Showing 32 of 32 projects
A comprehensive security scanner that finds vulnerabilities, misconfigurations, secrets, and SBOMs in containers, Kubernetes, code, and clouds.
A fast, customizable vulnerability scanner with a YAML-based DSL, powered by a global security community.
A security auditing and hardening tool for UNIX-based systems, performing in-depth scans and compliance testing.
A free, open-source web application security scanner for finding vulnerabilities during development and testing.
A free, open-source WordPress security scanner for professionals and site maintainers to test website vulnerabilities.
A static analysis tool that scans Go source code for security vulnerabilities by analyzing the AST and SSA representations.
Bandit is a tool designed to find common security issues in Python code.
A static analysis security vulnerability scanner for Ruby on Rails applications.
A source code analyzer that identifies features and characteristics in software components using static analysis and a JSON rules engine.
A Golang command-line utility that uses Chrome Headless to capture website screenshots and gather web data.
A scanner that detects JavaScript libraries with known vulnerabilities and can generate a Software Bill of Materials (SBOM).
A high-performance offensive security tool for reconnaissance, vulnerability scanning, and information gathering.
An Nmap NSE script that transforms nmap into a vulnerability scanner using offline vulnerability databases.
A simple IOC and YARA scanner for detecting malware and security threats via file names, hashes, YARA rules, and C2 connections.
Static code analysis tool for Kubernetes YAML and Helm charts that provides recommendations to improve reliability and security.
A semi-automatic OSINT framework and package manager for gathering intelligence and enumerating attack surfaces.
Monitor GitHub for sensitive information leaks in near real-time and send alert notifications.
A Python tool that scans HTTP servers for publicly accessible secret files and security vulnerabilities like git repos and backup files.
A Burp Suite extension for advanced GraphQL security testing, featuring vulnerability scanning, batch attacks, and schema analysis.
A static analysis tool that detects Common Weakness Enumerations (CWEs) in binary executables across multiple CPU architectures.
A modular vulnerability scanner that checks website security and automatically generates easy-to-read reports for organizations.
A friendly automotive security exploration tool for the CAN bus, enabling zero-knowledge discovery of services and vulnerabilities.
A static analysis security scanner for Ruby web applications, supporting Rails, Sinatra, and Padrino frameworks.
A static application security testing (SAST) CLI tool that scans source code for OWASP Top 10 vulnerabilities across multiple programming languages.
A bug hunting tool that scans websites for exposed .git repositories and dumps their contents for security analysis.
A static security scanner for PHP code that identifies potential vulnerabilities without executing the code.
A free and open-source scanner that identifies installed components, extensions, and files in Joomla CMS websites.
A self-hosted, single-container Docker monitoring dashboard with real-time metrics, anomaly detection, and Telegram alerts.
An Elixir wrapper for ClamAV that provides virus scanning capabilities for file uploads and system security.
A scanner to verify SHA256 compatibility of AWS agents, now archived and no longer maintained.
A fast security scanner that detects the Shai Hulud 2.0 npm supply chain attack by checking for malicious files, hashes, and compromised packages.
Fast, accurate scanner for the critical CVE-2025-55182 (React2Shell) RCE vulnerability in React Server Components.
Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.