head to head · open source
trivy vs bunkerweb
trivy has 37,969 GitHub stars, 692 forks, 269 open issues and last shipped yesterday. bunkerweb has 10,973 stars, 642 forks, 170 open issues and last shipped yesterday. trivy leads on adoption by 246% (37,969 vs 10,973 stars). trivy is written in Go under Apache-2.0; bunkerweb is written in Python under AGPL-3.0. trivy has attracted 2% as many forks as stars, bunkerweb 6%. trivy was the more recently maintained of the two, and both are self-hostable with no licence fee. The two share 3 topic tags (devsecops, docker, kubernetes), so they are genuine substitutes rather than adjacent tools.
Two open source projects, one decision. Both are free and self-hostable — the differences are community size, license terms, language stack and release pace.
← all 8884 open source comparisons
Side by side
| trivy | bunkerweb | |
|---|---|---|
| GitHub stars | ★ 38K | ★ 11K |
| License | Apache-2.0 | AGPL-3.0 |
| Written in | Go | Python |
| Last push | 2026-09-17 | 2026-09-17 |
| Forks | ⑂ 692 | ⑂ 642 |
| Self-hosting | Yes | Yes |
| Data ownership | Your server | Your server |
pick trivy if
- You weight community size — 38K stars and counting
- You want the Apache-2.0 license terms
- Your stack matches Go
- You value the larger contributor base for long-term maintenance
pick bunkerweb if
- You want the bunkerweb feature set and don't need the biggest community
- You prefer the AGPL-3.0 license terms
- Your stack matches Python
- You evaluated both and bunkerweb fits your workflow better
About trivy
Trivy is an open source security scanner written in Go and released under the Apache 2.0 license. It is an Aqua Security open source project, hosted at trivy.dev, and it lives in the cloud native and DevSecOps ecosystem alongside container runtimes, Kubernetes clusters, and infrastructure as code tooling. The design separates two ideas: scanners, which describe the classes of security issue Trivy looks for, and targets, which describe where it looks. The README presents the project as a comprehensive and versatile scanner, and the topic list — containers, devsecops, docker, iac, infrastructure as code, kubernetes…
read the full trivy overview →
About bunkerweb
BunkerWeb is a next generation, open source, cloud native Web Application Firewall built as a full featured web server on top of NGINX, designed to make web services secure by default, and it is aimed at teams running web services on Linux, Docker, Swarm, or Kubernetes who want protection in place as a reverse proxy rather than assembled by hand.
read the full bunkerweb overview →
More in Infrastructure & Operations
Related comparisons
More Cloud Infrastructure Management projects
Compare either of these against the rest of the Cloud Infrastructure Management field.
Frequently asked questions
Is trivy or bunkerweb more popular?
trivy has 37,969 GitHub stars and bunkerweb has 10,973. trivy has the larger community by that measure.
Are trivy and bunkerweb free?
Both are open source. trivy is licensed under Apache-2.0 and bunkerweb under AGPL-3.0. Neither carries a licence fee.
What is the difference between trivy and bunkerweb?
trivy is written in Go and bunkerweb in Python. The practical differences are community size, licence terms, language stack and release cadence — all compared in the table above.
Which should I choose, trivy or bunkerweb?
Choose trivy if you want the larger community (37,969 stars) or its Apache-2.0 licence terms. Choose bunkerweb if its feature set, stack or AGPL-3.0 licence fits better. Both are self-hostable.