
Nuclei
Fast, template-driven vulnerability scanner with zero false positives
- Stars
- 25,726
- License
- MIT
- Last commit
- 4 days ago
Explore leading tools in the Application Security Testing (SAST/DAST/SCA) category, including open-source options and SaaS products. Compare features, use cases, and find the best fit for your workflow.
10+ open-source projects · 6 SaaS products
These projects are active, self-hostable choices for knowledge management teams evaluating alternatives to SaaS tools.

Fast, template-driven vulnerability scanner with zero false positives

Automated web app security scanner for developers and pentesters

Comprehensive Perl-based web server vulnerability scanner that detects misconfigurations and known exploits

Comprehensive vulnerability scanner for code, containers, and licenses

Detect known vulnerabilities in project dependencies automatically.

Intelligent Ruby scanner for dynamic web application security
Fast, template-driven vulnerability scanner with zero false positives
Dependency-Check scans project libraries, maps them to CPE identifiers, and reports associated CVEs, helping teams identify and remediate known security flaws across multiple ecosystems.
Understand the commercial incumbents teams migrate from and how many open-source alternatives exist for each product.
Web vulnerability scanner for automated security testing of websites and web apps
Automated web application and infrastructure vulnerability scanning platform
Web application security testing platform
Cloud‑native application security platform with SAST, SCA, DAST, and more
Secret scanning tool for detecting exposed credentials in code repositories
Application security platform for vulnerability scanning and testing
Acunetix is a web vulnerability scanner that automatically tests websites and web applications for over 6,500 security vulnerabilities. It features advanced crawling and audit tools to identify issues like SQL injection, XSS, and other exploits, helping organizations remediate web security risks.
Frequently replaced when teams want private deployments and lower TCO.
Browse neighbouring categories in Security to widen your evaluation.