Go97Exceptionalhealth index

projectdiscovery/nucleiNuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.
Go★ 30.3KAug 5, 2026
PyPI94Exceptionalhealth index

PyCQA/banditBandit is a tool designed to find common security issues in Python code.
Python★ 8,243↓ 29.1M/moAug 28, 2026
PyPI · npm94Exceptionalhealth index
msaad00/agent-bomOpen security scanner and self-hosted control plane for AI, MCP, and cloud. One evidence model — run scans in your environment, centralize findings, govern in your VPC.
Python · TypeScript★ 28↓ 5,301/moJul 16, 2026
PyPI · npm94Exceptionalhealth index
sattyamjjain/agent-audit-kitStatic scanner for MCP-connected AI agent pipelines — 271 rules across 12 categories, 12 compliance frameworks, OWASP Agentic 10/10 + MCP 10/10, GitHub Action, SARIF, public CVE-to-rule ledger.
Python★ 13↓ 2,808/moAug 2, 2026
PyPI92Excellenthealth index

Ostorlab/oxoOXO is a security scanning orchestrator for the modern age.
Python★ 581↓ 21.2K/moSep 5, 2026
PyPI91Excellenthealth index
Python★ 576Jul 17, 2026
Go91Excellenthealth index

praetorian-inc/juliusSimple LLM service identification - translate IP:Port to Ollama, vLLM, LiteLLM, or 60+ other AI services in seconds
Go★ 175Aug 8, 2026
RubyGems91Excellenthealth index

wpscanteam/wpscanWPScan WordPress security scanner. Written for security professionals and blog maintainers to test the security of their WordPress websites. Contact us via contact@wpscan.com
Ruby★ 9,742Aug 28, 2026
PyPI · crates.io · npm86Excellenthealth index

nyudenkov/pysentry🐍 Scan your Python dependencies for known security vulnerabilities with Rust-powered scanner
Rust★ 247↓ 95K/moAug 20, 2026
npm · PyPI84Excellenthealth index
openshield-org/openshieldOpen source CSPM for Azure - scan for misconfigurations and quantum-unsafe cryptography, map findings to CIS/NIST/ISO27001/SOC2, and fix them with one command
Python · JavaScript★ 55Aug 4, 2026
NuGet83Excellenthealth index

microsoft/ApplicationInspectorA source code analyzer built for surfacing features of interest and other characteristics to answer the question 'What's in the code?' quickly using static analysis with a json based rules engine. Ideal for scanning components before use or detecting feature level changes.
C#★ 4,395Aug 28, 2026
cpeoples/ansible-security-scanner🛡️ Static security scanner (SAST) for Ansible playbooks, roles, and collections. 1,000+ rules across 30+ categories detecting malicious code, RCE, hardcoded credentials, and supply-chain risk. Outputs SARIF, CycloneDX SBOM, and GitLab SAST. SLSA Build Level 3, Sigstore-signed.
Python★ 9↓ 1,928/moJul 17, 2026
Python★ 3Sep 5, 2026
PyPI · npm75Goodhealth index
gautamvarmadatla/mcpsafetywardenMCP servers expose tools with no information about what they actually do at runtime. mcpsafetywarden sits between your agent and any MCP server, profiling tool behavior, blocking destructive calls, and running active security audits before you trust them in a workflow.
Python★ 9↓ 2,923/moAug 1, 2026
Go · Python★ 12Jul 23, 2026
Packagist71Goodhealth index

ShieldCI/laravelAutomated code analysis for Laravel applications with 73 comprehensive analyzers covering security, performance, reliability, code quality, and best practices. Works with Laravel 9+.
PHP★ 2↓ 1,097/moAug 22, 2026
vigolium/vigoliumVigolium - High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision
Go★ 826Jul 15, 2026
npm · crates.io · Go +163Moderatehealth index
ashfordeOU/graspGRASP — Code architecture visualizer + 150-tool MCP server. Dependency graphs, security scanning, multimodal knowledge graph, ORM tracking, git change impact, graph schema v3. Works with GitHub, GitLab & local dirs. 35 languages. Zero data collection.
HTML · TypeScript · JavaScript★ 10↓ 1,162/moJul 27, 2026
famclaw/honeybadgerSecurity scanner for AI agent skills and MCP servers. Detects secrets, CVEs, supply chain attacks, and prompt injection in SKILL.md files before they're installed. Pre-install gate for Claude Code, OpenClaw, PicoClaw, NanoBot, FamClaw, and CI/CD pipelines. Single Go binary, MIT licensed.
Go★ 3Jul 17, 2026
PyPI62Moderatehealth index
Python★ 4↓ 2,911/moAug 18, 2026
rudrendupaul/tenantguardCLI security scanner for self-hosted multi-tenant AI-agent platforms. 16 fail-closed OPA/Rego rules catch tenant-isolation defects (sandbox scoping, SSRF, cross-tenant cron/auth, secret leakage). SARIF and JSON output for CI.
Go · Open Policy Agent★ 0Jul 15, 2026
Go · npm57Moderatehealth index
cyberspacesec/certificate-skillsAI-native certificate security toolkit — Skills, CLI, MCP server & Go SDK for SSL/TLS analysis, cyberspace mapping and PKI operations
Go★ 0Jul 20, 2026
PyPI · crates.io · Maven +257Moderatehealth index
mattybellx/ansedeFind authorization bugs before attackers do. Free SAST — IDOR detection, 100% CVE recall, 0% false positives. 5 languages. Fully offline.
Python · HTML★ 12Jul 17, 2026
npm54Moderatehealth index
sudoeren/arhuslocal-first security analysis for TypeScript & JavaScript
TypeScript★ 6↓ 2,972/moJul 17, 2026
Go · npm54Moderatehealth index
undont/supplyscanscan JavaScript lockfiles to detect supply chain vulnerabilities and known exploits
Go★ 0Jul 22, 2026
npm51Moderatehealth index

nsasoft/nsauditor-aiNSAuditor AI — Open-source, AI-powered network security scanner. 27 plugins, CVE matching, MITRE ATT&CK mapping, verified vulnerabilities, continuous monitoring, MCP integration. Zero data exfiltration. MIT licensed.
JavaScript★ 20↓ 3,215/moSep 6, 2026
Go · PyPI48Weakhealth index
Zayan-Mohamed/secscanSecScan is a fast, configurable secret scanning tool written in Go that detects API keys, tokens, credentials, and high-entropy secrets across source code and full Git history. Built for developers and CI pipelines, with strong defaults and low false positives.
Go · Shell · PowerShell★ 4Jul 20, 2026
safetylab/ShadowSecurityScannerFree, open-source network vulnerability scanner & penetration testing tool that ranks findings by real-world exploitability (EPSS + CISA KEV). Single desktop app for Windows, macOS, Linux. No cloud, no telemetry. MIT.
Go★ 0Jul 21, 2026

FYFran/ironwall8-step open-source security audit CLI. Secrets, SAST, dependency CVEs, IaC, supply chain. MIT. AI-assisted.
Java · HTML★ 0Sep 6, 2026
PHP★ 339↓ 277.7K/moAug 13, 2026