Open source security-audit projects

Every project in the registry tagged security-audit, ranked by real GitHub adoption.

projects 6 combined stars ★ 31K refresh nightly
01 lynis ★ 16K

Lynis - Security auditing tool for Linux, macOS, and UNIX-based systems. Assists with compliance testing (HIPAA/ISO27001/PCI DSS) and system hardening. Agentles

last push26 hours ago languageShell licenseGPL-3.0
02 DependencyCheck ★ 7.7K

OWASP dependency-check is a software composition analysis utility that detects publicly disclosed vulnerabilities in application dependencies.

last push22 hours ago languageJava licenseApache-2.0
03 pwndoc ★ 2.9K

Pentest Report Generator

last push7 days ago languageJavaScript licenseMIT
04 fixinventory ★ 2.1K

Fix Inventory helps you identify and remove the most critical risks in AWS, GCP, Azure and Kubernetes.

last push6 months ago languagePython licenseApache-2.0
05 dep-scan ★ 1.3K

OWASP dep-scan is a next-generation security and risk audit tool based on known vulnerabilities, advisories, and license limitations for project dependencies. B

last push1 months ago languagePython licenseMIT
06 faction ★ 604

Pen Test Report Generation and Assessment Collaboration

last push7 days ago languageJava licenseGPL-2.0

Related tags

← all tags

Frequently asked questions

How many open source security-audit projects are there?

This registry tracks 6 projects tagged security-audit, with 30,912 GitHub stars between them. The most-adopted is lynis at 16,355 stars.

Are these security-audit projects free to use?

Yes — 6 of the 6 carry an explicit open-source licence across 4 distinct licences, so there is no licence fee. Where a project also sells a hosted or enterprise version, the self-hosted path remains free.

Which security-audit project should I choose?

The list above is ranked by GitHub stars, but stars measure attention rather than fit. Check three things on each card: the licence (permissive versus copyleft), the language it is written in, and the last-push date — a high-star project that has not been pushed in a year is a liability.

Are these security-audit projects still maintained?

5 of the 6 were pushed in the last 90 days, and every card shows its exact last-push date so you can see the rest. Sort your shortlist by that date before committing to a migration.