Category guides · published
"Best open source security testing tools": 18 listed, sorted by GitHub stars
Metrics as of , from the GitHub or GitLab API of each repository. Refreshed monthly.
The security category on FreeQATools lists open-source scanners and fuzzers used in application security testing. The table is sorted by GitHub stars on each tool's fetch date, which is a count and not a quality judgement. The sections below group the tools by documented scan target, check format, report output and CI support.
What each tool scans
Several scanners target running web applications and servers. ZAP scans web applications. Nikto looks for potentially dangerous files and outdated components on web servers. ffuf fuzzes content paths, virtual hosts, GET parameters and POST data. sqlmap tests GET and POST parameters plus cookie, User-Agent and Referer header values.
Nuclei scans URLs and hosts from a single target or a list file. The Nuclei README also lists OpenAPI, Swagger, Burp and raw HTTP input files. OWASP Nettacker accepts IPv4 addresses, IP ranges, CIDR blocks, domain names and HTTP or HTTPS URLs.
API definitions drive other tools. RESTler reads OpenAPI definitions to fuzz REST APIs. EvoMaster checks web APIs for 500 status codes, schema mismatches, access violations and SQL injection. The ZAP API scan accepts OpenAPI, Swagger or GraphQL definitions.
Code, dependencies, repositories and images are the target of other scanners. Bandit parses Python files into an abstract syntax tree. Gitleaks finds secrets in git repositories, files and stdin. OSV-Scanner checks project dependencies against the OSV database. Trivy scans container images, filesystems, remote Git repositories, VM images and Kubernetes.
Other entries fuzz programs and code directly. AFL++ instruments targets with LLVM or GCC and reaches binaries through QEMU, FRIDA or unicorn mode. Honggfuzz builds C and C++ targets with its compiler wrappers. Atheris fuzzes Python code and native CPython extensions.
LLMs and dialog systems are the target of garak. Promptfoo documents red teaming and vulnerability scanning for LLM apps.
Check and rule formats
Nuclei templates are YAML. OWASP Nettacker modules are declarative YAML. Gitleaks rules are TOML entries with Go regular expressions. Custom Trivy misconfiguration checks are written in Rego. Bandit tests are Python plugins.
Nikto keeps most of its tests in a CSV scan database.
Fuzzers and test generators are set up in other ways. AFL++ reads seed files from an input directory. Atheris fuzzers are Python entry point functions. The RESTler compiler generates grammar files from the API definition. EvoMaster generates test suites with an evolutionary algorithm.
Reports and CI
Bandit documents SARIF output. Gitleaks documents SARIF output. OSV-Scanner documents SARIF output. Trivy documents SARIF output. Nuclei exports results in SARIF format.
OWASP Nettacker documents SARIF output. The ZAP report templates include SARIF JSON. AFL++ writes crash and hang inputs to its output directory. Honggfuzz writes a report file to the working directory.
Bandit documents a GitHub Actions workflow. Gitleaks documents a GitHub Action. OSV-Scanner offers reusable GitHub Actions workflows. Trivy documents a GitHub Action.
ZAP lists packaged scans for GitHub Actions. EvoMaster documents a GitHub Action. Promptfoo documents a GitHub Action. A comparison row with no documented value is marked not documented instead of inferred (comparison method).
ffuf has no documented CI setup. garak has no documented CI setup. Honggfuzz has no documented CI setup. Nikto has no documented CI setup. RESTler has no documented CI setup.
OWASP dependency-check is archived on its host. Its catalogue entry notes that the project moved to a new repository (tool page). Archived entries also appear on the archived page.
How this list is sorted
The quoted title is a search query, not a verdict. FreeQATools does not rank tools by opinion. The list below is sorted by GitHub stars, descending, as fetched from the repository host API on the date shown with each value.
Stars count how many accounts have starred a repository. They say nothing about fit for a given project, so the documented facts under each tool are the part to compare.
Every tool here meets the inclusion rules: an OSI-approved license, a public repository, software testing or quality as its primary purpose and at least one release or tag. Each status badge follows the status rules on the methodology page.
Open-source security testing tools by GitHub stars
| sqlmap | 38,4921 | 2026-01-0111.10 | 2026-09-201 | GPL-2.0-or-later | Python | active |
|---|---|---|---|---|---|---|
| Trivy | 38,0091 | 2026-08-141v0.74.0 | 2026-09-221 | Apache-2.0 | Go | active |
| Nuclei | 31,4311 | 2026-08-081v3.11.1 | 2026-09-221 | MIT | Go | active |
| Gitleaks | 29,4281 | 2026-03-211v8.30.1 | 2026-07-221 | MIT | Go | active |
| Promptfoo | 25,3711 | 2026-09-1810.123.1 | 2026-09-221 | MIT | TypeScript | active |
| ffuf | 16,7031 | 2026-09-091v2.3.0 | 2026-09-091 | MIT | Go | active |
| ZAP | 15,8041 | 2025-12-151v2.17.0 | 2026-09-171 | Apache-2.0 | Java | active |
| OSV-Scanner | 11,0731 | 2026-09-141v2.6.0 | 2026-09-221 | Apache-2.0 | Go | active |
| Nikto | 10,7361 | 2026-07-3112.6.1 | 2026-08-151 | GPL-3.0-only | Perl | active |
| garak | 9,3301 | 2026-09-091v0.17.0 | 2026-09-161 | Apache-2.0 | Python | active |
| Bandit | 8,2781 | 2026-02-2511.9.4 | 2026-09-211 | Apache-2.0 | Python | active |
| AFL++ | 6,7651 | 2026-09-021v5.03c | 2026-09-021 | AGPL-3.0 | C | active |
| OWASP Nettacker | 5,6121 | 2026-08-2410.4.1 | 2026-09-221 | Apache-2.0 | Python | active |
| Honggfuzz | 3,3831 | 2024-07-201oss-fuzz | 2026-06-191 | Apache-2.0 | C | slow |
| RESTler | 2,9461 | 2025-01-301v9.3.1 | 2026-02-131 | MIT | Python | slow |
| Atheris | 1,6781 | 2025-11-2513.0.0 | 2026-06-171 | Apache-2.0 | Python | slow |
| EvoMaster | 7821 | 2026-09-151v6.2.0 | 2026-09-221 | LGPL-3.0 | Kotlin | active |
| OWASP dependency-check | 541 | 2025-02-171v12.1.0 | 2025-02-171 | Apache-2.0 | Java | archived |
1 Fetched from the GitHub or GitLab API on . Hover a value for its own date.
Filters for language, license and status are on the security testing category page.
Tools in this list
Each entry gives the tool's one-line summary from its README and the facts its documentation states for this category, each with its source. Facts that are not documented are left out here and marked on the comparison pages.
sqlmap
Command-line penetration testing tool that detects and exploits SQL injection flaws in database-backed applications. README, read 2026-09-22
- Scan targets
- Web application parameters: GET, POST, cookie, User-Agent and Referer values source: Docs: Features
- Languages or files analysed
- Database back ends including MySQL, Oracle, PostgreSQL, Microsoft SQL Server, SQLite and others listed source: Docs: Features
- Check or rule format
- Command-line options and switches; tamper scripts that transform payloads source: Docs: Usage
- CI integration
- JSON run report (--report-json) for feeding findings into CI pipelines source: Docs: Usage
- Report formats
- JSON run report (--report-json); dumped data as CSV, HTML, SQLite or JSONL source: Docs: Usage
- Install method
- Git clone of the repository, or tarball and zipball downloads; runs on Python 2.7 and 3.x source: README
Trivy
Security scanner for container images, filesystems, Git repositories, VM images and Kubernetes, covering CVEs, misconfigurations, secrets and licenses. README, read 2026-09-22
- Scan targets
- Container images, filesystems, remote Git repositories, virtual machine images, Kubernetes source: README
- Languages or files analysed
- OS packages, language-specific packages, IaC files, Kubernetes clusters source: Docs: Scanning Coverage
- Check or rule format
- Custom misconfiguration checks written in Rego source: Docs: Custom Checks
- CI integration
- GitHub Action aquasecurity/trivy-action; community CircleCI orb, Buildkite plugin and GitLab templates source: Docs: CI/CD Integrations
- Report formats
- Table, JSON, SARIF, template, SBOM, GitHub dependency snapshot source: Docs: Reporting
- Install method
- Homebrew (brew install trivy); Docker image aquasec/trivy; release binaries source: README
Nuclei
Template-based vulnerability scanner that runs YAML templates over HTTP, DNS, TCP, SSL and other protocols from a CLI. README, read 2026-09-22
- Scan targets
- Target URLs and hosts, from a single target or a list file source: README
- Languages or files analysed
- Target lists plus Burp, JSONL, YAML, OpenAPI, Swagger and raw HTTP input files source: README
- Check or rule format
- YAML templates source: README
- CI integration
- CI/CD pipeline use for vulnerability detection and regression testing source: README
- Report formats
- JSON, JSONL, Markdown, SARIF, PDF source: README
- Install method
- go install -v github.com/projectdiscovery/nuclei/v3/cmd/nuclei@latest (Go 1.24.2 or later) source: README
Gitleaks
CLI that detects secrets such as passwords, API keys and tokens in git repositories, files and stdin. README, read 2026-09-22
- Scan targets
- Secrets such as passwords, API keys and tokens in git repositories, files and stdin source: README
- Languages or files analysed
- Git commit patches (via git log -p), directories and files source: README
- Check or rule format
- TOML config file with [[rules]] entries using Go regular expressions source: README
- CI integration
- GitHub Action (Gitleaks-Action); pre-commit hook source: README
- Report formats
- JSON, CSV, JUnit, SARIF, custom template source: README
- Install method
- Homebrew (brew install gitleaks); Docker images zricethezav/gitleaks and ghcr.io/gitleaks/gitleaks; Go source build; release binaries source: README
Promptfoo
CLI and library for LLM evaluations, side-by-side model comparison and red teaming of LLM-based applications. README, read 2026-09-22
- Scan targets
- LLM apps, through red teaming and vulnerability scanning source: README
- Languages or files analysed
- Any LLM API or programming language source: README
- Check or rule format
- YAML config file (promptfooconfig.yaml) with prompts, providers and test cases source: Docs: Getting Started
- CI integration
- GitHub Actions guide and GitHub Marketplace action; CI/CD guide for other platforms source: Docs: CI/CD Integration for LLM Evaluation and Security
- Report formats
- HTML, JSON, CSV, JUnit XML (promptfoo eval --output) source: Docs: Output Formats
- Install method
- npm (npm install -g promptfoo), Homebrew (brew install promptfoo), pip (pip install promptfoo) source: README
ffuf
Go command-line web fuzzer for content, virtual host and parameter discovery using wordlists. README, read 2026-09-22
- Scan targets
- Web servers: content paths, virtual hosts, GET parameters and POST data source: README
- Languages or files analysed
- Wordlists (-w), raw HTTP request files (-request), command output (-input-cmd) source: README
- Check or rule format
- Command-line flags with the FUZZ keyword; ffufrc configuration files source: README
- Report formats
- JSON, ejson, HTML, Markdown, CSV, ecsv source: README
- Install method
- Release binaries; Scoop, Winget, Homebrew; go install github.com/ffuf/ffuf/v2@latest source: README
ZAP
Open source web application security scanner for automated scans and manual penetration testing. README, read 2026-09-22
- Scan targets
- Web applications source: README
- Languages or files analysed
- API definitions in OpenAPI / Swagger or GraphQL (API Scan) source: Docs: ZAP Docker Documentation
- Check or rule format
- YAML plan file (Automation Framework) source: Docs: Automation Framework
- CI integration
- GitHub Actions packaged scans on the GitHub Marketplace; Docker packaged scans source: Docs: Automate ZAP
- Report formats
- Report templates including SARIF JSON, HTML, JSON, Markdown, PDF and XML source: Docs: Report Generation
- Install method
- Docker image zaproxy/zap-stable (also ghcr.io/zaproxy/zaproxy:stable) source: Docs: Download ZAP
OSV-Scanner
CLI that checks project dependencies, container images and Linux OS packages against the OSV vulnerability database. README, read 2026-09-22
- Scan targets
- Project dependencies, checked against the OSV database source: README
- Languages or files analysed
- Dependencies in C/C++, Dart, Elixir, Go, Java, JavaScript, PHP, Python, R, Ruby, Rust source: README
- Check or rule format
- TOML config file osv-scanner.toml (for example, ignored vulnerability IDs) source: Docs: Configuration
- CI integration
- Reusable GitHub Actions workflows (pull request scan, full scan) source: Docs: GitHub Action
- Report formats
- Table, Markdown table, vertical, HTML, JSON, SARIF, SPDX, CycloneDX (--format flag) source: Docs: Output
- Install method
- Prebuilt binary per platform from GitHub releases source: README
Nikto
Command-line web server scanner in Perl with tunable test classes, evasion options and several report formats. README, read 2026-09-22
- Scan targets
- Web servers: potentially dangerous files or programs, outdated server components source: Docs: Overview & Description
- Languages or files analysed
- Server configuration items such as multiple index files and HTTP server options source: Docs: Overview & Description
- Check or rule format
- CSV scan database (db_tests) with a response-matching mini-DSL source: Docs: Scan Database Syntax
- Report formats
- CSV, JSON, HTML, XML, plain text, SQL (-Format option) source: README
- Install method
- Docker image hackllc/nikto (also ghcr.io/sullo/nikto) source: README
garak
Command-line scanner that probes LLMs for prompt injection, jailbreaks, data leakage and other failure modes. README, read 2026-09-22
- Scan targets
- LLMs and dialog systems reached through generators source: README
- Languages or files analysed
- LLM generations, checked by detectors for failure modes source: README
- Check or rule format
- CLI options (--target_type, --spec); YAML or JSON config files; plugin config items source: Docs: Configuring garak
- Report formats
- JSONL report, HTML report, JSONL hit log source: Docs: Reporting
- Install method
- pip (python -m pip install -U garak), or from source source: README
Bandit
Security linter from PyCQA that scans Python source through its AST to find common security issues. README, read 2026-09-22
- Scan targets
- Python code, for common security issues source: README
- Languages or files analysed
- Python files, parsed into an abstract syntax tree (AST) source: README
- Check or rule format
- Python test plugins registered through the bandit.plugins entry point source: Docs: Test Plugins
- CI integration
- GitHub Actions code scanning workflow with PyCQA/bandit-action source: Docs: GitHub Actions Workflow for Bandit
- Report formats
- CSV, custom, HTML, JSON, SARIF, screen, text, XML, YAML (-f option) source: Docs: bandit man page
- Install method
- pip (pip install bandit) source: Docs: Getting Started
AFL++
Fork of Google's AFL fuzzer with compiler instrumentation, custom modules, and guides for source, binary-only and network targets. README, read 2026-09-22
- Scan targets
- Programs or libraries compiled with afl-cc source: README
- Languages or files analysed
- Targets instrumented with LLVM or the GCC plugin; binaries through QEMU, FRIDA or unicorn mode source: Docs: Important features of AFL++
- Check or rule format
- Seed input files in a directory (-i), with an optional dictionary file (-x) source: README
- CI integration
- CI fuzzing section in the fuzzing in depth guide source: Docs: Fuzzing in depth
- Report formats
- Crash and hang inputs in crashes/ and hangs/ under the output directory source: README
- Install method
- Docker image aflplusplus/aflplusplus (x86_64 and arm64) source: README
OWASP Nettacker
Python framework for automated penetration testing and information gathering, with modular scans, a CLI, REST API and web UI. README, read 2026-09-22
- Scan targets
- IPv4 addresses, IP ranges, CIDR blocks, domain names and HTTP/HTTPS URLs source: README
- Languages or files analysed
- Services over HTTP/HTTPS, FTP, SSH, SMB, SMTP, ICMP, TELNET and XML-RPC source: README
- Check or rule format
- Declarative YAML module templates under nettacker/modules/ source: Docs: Modules
- CI integration
- CI/CD pipeline use through stored scan history and comparison (README use case) source: README
- Report formats
- HTML (with graph), CSV, JSON, SARIF, DefectDojo-compatible JSON source: Docs: Usage
- Install method
- Docker image owasp/nettacker source: README
Honggfuzz
Security-oriented coverage-feedback fuzzer with C and C++ compiler wrappers, for Linux, macOS, Android, BSD and Windows through Cygwin. README, read 2026-09-22
- Scan targets
- Programs, and APIs tested in-process (persistent fuzzing) source: README
- Languages or files analysed
- C and C++ targets built with the hfuzz-clang and hfuzz-clang++ wrappers source: README
- Check or rule format
- Input corpus directory, which can be empty source: README
- Report formats
- Report file HONGGFUZZ.REPORT.TXT in the working directory (--report option) source: Docs: USAGE
- Install method
- Build from source with make, which creates compiler wrappers in hfuzz_cc/ source: README
RESTler
Stateful REST API fuzzer that generates and runs tests from an OpenAPI specification to find service bugs. README, read 2026-09-22
- Scan targets
- Cloud services through their REST APIs source: README
- Languages or files analysed
- OpenAPI (Swagger) definitions in JSON or YAML source: README
- Check or rule format
- Grammar files (grammar.py, grammar.json) and dict.json generated by the compiler source: Docs: Compiling
- Report formats
- runSummary.json of HTTP error response codes received source: Docs: Fuzzing
- Install method
- Docker image built from the repository (docker build -t restler .) source: README
Atheris
Coverage-guided fuzzing engine for Python code and native CPython extensions, based on libFuzzer. README, read 2026-09-22
- Scan targets
- Python code and native extensions written for CPython source: README
- Languages or files analysed
- Python bytecode, instrumented for coverage source: README
- Check or rule format
- Python code: a fuzzer entry point function passed to atheris.Setup() source: README
- CI integration
- OSS-Fuzz, a continuous fuzzing service for open source projects source: README
- Report formats
- HTML coverage report through coverage.py (python3 -m coverage html) source: README
- Install method
- pip (pip3 install atheris) source: README
EvoMaster
AI-driven fuzzer that generates system-level test suites for REST, GraphQL and RPC APIs. README, read 2026-09-22
- Scan targets
- Web APIs; checks for 500 status codes, schema mismatches, BOLA access violations, SQL Injection source: README
- Languages or files analysed
- JVM bytecode (Java, Kotlin) in white-box mode source: README
- Check or rule format
- Tests generated automatically by an evolutionary algorithm, written out as executable test suites source: README
- CI integration
- Custom GitHub Action (WebFuzzing/evomaster-action) source: README
- Report formats
- Interactive HTML web report (index.html) source: README
- Install method
- pip (pip install evomaster); Docker image webfuzzing/evomaster; uber JAR source: README
OWASP dependency-check
Archived repository of OWASP dependency-check, a dependency vulnerability scanner that moved to github.com/dependency-check/DependencyCheck. README, read 2026-09-22
- Scan targets
- A project's dependencies, for publicly disclosed vulnerabilities source: Docs: Dependency-Check README (moved repository)
- Languages or files analysed
- Archives, JAR and WAR files, .NET assemblies, MSBuild projects, package.json and npm lock files (file type analyzers) source: Docs: File Type Analyzers
- Check or rule format
- Suppression XML files for false positives (--suppression) source: Docs: Command Line Arguments
- CI integration
- Jenkins plugin source: Docs: Dependency-Check README (moved repository)
- Report formats
- HTML, XML, CSV, JSON, JUnit, SARIF, Jenkins, GitLab (--format) source: Docs: Command Line Arguments
- Install method
- Homebrew (brew install dependency-check) source: Docs: Dependency-Check README (moved repository)