Open source bug-bounty projects

Every project in the registry tagged bug-bounty, ranked by real GitHub adoption.

projects 9 combined stars ★ 84K refresh nightly
01 strix ★ 63K

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

last push3 hours ago languagePython licenseApache-2.0
02 Agentic-Bug-Hunter ★ 4.9K

AI-powered bug bounty hunting toolkit that works with or without subscription.

last push17 hours ago languagePython licenseMIT
03 black-hat-rust ★ 4.4K

Applied offensive security with Rust - https://kerkour.com/black-hat-rust

last push12 months ago languageRust licenseMIT
04 CyberStrike ★ 2.8K

Open-source AI-powered offensive security harness for automated penetration testing.

last push7 hours ago languageTypeScript licenseAGPL-3.0
05 pentest-ai-agents ★ 2.2K

Turn Claude Code into your offensive security research assistant. Specialized AI subagents for authorized penetration testing plan engagements, analyze recon, r

last push1 months ago languageShell licenseMIT
06 open-kritt ★ 2.1K

Open-source, self-hosted AI vulnerability research tool that orchestrates agents to find and validate security issues in code.

last push2 days ago languageJavaScript licenseAGPL-3.0
07 pentest-ai ★ 1.7K

Open-source AI pentester that proves every finding. Machine oracles re-run each exploit; verified bugs ship a proof capsule you can replay yourself.

last push5 days ago languagePython licenseMIT
08 xalgorix ★ 1.1K

Autonomous AI pentesting agents — real-time reconnaissance, vulnerability detection, and exploitation orchestration. Go + TypeScript.

last push2 days ago languageGo licenseApache-2.0
09 reconmap ★ 981

Reconmap is a collaboration-first security operations platform for infosec teams and MSSPs, enabling end‑to‑end engagement management, from reconnaissance throu

last push4 days ago languageJavaScript licenseApache-2.0

Related tags

← all tags

Frequently asked questions

How many open source bug-bounty projects are there?

This registry tracks 9 projects tagged bug-bounty, with 83,525 GitHub stars between them. The most-adopted is strix at 63,281 stars.

Are these bug-bounty projects free to use?

Yes — 9 of the 9 carry an explicit open-source licence across 3 distinct licences, so there is no licence fee. Where a project also sells a hosted or enterprise version, the self-hosted path remains free.

Which bug-bounty project should I choose?

The list above is ranked by GitHub stars, but stars measure attention rather than fit. Check three things on each card: the licence (permissive versus copyleft), the language it is written in, and the last-push date — a high-star project that has not been pushed in a year is a liability.

Are these bug-bounty projects still maintained?

8 of the 9 were pushed in the last 90 days, and every card shows its exact last-push date so you can see the rest. Sort your shortlist by that date before committing to a migration.