Open source security projects
Every project in the registry tagged security, ranked by real GitHub adoption.
Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more
Advanced vulnerability detection and management platform
Cross-platform, secure password manager
Simple and flexible tool for managing secrets
SafeLine is a self-hosted WAF(Web Application Firewall) / reverse proxy to protect your web apps from attacks and exploits.
open-source agentic AI data assistant for the next generation of AI + Data products.
Zero Trust VPN solutions for secure business networking
Firefox user.js for optimal privacy and security. Your favorite browser, but better.
Fast, flexible VPN replacement with zero-trust security
Unified Policy as Code
Secure email, calendar and contacts with end-to-end encryption
OWASP dependency-check is a software composition analysis utility that detects publicly disclosed vulnerabilities in application dependencies.
WiFi security auditing tools suite
A Modern Orchestration Engine for Security
AI Agent Governance Toolkit — Policy enforcement, zero-trust identity, execution sandboxing, and reliability engineering for autonomous AI agents. Covers 10/10
Self-hosted cloud platform with automated security
Secure password management for teams
OSSEC is an Open Source Host-based Intrusion Detection System that performs log analysis, file integrity checking, policy monitoring, rootkit detection, real-ti
Hubble - Network, Service & Security Observability for Kubernetes using eBPF
scanner detecting the use of JavaScript libraries with known vulnerabilities. Can also generate an SBOM of the libraries it finds.
secure multiplexed execution paths for agents - zero trust, zero setup, zero latency.
Open source security automation platform for builders
Modern, privacy-friendly, and detailed web analytics that works without cookies or JS.
lightweight, dependency-free bash script for security, performance auditing and infrastructure monitoring of Linux servers.
Pentest Report Generator
Next-Gen CAPTCHA and Spam Protection, GDPR compliant
Find security vulnerabilities, compliance issues, and infrastructure misconfigurations early in the development cycle of your infrastructure-as-code with KICS b
HardeningKitty and Windows Hardening Settings
nodejsscan is a static security code scanner for Node.js applications.
A cryptographically verifiable code review system for the cargo (Rust) package manager.
ToolHive is an enterprise-grade platform for running and managing Model Context Protocol (MCP) servers.
Fix Inventory helps you identify and remove the most critical risks in AWS, GCP, Azure and Kubernetes.
Get audit-ready for SOC 2, ISO 27001, HIPAA, and GDPR
HardeningKitty - Checks and hardens your Windows configuration
🧵 CLI tool for directly patching container images!
A powerful tool for automated LLM fuzzing. It is designed to help developers and security researchers identify and mitigate potential jailbreaks in their LLM AP
GUAC aggregates software security metadata into a high fidelity graph database.
Privacy-first PDF utility (Zero-Server Architecture). Merge, split, compress, and edit PDFs 100% locally on your device. No uploads, no servers, no tracking.
Agile Threat Modeling Toolkit
Go implementation of The Update Framework (TUF)
Scans Software Bill of Materials (SBOMs) for security vulnerabilities
Pen Test Report Generation and Assessment Collaboration
Witness is a pluggable framework for software supply chain risk management. It automates, normalizes, and verifies software artifact provenance.
Common go library shared across sigstore services and clients
Simplify project management for developers
GDPR-compliant bot protection without user friction
Complete website health monitoring and security scanning
Related tags
Frequently asked questions
How many open source security projects are there?
This registry tracks 47 projects tagged security, with 317,409 GitHub stars between them. The most-adopted is trivy at 37,961 stars.
Are these security projects free to use?
Yes — 42 of the 47 carry an explicit open-source licence across 6 distinct licences, so there is no licence fee. Where a project also sells a hosted or enterprise version, the self-hosted path remains free.
Which security project should I choose?
The list above is ranked by GitHub stars, but stars measure attention rather than fit. Check three things on each card: the licence (permissive versus copyleft), the language it is written in, and the last-push date — a high-star project that has not been pushed in a year is a liability.
Are these security projects still maintained?
40 of the 47 were pushed in the last 90 days, and every card shows its exact last-push date so you can see the rest. Sort your shortlist by that date before committing to a migration.