kics fits your workflow better

full kics profile →

About kong

Kong (also known as Kong Gateway) is an open source, cloud native, platform agnostic API, LLM, and MCP gateway, licensed under Apache 2.0, built for platform, DevOps, and AI engineering teams that need a single high performance layer to route, secure, and observe both conventional API traffic and agentic LLM traffic.

read the full kong overview →

About kics

KICS is an open source security scanner for infrastructure as code projects. The project name stands for Keeping Infrastructure as Code Secure, and the repository describes it as a tool for finding security vulnerabilities, compliance issues, and infrastructure misconfigurations early in the development cycle. It is published by Checkmarx under the Apache 2.0 license and is associated with the cloud native, DevSecOps, and application security ecosystems. The repository also lists topics such as infrastructure as code, security, and vulnerability detection.

read the full kics overview →

More in Infrastructure & Operations

Immich ★ 114K Uptime Kuma ★ 91K worldmonitor ★ 87K mall ★ 85K NetData ★ 81K Elasticsearch ★ 78K

Related comparisons

kong vs trivy kong vs opentofu kong vs jenkins kong vs pulumi kong vs floci kong vs argo-cd kong vs sops trivy vs opentofu uptime-kuma vs worldmonitor uptime-kuma vs netdata uptime-kuma vs grafana worldmonitor vs netdata worldmonitor vs grafana netdata vs grafana uptime-kuma vs huginn worldmonitor vs huginn immich vs paperless-ngx immich vs ceph immich vs filestash immich vs garage immich vs storj immich vs alarik immich vs spinifex paperless-ngx vs ceph

More Cloud Infrastructure Management projects

Compare either of these against the rest of the Cloud Infrastructure Management field.

kong vs trivy kong vs OpenTofu kong vs jenkins kong vs Pulumi kong vs floci kong vs argo-cd kong vs sops kong vs wtf kong vs dagger kong vs task kong vs aws-cdk kong vs infracost

Frequently asked questions

Is kong or kics more popular?

kong has 44,147 GitHub stars and kics has 2,700. kong has the larger community by that measure.

Are kong and kics free?

Both are open source. kong is licensed under Apache-2.0 and kics under Apache-2.0. Neither carries a licence fee.

What is the difference between kong and kics?

kong is written in Lua and kics in Open Policy Agent. The practical differences are community size, licence terms, language stack and release cadence — all compared in the table above.

Which should I choose, kong or kics?

Choose kong if you want the larger community (44,147 stars) or its Apache-2.0 licence terms. Choose kics if its feature set, stack or Apache-2.0 licence fits better. Both are self-hostable.