Suggest a tool

Trivy alternatives: 8 open-source security testing tools

Metrics as of , from the GitHub or GitLab API of each repository. Refreshed monthly.

About Trivy

Trivy is a listed security testing tool: Security scanner for container images, filesystems, Git repositories, VM images and Kubernetes, covering CVEs, misconfigurations, secrets and licenses.

Order: Listed tools in the same category, with tools in the same primary language (GitHub API) first, then by GitHub stars. Each line gives one fact from the tool's own documentation where it differs from what Trivy's documentation states, with its source.

8 alternatives to Trivy

Repository metrics

Trivy and its alternatives. Sorted by GitHub stars, descending, descending. Select a column heading to change the sort.
sqlmap38,49212026-01-0111.102026-09-201GPL-2.0-or-laterPythonactive
Trivy38,00912026-08-141v0.74.02026-09-221Apache-2.0Goactive
Nuclei31,43112026-08-081v3.11.12026-09-221MITGoactive
Gitleaks29,42812026-03-211v8.30.12026-07-221MITGoactive
Promptfoo25,37112026-09-1810.123.12026-09-221MITTypeScriptactive
ffuf16,70312026-09-091v2.3.02026-09-091MITGoactive
ZAP15,80412025-12-151v2.17.02026-09-171Apache-2.0Javaactive
OSV-Scanner11,07312026-09-141v2.6.02026-09-221Apache-2.0Goactive
Nikto10,73612026-07-3112.6.12026-08-151GPL-3.0-onlyPerlactive

1 Fetched from the GitHub or GitLab API on . Hover a value for its own date.

Comparisons with Trivy