Open source audit projects

Every project in the registry tagged audit, ranked by real GitHub adoption.

projects 22 combined stars ★ 121K refresh nightly
01 lighthouse ★ 31K

Automated auditing, performance metrics, and best practices for the web.

last push3 hours ago languageJavaScript licenseApache-2.0
02 teleport ★ 21K

The easiest, and most secure way to access and protect all of your infrastructure.

last push7 hours ago languageGo licenseAGPL-3.0
03 Amphion ★ 10K

Amphion (/æmˈfaɪən/) is a toolkit for Audio, Music, and Speech Generation. Its purpose is to support reproducible research and help junior researchers and engin

last push6 months ago languagePython licenseMIT
04 aircrack-ng ★ 7.7K

WiFi security auditing tools suite

last push9 days ago languageC licenseGPL-2.0
05 rundeck ★ 6.3K

Enable Self-Service Operations: Give specific users access to your existing tools, services, and scripts

last push3 hours ago languageGroovy licenseApache-2.0
06 laravel-activitylog ★ 5.9K

Log activity inside your Laravel app

last push9 days ago languagePHP licenseMIT
07 next-terminal ★ 5.6K

A simple, secure, easy-to-use bastion and session auditing system. Supports RDP, SSH, VNC, Telnet, HTTP, records and replays sessions for auditing and complianc

last push18 hours ago languageTypeScript licenseApache-2.0
08 Harden-Windows-Security ★ 4.7K

Harden Windows Safely, Securely using Official Supported Microsoft methods and proper explanation | Always up-to-date and works with the latest build of Windows

last push2 days ago languageC# licenseMIT
09 black-hat-rust ★ 4.4K

Applied offensive security with Rust - https://kerkour.com/black-hat-rust

last push12 months ago languageRust licenseMIT
10 laravel-auditing ★ 3.5K

Record the change log from models in Laravel

last push2 months ago languagePHP licenseMIT
11 polaris ★ 3.4K

Validation of best practices in your Kubernetes clusters

last push32 hours ago languageGo licenseApache-2.0
12 pwndoc ★ 2.9K

Pentest Report Generator

last push7 days ago languageJavaScript licenseMIT
13 windows_hardening ★ 2.7K

HardeningKitty and Windows Hardening Settings

last push17 days ago languagePowerShell licenseMIT
14 Audit.NET ★ 2.7K

An extensible framework to audit executing operations in .NET

last pushyesterday languageC# licenseMIT
15 Comp AI ★ 2.0K

Get audit-ready for SOC 2, ISO 27001, HIPAA, and GDPR

last push9 days ago languageTypeScript licenseAGPL-3.0
16 HardeningKitty ★ 1.8K

HardeningKitty - Checks and hardens your Windows configuration

last push2 months ago languagePowerShell licenseMIT
17 webterminal ★ 1.7K

ssh rdp vnc telnet sftp bastion/jump web putty xshell terminal jumpserver audit realtime monitor rz/sz 堡垒机 云桌面 linux devops sftp websocket file management rz/s

last push11 months ago languagePython licenseLGPL-3.0
18 flashlight ★ 1.6K

📱⚡️ Lighthouse for Mobile - audits your app and gives a performance score to your Android apps (native, React Native, Flutter..). Measure performance on CLI, E

last push26 hours ago languageTypeScript licenseMIT
19 EntityAuditBundle ★ 643

Audit for Doctrine Entities

last push5 months ago languagePHP licenseMIT
20 wallace-cli ★ 643

Pretty CSS analytics on the CLI

last push7 days ago languageTypeScript licenseMIT
21 VerifyWise ★ 352

AI governance made simple, secure, and compliant

last push3 hours ago languageTypeScript license
22 Werbot ★ 170

Secure, scalable server access management for DevOps

last push2 months ago languageGo license

Related tags

← all tags

Frequently asked questions

How many open source audit projects are there?

This registry tracks 22 projects tagged audit, with 120,639 GitHub stars between them. The most-adopted is lighthouse at 30,785 stars.

Are these audit projects free to use?

Yes — 20 of the 22 carry an explicit open-source licence across 5 distinct licences, so there is no licence fee. Where a project also sells a hosted or enterprise version, the self-hosted path remains free.

Which audit project should I choose?

The list above is ranked by GitHub stars, but stars measure attention rather than fit. Check three things on each card: the licence (permissive versus copyleft), the language it is written in, and the last-push date — a high-star project that has not been pushed in a year is a liability.

Are these audit projects still maintained?

18 of the 22 were pushed in the last 90 days, and every card shows its exact last-push date so you can see the rest. Sort your shortlist by that date before committing to a migration.