PyPI95Exceptionalhealth index
cve-search/vulnerability-lookupVulnerability-Lookup facilitates quick correlation of vulnerabilities from various sources, independent of vulnerability IDs, and streamlines the management of Coordinated Vulnerability Disclosure (CVD).
Python · HTML★ 547Jul 19, 2026
npm94Exceptionalhealth index

dubzzz/fast-checkProperty based testing framework for JavaScript (like QuickCheck) written in TypeScript
TypeScript★ 5,093↓ 123M/moAug 12, 2026
PyPI · npm94Exceptionalhealth index
msaad00/agent-bomOpen security scanner and self-hosted control plane for AI, MCP, and cloud. One evidence model — run scans in your environment, centralize findings, govern in your VPC.
Python · TypeScript★ 28↓ 5,301/moJul 16, 2026
npm88Excellenthealth index
OWASP/cve-lite-cliFast, developer-friendly JS/TS dependency vulnerability scanner with local lockfile scanning, OSV matching, direct vs transitive visibility, --fix, JSON output, and practical remediation guidance.
TypeScript★ 635↓ 20.2K/moJul 16, 2026
Go88Excellenthealth index
l3montree-dev/devguardDevGuard Backend - Secure your Software Supply Chain - Attestation-based compliance as Code, manage your CVEs seamlessly, Integrate your Vulnerability Scanners, Security Framework Documentation made easy - OWASP Incubating Project
Go★ 146Jul 17, 2026
PyPI87Excellenthealth index
aboutcode-org/vulnerablecodeA free and open vulnerabilities database and the packages they impact. And the tools to aggregate and correlate these vulnerabilities. Sponsored by NLnet https://nlnet.nl/project/vulnerabilitydatabase/ for https://www.aboutcode.org/ Chat at https://gitter.im/aboutcode-org/vulnerablecode Docs at https://vulnerablecode.readthedocs.org/
Python · HTML★ 693Jul 20, 2026
Go87Excellenthealth index
l3montree-dev/flawfixDevGuard Backend - Secure your Software Supply Chain - Attestation-based compliance as Code, manage your CVEs seamlessly, Integrate your Vulnerability Scanners, Security Framework Documentation made easy - OWASP Incubating Project
Go★ 146Jul 18, 2026
PyPI · npm84Excellenthealth index

owasp-dep-scan/dep-scanOWASP dep-scan is a next-generation security and risk audit tool based on known vulnerabilities, advisories, and license limitations for project dependencies. Both local repositories and container images are supported as the input, and the tool is ideal for integration.
Python★ 1,281↓ 10.9K/moAug 24, 2026
PyPI83Excellenthealth index
Python★ 6,698↓ 917/moAug 29, 2026
crates.io81Excellenthealth index
guacsec/trustifySBOM analysis platform for storing, correlating, and querying software bill of materials and security advisories (CSAF/VEX, OSV, CVE) at scale.
Rust★ 61Jul 17, 2026
Packagist69Goodhealth index

dgtlss/wardenA Laravel package that proactively monitors your dependencies for security vulnerabilities by running automated composer audits and sending notifications via webhooks and email
PHP★ 97↓ 7,100/moSep 5, 2026
goklab/guardvibeSecurity infrastructure your AI can't be — deterministic, daily CVE intel past your model's training cutoff, whole-repo-aware, author-independent, and shift-left: secure_prompt secures the prompt before code generation. The security MCP for vibe coding: 450 rules, 39 tools, CLI + doctor for Next.js, Supabase, Clerk, Stripe, Prisma, Hono & MCP.
TypeScript★ 4↓ 6,125/moJul 17, 2026
patchstack/connectPatchstack connector for JavaScript applications. Scans your lockfile and reports installed packages to Patchstack for vulnerability monitoring.
TypeScript · JavaScript★ 1↓ 4,203/moJul 20, 2026
ra1nb0rn/search_vulnsA modular tool to search for known vulnerabilities, exploits and more across various data sources
Python · CSS · JavaScript★ 91↓ 3,793/moJul 18, 2026
famclaw/honeybadgerSecurity scanner for AI agent skills and MCP servers. Detects secrets, CVEs, supply chain attacks, and prompt injection in SKILL.md files before they're installed. Pre-install gate for Claude Code, OpenClaw, PicoClaw, NanoBot, FamClaw, and CI/CD pipelines. Single Go binary, MIT licensed.
Go★ 3Jul 17, 2026
Go★ 15Jul 30, 2026

kidoz/go-vulnersGo client library for the Vulners vulnerability database API — search, audit, SBOM, VScanner, and more
Go★ 0Aug 22, 2026
kidoz/vulners-cliCLI vulnerability scanner powered by Vulners — search, audit, scan, offline mode
Go★ 6Jul 17, 2026
Go · Shell★ 0Aug 5, 2026
npm54Moderatehealth index
badchars/cve-mcp23-tool MCP server for CVE & vulnerability intelligence. NVD, EPSS, CISA KEV, GitHub Advisory, OSV — unified in one server. Risk scoring, bulk triage, exploit search. 2 dependencies, runs with npx.
TypeScript★ 18↓ 1,669/moAug 4, 2026
krisiasty/vcheckVulnerability detection and mitigation tool for Copy Fail and Dirty Frag bugs (CVE-2026-31431, CVE-2026-43284, CVE-2026-43500)
Go★ 2Jul 18, 2026
npm51Moderatehealth index

nsasoft/nsauditor-aiNSAuditor AI — Open-source, AI-powered network security scanner. 27 plugins, CVE matching, MITRE ATT&CK mapping, verified vulnerabilities, continuous monitoring, MCP integration. Zero data exfiltration. MIT licensed.
JavaScript★ 20↓ 3,215/moSep 6, 2026
safetylab/ShadowSecurityScannerFree, open-source network vulnerability scanner & penetration testing tool that ranks findings by real-world exploitability (EPSS + CISA KEV). Single desktop app for Windows, macOS, Linux. No cloud, no telemetry. MIT.
Go★ 0Jul 21, 2026

nsasoft/nsauditor-ai-agent-skillAI Agent Skill for NSAuditor AI — gives any AI coding agent built-in knowledge of NSAuditor's MCP tools, schemas, plugins, and security audit workflows. Works with Claude Code, Cursor, Windsurf, and any MCP-aware agent.
JavaScript★ 4↓ 7,235/moSep 6, 2026
TypeScript★ 0↓ 6,697/moAug 5, 2026
PyPI28At Riskhealth index
Python★ 486Aug 4, 2026
TypeScript★ 0↓ 3,498/moAug 5, 2026
TypeScript★ 0↓ 2,131/moAug 5, 2026