Python vulnerability-scanner

Open-source Python projects categorized as vulnerability-scanner

Top 23 Python vulnerability-scanner Projects

vulnerability-scanner
  1. SQLMap

    Automatic SQL injection and database takeover tool

  2. Kargo

    Stop Scripting Promotions. Start Shipping with Kargo. Kargo automates promotion across dev, staging, and prod with approval gates and verification. Open source, built by the team behind Argo CD. Download now.

    Kargo logo
  3. DeepAudit

    DeepAudit:人人拥有的 AI 黑客战队,让漏洞挖掘触手可及。国内首个开源的代码漏洞挖掘多智能体系统。小白一键部署运行,自主协作审计 + 自动化沙箱 PoC 验证。支持 Ollama 私有部署 ,一键生成报告。支持中转站。​让安全不再昂贵,让审计不再复杂。

    Project mention: Show HN: DeepAudit – open-source auditing agent (LLMs and Static Analysis) | news.ycombinator.com | 2025-12-15
  4. commix

    Automated Αll-in-One OS command injection exploitation tool.

  5. Nettacker

    Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management

  6. Agentic-Bug-Hunter

    AI-powered bug bounty hunting toolkit that works with or without subscription.

    Project mention: Show HN: Pentesting Tool Using Claude | news.ycombinator.com | 2026-03-26
  7. Raccoon

    A high performance offensive security tool for reconnaissance and vulnerability scanning

  8. rapidscan

    :new: The Multi-Tool Web Vulnerability Scanner.

  9. AppSignal

    AppSignal knows why the f*#k it crashed. Stop vibe-debugging. Every exception, every backtrace, grouped so you see patterns, not noise.

    AppSignal logo
  10. pentest-ai

    Offensive-security MCP server with 205 wrapped tools, 17 specialist agents, and 60 SPA-aware probes for OWASP Top 10. CLI + MCP, BYO LLM. No API key needed on MCP path.

    Project mention: Show HN: Ptai – an MCP that chains low-sev findings into RCE | news.ycombinator.com | 2026-05-19
  11. Secrover

    Open-Source Security Reports, Made Simple - 100% free. No paywalls, just actionable insights.

  12. agent-audit

    Static security scanner for LLM agents — prompt injection, MCP config auditing, taint analysis. 51 rules mapped to OWASP Agentic Top 10 (2026). Works with LangChain, CrewAI, AutoGen.

    Project mention: Show HN: Agent Audit – Open-source security scanner for AI agents | news.ycombinator.com | 2026-02-06

    - Static analysis limitations apply — can't catch runtime-only issues

    *Some numbers from scanning open-source projects:*

    I scanned 6 popular agent repos (OpenHands, SWE-agent, Gorilla, etc.). Found 617 findings total, 269 critical. Most common issue: tool functions that pass LLM-provided strings directly to dangerous sinks without validation.

    Full report: https://github.com/HeadyZhang/agent-audit/blob/master/docs/r...

    *Install:*

    ```

  13. whalescan

    Whalescan is a vulnerability scanner for Windows containers, which performs several benchmark checks, as well as checking for CVEs/vulnerable packages on the container

  14. neural-network-hacking

    Hacking the Singularity. Deep learning hacking. Weaponizing AI in Offensive security

  15. tengu

    AI-powered penetration testing MCP server

    Project mention: Tengu – An MCP server that turns Claude into a pentester's copilot | news.ycombinator.com | 2026-03-08
  16. isitsecure

    Find and fix web-app vulnerabilities in one command — SAST + DAST + AI, for devs who aren't security experts.

    Project mention: Show HN: Isitsecure – 1-command SAST and DAST and LLM security scanner for web apps | news.ycombinator.com | 2026-07-12
  17. OrgASM

    A tool for Oragnized ASM (Attack Surface Mapper). Subdomains enumeration, IPs scans, Vulnerability assesment...

  18. brs-xss

    MIT license BRS-XSS is a modular Python CLI scanner for XSS vulnerabilities. Features context-aware payloads, WAF evasion, DOM analysis via Playwright, ML-based risk scoring, and export in HTML/JSON/SARIF. Designed for integration with Brabus Recon Suite (BRS).

  19. ai-red-teaming

    Whitebox & Blackbox AI red-teaming framework for LLMs & Agentic AI apps. It analyzes your app's source code to discover tools, roles, and guardrails, then generates new attacks chains across several categories and adapts over multiple multi turn rounds to find vulnerabilities

    Project mention: Show HN: Open-source white-box agentic red teamer for AI agents | news.ycombinator.com | 2026-03-17
  20. benchjack

    AI agent benchmark hackability scanner — find evaluation vulnerabilities before they undermine your results

    Project mention: BenchJack – an open-source hackability scanner for AI agent benchmarks | news.ycombinator.com | 2026-04-18
  21. wshawk

    Open source toolkit for WebSocket security testing, web application penetration testing, and stateful attack validation. It combines a CLI scanner, web dashboard, Electron desktop app, browser companion, and project-backed workflows for authorized security assessments.

    Project mention: Why I stopped treating WebSocket messages as the unit of work (and built WSHawk instead) | dev.to | 2026-07-11

    Repo's here if you want to dig in : https://github.com/regaan/wshawk

  22. HunterX

    AI-Assisted Vulnerability Discovery, Validation & Proof Engine

  23. BugBounty Arsenal

    60+ detectors for web, plus mobile apps and smart contracts. Every finding is mapped to the OWASP Top 10, marked Confirmed when we have proof, and comes with AI fix guidance — plus scheduled scans, the Red vs Blue Arena, branded PDF reports and CI/CD gating. Free, open-source and self-hostable.

    Project mention: Show HN: Professional Security Testing Platform | news.ycombinator.com | 2026-09-04
  24. ONUS

    Open-source AI-assisted VAPT platform for automated vulnerability scanning, evidence verification, deterministic CVSS scoring, and actionable security remediation. Findings are explained in plain english language for you to act on without security knowledge.[Scan your website for vulnerabilities]

    Project mention: Where the LLM Stops: Deterministic Scoring in an AI-Assisted VAPT Pipeline | dev.to | 2026-08-22

    Project site: tryonus.tech

  25. Shield-Eye-Core

    Network security scanner. Nmap-powered port scanning, CMS detection with live CVE lookup (CIRCL), security headers scoring and SSL/TLS analysis. GTK4 desktop GUI. Part of the ShieldEye toolkit.

  26. SaaSHub

    SaaSHub - Software Alternatives and Reviews. SaaSHub helps you find the best software and product alternatives

    SaaSHub logo
NOTE: The open source projects on this list are ordered by number of github stars. The number of mentions indicates repo mentiontions in the last 12 Months or since we started tracking (Dec 2020).

Python vulnerability-scanner discussion

Log in or Post with

Python vulnerability-scanner related posts

  • Show HN: Professional Security Testing Platform

    1 project | news.ycombinator.com | 4 Sep 2026
  • I wrote a blazing fast subdomain enumerator! (100.000 domains checked under 10 minutes!)

    2 projects | /r/hacking | 16 Mar 2022
  • Finding “secret” directories on local servers

    1 project | /r/hacking | 2 Mar 2022

Index

What are some of the best open-source vulnerability-scanner projects in Python? This list will help you:

# Project Stars
1 SQLMap 38,427
2 DeepAudit 6,990
3 commix 5,838
4 Nettacker 5,564
5 Agentic-Bug-Hunter 4,753
6 Raccoon 4,022
7 rapidscan 2,128
8 pentest-ai 266
9 Secrover 251
10 agent-audit 229
11 whalescan 157
12 neural-network-hacking 107
13 tengu 57
14 isitsecure 43
15 OrgASM 38
16 brs-xss 34
17 ai-red-teaming 28
18 benchjack 19
19 wshawk 14
20 HunterX 13
21 BugBounty Arsenal 12
22 ONUS 12
23 Shield-Eye-Core 11

Sponsored
Stop Scripting Promotions. Start Shipping with Kargo
Kargo automates promotion across dev, staging, and prod with approval gates and verification. Open source, built by the team behind Argo CD. Download now.
akuity.io

Did you know that Python is
the 1st most popular programming language
based on number of references?