Open source pentesting projects

Every project in the registry tagged pentesting, ranked by real GitHub adoption.

projects 7 combined stars ★ 124K refresh nightly
01 shannon ★ 48K

Shannon is an AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes real exploits to prove vulnerabi

last push9 days ago languageTypeScript licenseAGPL-3.0
02 maigret ★ 38K

🕵️‍♂️ Collect a dossier on a person by username from 3000+ sites

last push9 hours ago languagePython licenseMIT
03 promptfoo ★ 25K

Test your prompts, agents, and RAGs. Red teaming/pentesting/vulnerability scanning for AI. Compare performance of GPT, Claude, Gemini, DeepSeek, and more. Simpl

last push6 hours ago languageTypeScript licenseMIT
04 osmedeus ★ 6.6K

A Modern Orchestration Engine for Security

last push6 days ago languageGo licenseMIT
05 black-hat-rust ★ 4.4K

Applied offensive security with Rust - https://kerkour.com/black-hat-rust

last push12 months ago languageRust licenseMIT
06 reconmap ★ 981

Reconmap is a collaboration-first security operations platform for infosec teams and MSSPs, enabling end‑to‑end engagement management, from reconnaissance throu

last push4 days ago languageJavaScript licenseApache-2.0
07 faction ★ 604

Pen Test Report Generation and Assessment Collaboration

last push7 days ago languageJava licenseGPL-2.0

Related tags

← all tags

Frequently asked questions

How many open source pentesting projects are there?

This registry tracks 7 projects tagged pentesting, with 123,627 GitHub stars between them. The most-adopted is shannon at 48,105 stars.

Are these pentesting projects free to use?

Yes — 7 of the 7 carry an explicit open-source licence across 4 distinct licences, so there is no licence fee. Where a project also sells a hosted or enterprise version, the self-hosted path remains free.

Which pentesting project should I choose?

The list above is ranked by GitHub stars, but stars measure attention rather than fit. Check three things on each card: the licence (permissive versus copyleft), the language it is written in, and the last-push date — a high-star project that has not been pushed in a year is a liability.

Are these pentesting projects still maintained?

6 of the 7 were pushed in the last 90 days, and every card shows its exact last-push date so you can see the rest. Sort your shortlist by that date before committing to a migration.