Open source security-scanner projects

Every project in the registry tagged security-scanner, ranked by real GitHub adoption.

projects 5 combined stars ★ 75K refresh nightly
01 ProjectDiscovery ★ 31K

Advanced vulnerability detection and management platform

last push3 days ago languageGo licenseMIT
02 SkillSpector ★ 18K

Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, security risks, prompt injection, data exfiltration, and supply-chain risks in

last push6 hours ago languagePython licenseApache-2.0
03 lynis ★ 16K

Lynis - Security auditing tool for Linux, macOS, and UNIX-based systems. Assists with compliance testing (HIPAA/ISO27001/PCI DSS) and system hardening. Agentles

last push28 hours ago languageShell licenseGPL-3.0
04 DeepAudit ★ 7.0K

DeepAudit:人人拥有的 AI 黑客战队,让漏洞挖掘触手可及。国内首个开源的代码漏洞挖掘多智能体系统。小白一键部署运行,自主协作审计 + 自动化沙箱 PoC 验证。支持 Ollama 私有部署 ,一键生成报告。支持中转站。​让安全不再昂贵,让审计不再复杂。

last push41 hours ago languagePython licenseAGPL-3.0
05 nodejsscan ★ 2.6K

nodejsscan is a static security code scanner for Node.js applications.

last push11 months ago languageCSS licenseGPL-3.0

← all tags

Frequently asked questions

How many open source security-scanner projects are there?

This registry tracks 5 projects tagged security-scanner, with 74,851 GitHub stars between them. The most-adopted is ProjectDiscovery at 31,272 stars.

Are these security-scanner projects free to use?

Yes — 5 of the 5 carry an explicit open-source licence across 4 distinct licences, so there is no licence fee. Where a project also sells a hosted or enterprise version, the self-hosted path remains free.

Which security-scanner project should I choose?

The list above is ranked by GitHub stars, but stars measure attention rather than fit. Check three things on each card: the licence (permissive versus copyleft), the language it is written in, and the last-push date — a high-star project that has not been pushed in a year is a liability.

Are these security-scanner projects still maintained?

4 of the 5 were pushed in the last 90 days, and every card shows its exact last-push date so you can see the rest. Sort your shortlist by that date before committing to a migration.