Suggest a tool

Category guides · published

"Best open source security testing tools": 18 listed, sorted by GitHub stars

Metrics as of , from the GitHub or GitLab API of each repository. Refreshed monthly.

The security category on FreeQATools lists open-source scanners and fuzzers used in application security testing. The table is sorted by GitHub stars on each tool's fetch date, which is a count and not a quality judgement. The sections below group the tools by documented scan target, check format, report output and CI support.

What each tool scans

Several scanners target running web applications and servers. ZAP scans web applications. Nikto looks for potentially dangerous files and outdated components on web servers. ffuf fuzzes content paths, virtual hosts, GET parameters and POST data. sqlmap tests GET and POST parameters plus cookie, User-Agent and Referer header values.

Nuclei scans URLs and hosts from a single target or a list file. The Nuclei README also lists OpenAPI, Swagger, Burp and raw HTTP input files. OWASP Nettacker accepts IPv4 addresses, IP ranges, CIDR blocks, domain names and HTTP or HTTPS URLs.

API definitions drive other tools. RESTler reads OpenAPI definitions to fuzz REST APIs. EvoMaster checks web APIs for 500 status codes, schema mismatches, access violations and SQL injection. The ZAP API scan accepts OpenAPI, Swagger or GraphQL definitions.

Code, dependencies, repositories and images are the target of other scanners. Bandit parses Python files into an abstract syntax tree. Gitleaks finds secrets in git repositories, files and stdin. OSV-Scanner checks project dependencies against the OSV database. Trivy scans container images, filesystems, remote Git repositories, VM images and Kubernetes.

Other entries fuzz programs and code directly. AFL++ instruments targets with LLVM or GCC and reaches binaries through QEMU, FRIDA or unicorn mode. Honggfuzz builds C and C++ targets with its compiler wrappers. Atheris fuzzes Python code and native CPython extensions.

LLMs and dialog systems are the target of garak. Promptfoo documents red teaming and vulnerability scanning for LLM apps.

Check and rule formats

Nuclei templates are YAML. OWASP Nettacker modules are declarative YAML. Gitleaks rules are TOML entries with Go regular expressions. Custom Trivy misconfiguration checks are written in Rego. Bandit tests are Python plugins.

Nikto keeps most of its tests in a CSV scan database.

Fuzzers and test generators are set up in other ways. AFL++ reads seed files from an input directory. Atheris fuzzers are Python entry point functions. The RESTler compiler generates grammar files from the API definition. EvoMaster generates test suites with an evolutionary algorithm.

Reports and CI

Bandit documents SARIF output. Gitleaks documents SARIF output. OSV-Scanner documents SARIF output. Trivy documents SARIF output. Nuclei exports results in SARIF format.

OWASP Nettacker documents SARIF output. The ZAP report templates include SARIF JSON. AFL++ writes crash and hang inputs to its output directory. Honggfuzz writes a report file to the working directory.

Bandit documents a GitHub Actions workflow. Gitleaks documents a GitHub Action. OSV-Scanner offers reusable GitHub Actions workflows. Trivy documents a GitHub Action.

ZAP lists packaged scans for GitHub Actions. EvoMaster documents a GitHub Action. Promptfoo documents a GitHub Action. A comparison row with no documented value is marked not documented instead of inferred (comparison method).

ffuf has no documented CI setup. garak has no documented CI setup. Honggfuzz has no documented CI setup. Nikto has no documented CI setup. RESTler has no documented CI setup.

OWASP dependency-check is archived on its host. Its catalogue entry notes that the project moved to a new repository (tool page). Archived entries also appear on the archived page.

How this list is sorted

The quoted title is a search query, not a verdict. FreeQATools does not rank tools by opinion. The list below is sorted by GitHub stars, descending, as fetched from the repository host API on the date shown with each value.

Stars count how many accounts have starred a repository. They say nothing about fit for a given project, so the documented facts under each tool are the part to compare.

Every tool here meets the inclusion rules: an OSI-approved license, a public repository, software testing or quality as its primary purpose and at least one release or tag. Each status badge follows the status rules on the methodology page.

Open-source security testing tools by GitHub stars

Security testing tools. Sorted by GitHub stars, descending. Select a column heading to change the sort.
sqlmap38,49212026-01-0111.102026-09-201GPL-2.0-or-laterPythonactive
Trivy38,00912026-08-141v0.74.02026-09-221Apache-2.0Goactive
Nuclei31,43112026-08-081v3.11.12026-09-221MITGoactive
Gitleaks29,42812026-03-211v8.30.12026-07-221MITGoactive
Promptfoo25,37112026-09-1810.123.12026-09-221MITTypeScriptactive
ffuf16,70312026-09-091v2.3.02026-09-091MITGoactive
ZAP15,80412025-12-151v2.17.02026-09-171Apache-2.0Javaactive
OSV-Scanner11,07312026-09-141v2.6.02026-09-221Apache-2.0Goactive
Nikto10,73612026-07-3112.6.12026-08-151GPL-3.0-onlyPerlactive
garak9,33012026-09-091v0.17.02026-09-161Apache-2.0Pythonactive
Bandit8,27812026-02-2511.9.42026-09-211Apache-2.0Pythonactive
AFL++6,76512026-09-021v5.03c2026-09-021AGPL-3.0Cactive
OWASP Nettacker5,61212026-08-2410.4.12026-09-221Apache-2.0Pythonactive
Honggfuzz3,38312024-07-201oss-fuzz2026-06-191Apache-2.0Cslow
RESTler2,94612025-01-301v9.3.12026-02-131MITPythonslow
Atheris1,67812025-11-2513.0.02026-06-171Apache-2.0Pythonslow
EvoMaster78212026-09-151v6.2.02026-09-221LGPL-3.0Kotlinactive
OWASP dependency-check5412025-02-171v12.1.02025-02-171Apache-2.0Javaarchived

1 Fetched from the GitHub or GitLab API on . Hover a value for its own date.

Filters for language, license and status are on the security testing category page.

Tools in this list

Each entry gives the tool's one-line summary from its README and the facts its documentation states for this category, each with its source. Facts that are not documented are left out here and marked on the comparison pages.

  1. sqlmap

    Command-line penetration testing tool that detects and exploits SQL injection flaws in database-backed applications. README, read 2026-09-22

    Scan targets
    Web application parameters: GET, POST, cookie, User-Agent and Referer values source: Docs: Features
    Languages or files analysed
    Database back ends including MySQL, Oracle, PostgreSQL, Microsoft SQL Server, SQLite and others listed source: Docs: Features
    Check or rule format
    Command-line options and switches; tamper scripts that transform payloads source: Docs: Usage
    CI integration
    JSON run report (--report-json) for feeding findings into CI pipelines source: Docs: Usage
    Report formats
    JSON run report (--report-json); dumped data as CSV, HTML, SQLite or JSONL source: Docs: Usage
    Install method
    Git clone of the repository, or tarball and zipball downloads; runs on Python 2.7 and 3.x source: README
  2. Trivy

    Security scanner for container images, filesystems, Git repositories, VM images and Kubernetes, covering CVEs, misconfigurations, secrets and licenses. README, read 2026-09-22

    Scan targets
    Container images, filesystems, remote Git repositories, virtual machine images, Kubernetes source: README
    Languages or files analysed
    OS packages, language-specific packages, IaC files, Kubernetes clusters source: Docs: Scanning Coverage
    Check or rule format
    Custom misconfiguration checks written in Rego source: Docs: Custom Checks
    CI integration
    GitHub Action aquasecurity/trivy-action; community CircleCI orb, Buildkite plugin and GitLab templates source: Docs: CI/CD Integrations
    Report formats
    Table, JSON, SARIF, template, SBOM, GitHub dependency snapshot source: Docs: Reporting
    Install method
    Homebrew (brew install trivy); Docker image aquasec/trivy; release binaries source: README
  3. Nuclei

    Template-based vulnerability scanner that runs YAML templates over HTTP, DNS, TCP, SSL and other protocols from a CLI. README, read 2026-09-22

    Scan targets
    Target URLs and hosts, from a single target or a list file source: README
    Languages or files analysed
    Target lists plus Burp, JSONL, YAML, OpenAPI, Swagger and raw HTTP input files source: README
    Check or rule format
    YAML templates source: README
    CI integration
    CI/CD pipeline use for vulnerability detection and regression testing source: README
    Report formats
    JSON, JSONL, Markdown, SARIF, PDF source: README
    Install method
    go install -v github.com/projectdiscovery/nuclei/v3/cmd/nuclei@latest (Go 1.24.2 or later) source: README
  4. Gitleaks

    CLI that detects secrets such as passwords, API keys and tokens in git repositories, files and stdin. README, read 2026-09-22

    Scan targets
    Secrets such as passwords, API keys and tokens in git repositories, files and stdin source: README
    Languages or files analysed
    Git commit patches (via git log -p), directories and files source: README
    Check or rule format
    TOML config file with [[rules]] entries using Go regular expressions source: README
    CI integration
    GitHub Action (Gitleaks-Action); pre-commit hook source: README
    Report formats
    JSON, CSV, JUnit, SARIF, custom template source: README
    Install method
    Homebrew (brew install gitleaks); Docker images zricethezav/gitleaks and ghcr.io/gitleaks/gitleaks; Go source build; release binaries source: README
  5. Promptfoo

    CLI and library for LLM evaluations, side-by-side model comparison and red teaming of LLM-based applications. README, read 2026-09-22

    Scan targets
    LLM apps, through red teaming and vulnerability scanning source: README
    Languages or files analysed
    Any LLM API or programming language source: README
    Check or rule format
    YAML config file (promptfooconfig.yaml) with prompts, providers and test cases source: Docs: Getting Started
    CI integration
    GitHub Actions guide and GitHub Marketplace action; CI/CD guide for other platforms source: Docs: CI/CD Integration for LLM Evaluation and Security
    Report formats
    HTML, JSON, CSV, JUnit XML (promptfoo eval --output) source: Docs: Output Formats
    Install method
    npm (npm install -g promptfoo), Homebrew (brew install promptfoo), pip (pip install promptfoo) source: README
  6. ffuf

    Go command-line web fuzzer for content, virtual host and parameter discovery using wordlists. README, read 2026-09-22

    Scan targets
    Web servers: content paths, virtual hosts, GET parameters and POST data source: README
    Languages or files analysed
    Wordlists (-w), raw HTTP request files (-request), command output (-input-cmd) source: README
    Check or rule format
    Command-line flags with the FUZZ keyword; ffufrc configuration files source: README
    Report formats
    JSON, ejson, HTML, Markdown, CSV, ecsv source: README
    Install method
    Release binaries; Scoop, Winget, Homebrew; go install github.com/ffuf/ffuf/v2@latest source: README
  7. ZAP

    Open source web application security scanner for automated scans and manual penetration testing. README, read 2026-09-22

    Scan targets
    Web applications source: README
    Languages or files analysed
    API definitions in OpenAPI / Swagger or GraphQL (API Scan) source: Docs: ZAP Docker Documentation
    Check or rule format
    YAML plan file (Automation Framework) source: Docs: Automation Framework
    CI integration
    GitHub Actions packaged scans on the GitHub Marketplace; Docker packaged scans source: Docs: Automate ZAP
    Report formats
    Report templates including SARIF JSON, HTML, JSON, Markdown, PDF and XML source: Docs: Report Generation
    Install method
    Docker image zaproxy/zap-stable (also ghcr.io/zaproxy/zaproxy:stable) source: Docs: Download ZAP
  8. OSV-Scanner

    CLI that checks project dependencies, container images and Linux OS packages against the OSV vulnerability database. README, read 2026-09-22

    Scan targets
    Project dependencies, checked against the OSV database source: README
    Languages or files analysed
    Dependencies in C/C++, Dart, Elixir, Go, Java, JavaScript, PHP, Python, R, Ruby, Rust source: README
    Check or rule format
    TOML config file osv-scanner.toml (for example, ignored vulnerability IDs) source: Docs: Configuration
    CI integration
    Reusable GitHub Actions workflows (pull request scan, full scan) source: Docs: GitHub Action
    Report formats
    Table, Markdown table, vertical, HTML, JSON, SARIF, SPDX, CycloneDX (--format flag) source: Docs: Output
    Install method
    Prebuilt binary per platform from GitHub releases source: README
  9. Nikto

    Command-line web server scanner in Perl with tunable test classes, evasion options and several report formats. README, read 2026-09-22

    Scan targets
    Web servers: potentially dangerous files or programs, outdated server components source: Docs: Overview & Description
    Languages or files analysed
    Server configuration items such as multiple index files and HTTP server options source: Docs: Overview & Description
    Check or rule format
    CSV scan database (db_tests) with a response-matching mini-DSL source: Docs: Scan Database Syntax
    Report formats
    CSV, JSON, HTML, XML, plain text, SQL (-Format option) source: README
    Install method
    Docker image hackllc/nikto (also ghcr.io/sullo/nikto) source: README
  10. garak

    Command-line scanner that probes LLMs for prompt injection, jailbreaks, data leakage and other failure modes. README, read 2026-09-22

    Scan targets
    LLMs and dialog systems reached through generators source: README
    Languages or files analysed
    LLM generations, checked by detectors for failure modes source: README
    Check or rule format
    CLI options (--target_type, --spec); YAML or JSON config files; plugin config items source: Docs: Configuring garak
    Report formats
    JSONL report, HTML report, JSONL hit log source: Docs: Reporting
    Install method
    pip (python -m pip install -U garak), or from source source: README
  11. Bandit

    Security linter from PyCQA that scans Python source through its AST to find common security issues. README, read 2026-09-22

    Scan targets
    Python code, for common security issues source: README
    Languages or files analysed
    Python files, parsed into an abstract syntax tree (AST) source: README
    Check or rule format
    Python test plugins registered through the bandit.plugins entry point source: Docs: Test Plugins
    CI integration
    GitHub Actions code scanning workflow with PyCQA/bandit-action source: Docs: GitHub Actions Workflow for Bandit
    Report formats
    CSV, custom, HTML, JSON, SARIF, screen, text, XML, YAML (-f option) source: Docs: bandit man page
    Install method
    pip (pip install bandit) source: Docs: Getting Started
  12. AFL++

    Fork of Google's AFL fuzzer with compiler instrumentation, custom modules, and guides for source, binary-only and network targets. README, read 2026-09-22

    Scan targets
    Programs or libraries compiled with afl-cc source: README
    Languages or files analysed
    Targets instrumented with LLVM or the GCC plugin; binaries through QEMU, FRIDA or unicorn mode source: Docs: Important features of AFL++
    Check or rule format
    Seed input files in a directory (-i), with an optional dictionary file (-x) source: README
    CI integration
    CI fuzzing section in the fuzzing in depth guide source: Docs: Fuzzing in depth
    Report formats
    Crash and hang inputs in crashes/ and hangs/ under the output directory source: README
    Install method
    Docker image aflplusplus/aflplusplus (x86_64 and arm64) source: README
  13. OWASP Nettacker

    Python framework for automated penetration testing and information gathering, with modular scans, a CLI, REST API and web UI. README, read 2026-09-22

    Scan targets
    IPv4 addresses, IP ranges, CIDR blocks, domain names and HTTP/HTTPS URLs source: README
    Languages or files analysed
    Services over HTTP/HTTPS, FTP, SSH, SMB, SMTP, ICMP, TELNET and XML-RPC source: README
    Check or rule format
    Declarative YAML module templates under nettacker/modules/ source: Docs: Modules
    CI integration
    CI/CD pipeline use through stored scan history and comparison (README use case) source: README
    Report formats
    HTML (with graph), CSV, JSON, SARIF, DefectDojo-compatible JSON source: Docs: Usage
    Install method
    Docker image owasp/nettacker source: README
  14. Honggfuzz

    Security-oriented coverage-feedback fuzzer with C and C++ compiler wrappers, for Linux, macOS, Android, BSD and Windows through Cygwin. README, read 2026-09-22

    Scan targets
    Programs, and APIs tested in-process (persistent fuzzing) source: README
    Languages or files analysed
    C and C++ targets built with the hfuzz-clang and hfuzz-clang++ wrappers source: README
    Check or rule format
    Input corpus directory, which can be empty source: README
    Report formats
    Report file HONGGFUZZ.REPORT.TXT in the working directory (--report option) source: Docs: USAGE
    Install method
    Build from source with make, which creates compiler wrappers in hfuzz_cc/ source: README
  15. RESTler

    Stateful REST API fuzzer that generates and runs tests from an OpenAPI specification to find service bugs. README, read 2026-09-22

    Scan targets
    Cloud services through their REST APIs source: README
    Languages or files analysed
    OpenAPI (Swagger) definitions in JSON or YAML source: README
    Check or rule format
    Grammar files (grammar.py, grammar.json) and dict.json generated by the compiler source: Docs: Compiling
    Report formats
    runSummary.json of HTTP error response codes received source: Docs: Fuzzing
    Install method
    Docker image built from the repository (docker build -t restler .) source: README
  16. Atheris

    Coverage-guided fuzzing engine for Python code and native CPython extensions, based on libFuzzer. README, read 2026-09-22

    Scan targets
    Python code and native extensions written for CPython source: README
    Languages or files analysed
    Python bytecode, instrumented for coverage source: README
    Check or rule format
    Python code: a fuzzer entry point function passed to atheris.Setup() source: README
    CI integration
    OSS-Fuzz, a continuous fuzzing service for open source projects source: README
    Report formats
    HTML coverage report through coverage.py (python3 -m coverage html) source: README
    Install method
    pip (pip3 install atheris) source: README
  17. EvoMaster

    AI-driven fuzzer that generates system-level test suites for REST, GraphQL and RPC APIs. README, read 2026-09-22

    Scan targets
    Web APIs; checks for 500 status codes, schema mismatches, BOLA access violations, SQL Injection source: README
    Languages or files analysed
    JVM bytecode (Java, Kotlin) in white-box mode source: README
    Check or rule format
    Tests generated automatically by an evolutionary algorithm, written out as executable test suites source: README
    CI integration
    Custom GitHub Action (WebFuzzing/evomaster-action) source: README
    Report formats
    Interactive HTML web report (index.html) source: README
    Install method
    pip (pip install evomaster); Docker image webfuzzing/evomaster; uber JAR source: README
  18. OWASP dependency-check

    Archived repository of OWASP dependency-check, a dependency vulnerability scanner that moved to github.com/dependency-check/DependencyCheck. README, read 2026-09-22

    Scan targets
    A project's dependencies, for publicly disclosed vulnerabilities source: Docs: Dependency-Check README (moved repository)
    Languages or files analysed
    Archives, JAR and WAR files, .NET assemblies, MSBuild projects, package.json and npm lock files (file type analyzers) source: Docs: File Type Analyzers
    Check or rule format
    Suppression XML files for false positives (--suppression) source: Docs: Command Line Arguments
    Report formats
    HTML, XML, CSV, JSON, JUnit, SARIF, Jenkins, GitLab (--format) source: Docs: Command Line Arguments
    Install method
    Homebrew (brew install dependency-check) source: Docs: Dependency-Check README (moved repository)

Comparisons in this category