Open source application-security projects

Every project in the registry tagged application-security, ranked by real GitHub adoption.

projects 7 combined stars ★ 38K refresh nightly
01 SafeLine ★ 23K

SafeLine is a self-hosted WAF(Web Application Firewall) / reverse proxy to protect your web apps from attacks and exploits.

last push8 days ago languageGo licenseGPL-3.0
02 codex-security ★ 11K

OpenAI's Codex Security CLI and TypeScript SDK for finding, validating, and fixing security vulnerabilities. npm: https://www.npmjs.com/package/@openai/codex-se

last push6 hours ago languageTypeScript licenseApache-2.0
03 mantis ★ 1.6K

A modular, stack-agnostic toolkit of security review skills for AI coding agents to autonomously find, reproduce, and patch vulnerabilities.

last push5 days ago languagePython licenseApache-2.0
04 stride-gpt ★ 1.1K

An AI-powered threat modeling tool that leverages OpenAI's GPT models to generate threat models for a given application based on the STRIDE methodology.

last push3 days ago languagePython licenseMIT
05 vuln-bank ★ 933

A deliberately vulnerable banking application designed for practicing Security Testing of Web App, APIs, AI integrated App and secure code reviews. Features com

last push6 days ago languageHTML licenseMIT
06 arcjet-js ★ 683

Runtime security for AI apps and agents: prompt injection detection, tool-call authorization, sensitive-data redaction, bot protection, and rate limiting. Drop

last push10 hours ago languageTypeScript licenseApache-2.0
07 faction ★ 604

Pen Test Report Generation and Assessment Collaboration

last push7 days ago languageJava licenseGPL-2.0

Related tags

← all tags

Frequently asked questions

How many open source application-security projects are there?

This registry tracks 7 projects tagged application-security, with 38,274 GitHub stars between them. The most-adopted is SafeLine at 22,606 stars.

Are these application-security projects free to use?

Yes — 7 of the 7 carry an explicit open-source licence across 4 distinct licences, so there is no licence fee. Where a project also sells a hosted or enterprise version, the self-hosted path remains free.

Which application-security project should I choose?

The list above is ranked by GitHub stars, but stars measure attention rather than fit. Check three things on each card: the licence (permissive versus copyleft), the language it is written in, and the last-push date — a high-star project that has not been pushed in a year is a liability.

Are these application-security projects still maintained?

7 of the 7 were pushed in the last 90 days, and every card shows its exact last-push date so you can see the rest. Sort your shortlist by that date before committing to a migration.