Open source appsec projects

Every project in the registry tagged appsec, ranked by real GitHub adoption.

projects 5 combined stars ★ 82K refresh nightly
01 shannon ★ 48K

Shannon is an AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes real exploits to prove vulnerabi

last push9 days ago languageTypeScript licenseAGPL-3.0
02 SafeLine ★ 23K

SafeLine is a self-hosted WAF(Web Application Firewall) / reverse proxy to protect your web apps from attacks and exploits.

last push7 days ago languageGo licenseGPL-3.0
03 faraday ★ 6.7K

Open Source Vulnerability Management Platform

last push13 days ago languagePython licenseGPL-3.0
04 kics ★ 2.7K

Find security vulnerabilities, compliance issues, and infrastructure misconfigurations early in the development cycle of your infrastructure-as-code with KICS b

last push12 hours ago languageOpen Policy Agent licenseApache-2.0
05 pentest-ai ★ 1.7K

Open-source AI pentester that proves every finding. Machine oracles re-run each exploit; verified bugs ship a proof capsule you can replay yourself.

last push5 days ago languagePython licenseMIT

Related tags

← all tags

Frequently asked questions

How many open source appsec projects are there?

This registry tracks 5 projects tagged appsec, with 81,833 GitHub stars between them. The most-adopted is shannon at 48,105 stars.

Are these appsec projects free to use?

Yes — 5 of the 5 carry an explicit open-source licence across 4 distinct licences, so there is no licence fee. Where a project also sells a hosted or enterprise version, the self-hosted path remains free.

Which appsec project should I choose?

The list above is ranked by GitHub stars, but stars measure attention rather than fit. Check three things on each card: the licence (permissive versus copyleft), the language it is written in, and the last-push date — a high-star project that has not been pushed in a year is a liability.

Are these appsec projects still maintained?

5 of the 5 were pushed in the last 90 days, and every card shows its exact last-push date so you can see the rest. Sort your shortlist by that date before committing to a migration.