Open source bugbounty projects

Every project in the registry tagged bugbounty, ranked by real GitHub adoption.

projects 3 combined stars ★ 11K refresh nightly
01 osmedeus ★ 6.6K

A Modern Orchestration Engine for Security

last push6 days ago languageGo licenseMIT
02 cariddi ★ 3.8K

Take a list of domains, crawl urls and scan for endpoints, secrets, api keys, file extensions, tokens and more

last push11 days ago languageGo licenseGPL-3.0
03 vulnrepo ★ 579

VULNRΞPO - Free vulnerability report generator and repository, end-to-end encrypted! Templates of issues, CWE,CVE,MITRE ATT&CK,PCI DSS, import Nmap/Nessus/Burp/

last push38 hours ago languageTypeScript licenseApache-2.0

Related tags

← all tags

Frequently asked questions

How many open source bugbounty projects are there?

This registry tracks 3 projects tagged bugbounty, with 10,920 GitHub stars between them. The most-adopted is osmedeus at 6,569 stars.

Are these bugbounty projects free to use?

Yes — 3 of the 3 carry an explicit open-source licence across 3 distinct licences, so there is no licence fee. Where a project also sells a hosted or enterprise version, the self-hosted path remains free.

Which bugbounty project should I choose?

The list above is ranked by GitHub stars, but stars measure attention rather than fit. Check three things on each card: the licence (permissive versus copyleft), the language it is written in, and the last-push date — a high-star project that has not been pushed in a year is a liability.

Are these bugbounty projects still maintained?

3 of the 3 were pushed in the last 90 days, and every card shows its exact last-push date so you can see the rest. Sort your shortlist by that date before committing to a migration.