head to head · open source
lighthouse vs ThreatMapper
lighthouse has 30,785 GitHub stars, 9,765 forks, 470 open issues and last shipped yesterday. ThreatMapper has 5,321 stars, 631 forks, 144 open issues and last shipped 4 months ago. lighthouse leads on adoption by 479% (30,785 vs 5,321 stars). lighthouse is written in JavaScript under Apache-2.0; ThreatMapper is written in TypeScript under Apache-2.0. lighthouse has attracted 32% as many forks as stars, ThreatMapper 12%. lighthouse was the more recently maintained of the two, and both are self-hostable with no licence fee.
Two open source projects, one decision. Both are free and self-hostable — the differences are community size, license terms, language stack and release pace.
← all 8884 open source comparisons
Side by side
| lighthouse | ThreatMapper | |
|---|---|---|
| GitHub stars | ★ 31K | ★ 5.3K |
| License | Apache-2.0 | Apache-2.0 |
| Written in | JavaScript | TypeScript |
| Last push | 2026-09-17 | 2026-06-01 |
| Forks | ⑂ 9.8K | ⑂ 631 |
| Self-hosting | Yes | Yes |
| Data ownership | Your server | Your server |
pick lighthouse if
- You weight community size — 31K stars and counting
- You want the Apache-2.0 license terms
- Your stack matches JavaScript
- You value the larger contributor base for long-term maintenance
pick ThreatMapper if
- You want the ThreatMapper feature set and don't need the biggest community
- You prefer the Apache-2.0 license terms
- Your stack matches TypeScript
- You evaluated both and ThreatMapper fits your workflow better
About lighthouse
Lighthouse is an open source, automated auditing tool for web applications and web pages. It analyzes a target URL and collects modern performance metrics alongside insights into developer best practices, producing a structured report that scores and explains what it finds. The project lives in the JavaScript ecosystem, is distributed under the Apache 2.0 license, and is maintained under the GoogleChrome organization. It has been developed for roughly eleven years and is published to npm as the lighthouse package.
read the full lighthouse overview →
About ThreatMapper
ThreatMapper is an open source Cloud Native Application Protection Platform for runtime threat management and attack path enumeration. It operates in the cloud native security ecosystem and targets containers, Kubernetes, serverless platforms, cloud infrastructure, and on premises workloads. The project is Apache 2.0 licensed and written in TypeScript.
read the full ThreatMapper overview →
More in Business Software
Related comparisons
More Compliance & Risk Management projects
Compare either of these against the rest of the Compliance & Risk Management field.
Frequently asked questions
Is lighthouse or ThreatMapper more popular?
lighthouse has 30,785 GitHub stars and ThreatMapper has 5,321. lighthouse has the larger community by that measure.
Are lighthouse and ThreatMapper free?
Both are open source. lighthouse is licensed under Apache-2.0 and ThreatMapper under Apache-2.0. Neither carries a licence fee.
What is the difference between lighthouse and ThreatMapper?
lighthouse is written in JavaScript and ThreatMapper in TypeScript. The practical differences are community size, licence terms, language stack and release cadence — all compared in the table above.
Which should I choose, lighthouse or ThreatMapper?
Choose lighthouse if you want the larger community (30,785 stars) or its Apache-2.0 licence terms. Choose ThreatMapper if its feature set, stack or Apache-2.0 licence fits better. Both are self-hostable.