Open source security projects

Every project in the registry tagged security, ranked by real GitHub adoption.

projects 47 combined stars ★ 317K refresh nightly
01 trivy ★ 38K

Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

last push10 hours ago languageGo licenseApache-2.0
02 ProjectDiscovery ★ 31K

Advanced vulnerability detection and management platform

last push3 days ago languageGo licenseMIT
03 KeePassXC ★ 29K

Cross-platform, secure password manager

last push27 hours ago languageC++ license
04 sops ★ 23K

Simple and flexible tool for managing secrets

last push4 days ago languageGo licenseMPL-2.0
05 SafeLine ★ 23K

SafeLine is a self-hosted WAF(Web Application Firewall) / reverse proxy to protect your web apps from attacks and exploits.

last push8 days ago languageGo licenseGPL-3.0
06 DB-GPT ★ 20K

open-source agentic AI data assistant for the next generation of AI + Data products.

last pushyesterday languagePython licenseMIT
07 OpenVPN ★ 15K

Zero Trust VPN solutions for secure business networking

last push8 hours ago languageC license
08 Betterfox ★ 11K

Firefox user.js for optimal privacy and security. Your favorite browser, but better.

last push10 days ago languageJavaScript licenseMIT
09 FireZone ★ 9.1K

Fast, flexible VPN replacement with zero-trust security

last push20 hours ago languageElixir licenseApache-2.0
10 kyverno ★ 8.2K

Unified Policy as Code

last push12 hours ago languageGo licenseApache-2.0
11 Tuta ★ 7.9K

Secure email, calendar and contacts with end-to-end encryption

last push7 hours ago languageTypeScript licenseGPL-3.0
12 DependencyCheck ★ 7.7K

OWASP dependency-check is a software composition analysis utility that detects publicly disclosed vulnerabilities in application dependencies.

last push23 hours ago languageJava licenseApache-2.0
13 aircrack-ng ★ 7.7K

WiFi security auditing tools suite

last push9 days ago languageC licenseGPL-2.0
14 osmedeus ★ 6.6K

A Modern Orchestration Engine for Security

last push6 days ago languageGo licenseMIT
15 agent-governance-toolkit ★ 6.3K

AI Agent Governance Toolkit — Policy enforcement, zero-trust identity, execution sandboxing, and reliability engineering for autonomous AI agents. Covers 10/10

last push6 hours ago languagePython licenseMIT
16 Cosmos Server ★ 6.2K

Self-hosted cloud platform with automated security

last push12 days ago languageGo license
17 Passbolt ★ 6.1K

Secure password management for teams

last push15 hours ago languagePHP licenseAGPL-3.0
18 ossec-hids ★ 5.1K

OSSEC is an Open Source Host-based Intrusion Detection System that performs log analysis, file integrity checking, policy monitoring, rootkit detection, real-ti

last push11 hours ago languageC licenseGPL-2.0
19 hubble ★ 4.3K

Hubble - Network, Service & Security Observability for Kubernetes using eBPF

last push3 days ago languageMakefile licenseApache-2.0
20 retire.js ★ 4.2K

scanner detecting the use of JavaScript libraries with known vulnerabilities. Can also generate an SBOM of the libraries it finds.

last push4 days ago languageJavaScript licenseApache-2.0
21 nono ★ 4.1K

secure multiplexed execution paths for agents - zero trust, zero setup, zero latency.

last push9 hours ago languageRust licenseApache-2.0
22 Tracecat ★ 3.8K

Open source security automation platform for builders

last push5 hours ago languagePython licenseAGPL-3.0
23 shynet ★ 3.2K

Modern, privacy-friendly, and detailed web analytics that works without cookies or JS.

last push6 months ago languagePython licenseApache-2.0
24 vps-audit ★ 3.1K

lightweight, dependency-free bash script for security, performance auditing and infrastructure monitoring of Linux servers.

last push1 months ago languageShell licenseMIT
25 pwndoc ★ 2.9K

Pentest Report Generator

last push7 days ago languageJavaScript licenseMIT
26 ALTCHA ★ 2.8K

Next-Gen CAPTCHA and Spam Protection, GDPR compliant

last push7 days ago languageTypeScript licenseMIT
27 kics ★ 2.7K

Find security vulnerabilities, compliance issues, and infrastructure misconfigurations early in the development cycle of your infrastructure-as-code with KICS b

last push14 hours ago languageOpen Policy Agent licenseApache-2.0
28 windows_hardening ★ 2.7K

HardeningKitty and Windows Hardening Settings

last push17 days ago languagePowerShell licenseMIT
29 nodejsscan ★ 2.6K

nodejsscan is a static security code scanner for Node.js applications.

last push11 months ago languageCSS licenseGPL-3.0
30 cargo-crev ★ 2.3K

A cryptographically verifiable code review system for the cargo (Rust) package manager.

last push2 months ago languageRust licenseApache-2.0
31 toolhive ★ 2.2K

ToolHive is an enterprise-grade platform for running and managing Model Context Protocol (MCP) servers.

last push6 hours ago languageGo licenseApache-2.0
32 fixinventory ★ 2.1K

Fix Inventory helps you identify and remove the most critical risks in AWS, GCP, Azure and Kubernetes.

last push6 months ago languagePython licenseApache-2.0
33 Comp AI ★ 2.0K

Get audit-ready for SOC 2, ISO 27001, HIPAA, and GDPR

last push9 days ago languageTypeScript licenseAGPL-3.0
34 HardeningKitty ★ 1.8K

HardeningKitty - Checks and hardens your Windows configuration

last push2 months ago languagePowerShell licenseMIT
35 copacetic ★ 1.7K

🧵 CLI tool for directly patching container images!

last push3 days ago languageGo licenseApache-2.0
36 FuzzyAI ★ 1.6K

A powerful tool for automated LLM fuzzing. It is designed to help developers and security researchers identify and mitigate potential jailbreaks in their LLM AP

last push7 months ago languageJupyter Notebook licenseApache-2.0
37 guac ★ 1.5K

GUAC aggregates software security metadata into a high fidelity graph database.

last push26 hours ago languageGo licenseApache-2.0
38 PaperKnife ★ 1.5K

Privacy-first PDF utility (Zero-Server Architecture). Merge, split, compress, and edit PDFs 100% locally on your device. No uploads, no servers, no tracking.

last push2 days ago languageTypeScript licenseAGPL-3.0
39 threagile ★ 780

Agile Threat Modeling Toolkit

last push5 months ago languageGo licenseMIT
40 go-tuf ★ 717

Go implementation of The Update Framework (TUF)

last push39 hours ago languageGo licenseApache-2.0
41 bomber ★ 624

Scans Software Bill of Materials (SBOMs) for security vulnerabilities

last push7 months ago languageGo licenseMPL-2.0
42 faction ★ 604

Pen Test Report Generation and Assessment Collaboration

last push7 days ago languageJava licenseGPL-2.0
43 witness ★ 546

Witness is a pluggable framework for software supply chain risk management. It automates, normalizes, and verifies software artifact provenance.

last push34 hours ago languageGo licenseApache-2.0
44 sigstore ★ 535

Common go library shared across sigstore services and clients

last push3 days ago languageGo licenseApache-2.0
45 Shelve ★ 456

Simplify project management for developers

last push7 hours ago languageTypeScript licenseApache-2.0
46 Private Captcha ★ 195

GDPR-compliant bot protection without user friction

last push8 hours ago languageGo license
47 StatusScout ★ 15

Complete website health monitoring and security scanning

last push4 months ago languageJavaScript license

Related tags

← all tags

Frequently asked questions

How many open source security projects are there?

This registry tracks 47 projects tagged security, with 317,409 GitHub stars between them. The most-adopted is trivy at 37,961 stars.

Are these security projects free to use?

Yes — 42 of the 47 carry an explicit open-source licence across 6 distinct licences, so there is no licence fee. Where a project also sells a hosted or enterprise version, the self-hosted path remains free.

Which security project should I choose?

The list above is ranked by GitHub stars, but stars measure attention rather than fit. Check three things on each card: the licence (permissive versus copyleft), the language it is written in, and the last-push date — a high-star project that has not been pushed in a year is a liability.

Are these security projects still maintained?

40 of the 47 were pushed in the last 90 days, and every card shows its exact last-push date so you can see the rest. Sort your shortlist by that date before committing to a migration.