Top 23 Python vulnerability-scanner Projects
-
-
Kargo
Stop Scripting Promotions. Start Shipping with Kargo. Kargo automates promotion across dev, staging, and prod with approval gates and verification. Open source, built by the team behind Argo CD. Download now.
-
DeepAudit
DeepAudit:人人拥有的 AI 黑客战队,让漏洞挖掘触手可及。国内首个开源的代码漏洞挖掘多智能体系统。小白一键部署运行,自主协作审计 + 自动化沙箱 PoC 验证。支持 Ollama 私有部署 ,一键生成报告。支持中转站。让安全不再昂贵,让审计不再复杂。
Project mention: Show HN: DeepAudit – open-source auditing agent (LLMs and Static Analysis) | news.ycombinator.com | 2025-12-15 -
-
Nettacker
Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management
-
-
-
-
AppSignal
AppSignal knows why the f*#k it crashed. Stop vibe-debugging. Every exception, every backtrace, grouped so you see patterns, not noise.
-
pentest-ai
Offensive-security MCP server with 205 wrapped tools, 17 specialist agents, and 60 SPA-aware probes for OWASP Top 10. CLI + MCP, BYO LLM. No API key needed on MCP path.
Project mention: Show HN: Ptai – an MCP that chains low-sev findings into RCE | news.ycombinator.com | 2026-05-19 -
Secrover
Open-Source Security Reports, Made Simple - 100% free. No paywalls, just actionable insights.
-
agent-audit
Static security scanner for LLM agents — prompt injection, MCP config auditing, taint analysis. 51 rules mapped to OWASP Agentic Top 10 (2026). Works with LangChain, CrewAI, AutoGen.
Project mention: Show HN: Agent Audit – Open-source security scanner for AI agents | news.ycombinator.com | 2026-02-06- Static analysis limitations apply — can't catch runtime-only issues
*Some numbers from scanning open-source projects:*
I scanned 6 popular agent repos (OpenHands, SWE-agent, Gorilla, etc.). Found 617 findings total, 269 critical. Most common issue: tool functions that pass LLM-provided strings directly to dangerous sinks without validation.
Full report: https://github.com/HeadyZhang/agent-audit/blob/master/docs/r...
*Install:*
```
-
whalescan
Whalescan is a vulnerability scanner for Windows containers, which performs several benchmark checks, as well as checking for CVEs/vulnerable packages on the container
-
neural-network-hacking
Hacking the Singularity. Deep learning hacking. Weaponizing AI in Offensive security
-
Project mention: Tengu – An MCP server that turns Claude into a pentester's copilot | news.ycombinator.com | 2026-03-08
-
isitsecure
Find and fix web-app vulnerabilities in one command — SAST + DAST + AI, for devs who aren't security experts.
Project mention: Show HN: Isitsecure – 1-command SAST and DAST and LLM security scanner for web apps | news.ycombinator.com | 2026-07-12 -
OrgASM
A tool for Oragnized ASM (Attack Surface Mapper). Subdomains enumeration, IPs scans, Vulnerability assesment...
-
brs-xss
MIT license BRS-XSS is a modular Python CLI scanner for XSS vulnerabilities. Features context-aware payloads, WAF evasion, DOM analysis via Playwright, ML-based risk scoring, and export in HTML/JSON/SARIF. Designed for integration with Brabus Recon Suite (BRS).
-
ai-red-teaming
Whitebox & Blackbox AI red-teaming framework for LLMs & Agentic AI apps. It analyzes your app's source code to discover tools, roles, and guardrails, then generates new attacks chains across several categories and adapts over multiple multi turn rounds to find vulnerabilities
Project mention: Show HN: Open-source white-box agentic red teamer for AI agents | news.ycombinator.com | 2026-03-17 -
benchjack
AI agent benchmark hackability scanner — find evaluation vulnerabilities before they undermine your results
Project mention: BenchJack – an open-source hackability scanner for AI agent benchmarks | news.ycombinator.com | 2026-04-18 -
wshawk
Open source toolkit for WebSocket security testing, web application penetration testing, and stateful attack validation. It combines a CLI scanner, web dashboard, Electron desktop app, browser companion, and project-backed workflows for authorized security assessments.
Project mention: Why I stopped treating WebSocket messages as the unit of work (and built WSHawk instead) | dev.to | 2026-07-11Repo's here if you want to dig in : https://github.com/regaan/wshawk
-
-
BugBounty Arsenal
60+ detectors for web, plus mobile apps and smart contracts. Every finding is mapped to the OWASP Top 10, marked Confirmed when we have proof, and comes with AI fix guidance — plus scheduled scans, the Red vs Blue Arena, branded PDF reports and CI/CD gating. Free, open-source and self-hostable.
Project mention: Show HN: Professional Security Testing Platform | news.ycombinator.com | 2026-09-04 -
ONUS
Open-source AI-assisted VAPT platform for automated vulnerability scanning, evidence verification, deterministic CVSS scoring, and actionable security remediation. Findings are explained in plain english language for you to act on without security knowledge.[Scan your website for vulnerabilities]
Project mention: Where the LLM Stops: Deterministic Scoring in an AI-Assisted VAPT Pipeline | dev.to | 2026-08-22Project site: tryonus.tech
-
Shield-Eye-Core
Network security scanner. Nmap-powered port scanning, CMS detection with live CVE lookup (CIRCL), security headers scoring and SSL/TLS analysis. GTK4 desktop GUI. Part of the ShieldEye toolkit.
-
SaaSHub
SaaSHub - Software Alternatives and Reviews. SaaSHub helps you find the best software and product alternatives
Python vulnerability-scanner discussion
Python vulnerability-scanner related posts
Index
What are some of the best open-source vulnerability-scanner projects in Python? This list will help you:
| # | Project | Stars |
|---|---|---|
| 1 | SQLMap | 38,427 |
| 2 | DeepAudit | 6,990 |
| 3 | commix | 5,838 |
| 4 | Nettacker | 5,564 |
| 5 | Agentic-Bug-Hunter | 4,753 |
| 6 | Raccoon | 4,022 |
| 7 | rapidscan | 2,128 |
| 8 | pentest-ai | 266 |
| 9 | Secrover | 251 |
| 10 | agent-audit | 229 |
| 11 | whalescan | 157 |
| 12 | neural-network-hacking | 107 |
| 13 | tengu | 57 |
| 14 | isitsecure | 43 |
| 15 | OrgASM | 38 |
| 16 | brs-xss | 34 |
| 17 | ai-red-teaming | 28 |
| 18 | benchjack | 19 |
| 19 | wshawk | 14 |
| 20 | HunterX | 13 |
| 21 | BugBounty Arsenal | 12 |
| 22 | ONUS | 12 |
| 23 | Shield-Eye-Core | 11 |