awesome-repositories.com
Blog
MCP
awesome-repositories.com

Descoperă cele mai bune repository-uri open source cu căutare AI.

ExploreazăCăutări recomandateAlternative open-sourceSoftware self-hostedBlogHartă site
ProiectServer MCPDespreCum realizăm clasamentulPresă
LegalConfidențialitateTermeni
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
Back to pumasecurity/puma-scan

Open-source alternatives to Puma Scan

30 open-source projects similar to pumasecurity/puma-scan, ranked by how many features they have in common. Compare stars, activity and what each one does to find the best Puma Scan alternative.

  • securego/gosecAvatar securego

    securego/gosec

    8,866Vezi pe GitHub↗

    gosec is a static analysis security tool designed to scan Go source code for vulnerabilities and common coding flaws. It functions as a security analyzer that inspects the abstract syntax tree to identify insecure function calls, API usage, and potential security risks. The tool distinguishes itself by mapping detected vulnerabilities to Common Weakness Enumeration identifiers for standardized reporting and integrating with external AI models to suggest code fixes for identified issues. Its capabilities cover the detection of injection vulnerabilities, hardcoded credentials, weak cryptograph

    Go
    Vezi pe GitHub↗8,866
  • presidentbeef/brakemanAvatar presidentbeef

    presidentbeef/brakeman

    7,248Vezi pe GitHub↗

    Brakeman is a static analysis security tool and scanner specifically designed for Ruby on Rails source code. It identifies common security vulnerabilities, such as injection and cross-site scripting, by analyzing the application codebase without executing the application. The tool functions as a security auditor that detects mass assignment risks and template vulnerabilities. It evaluates the final output of rendered views and identifies unrestricted assignment patterns that could allow unauthorized modification of model attributes. The system provides vulnerability management through the us

    Ruby
    Vezi pe GitHub↗7,248
  • aboul3la/sublist3rAvatar aboul3la

    aboul3la/Sublist3r

    10,957Vezi pe GitHub↗

    Sublist3r is a subdomain enumeration tool and passive reconnaissance framework designed to discover subdomains by querying search engines and public intelligence sources. It functions as a security tool for identifying the digital footprint of a target domain. The project provides both passive enumeration through multi-source API aggregation and active discovery via a DNS brute force tool. It includes a TCP port scanner to identify active services and open ports on discovered subdomains, facilitating attack surface mapping. The tool can be used as a standalone utility or as a Python security

    Python
    Vezi pe GitHub↗10,957

Căutare AI

Explorează mai multe repository-uri excelente

Descrie ce ai nevoie în limbaj simplu — AI-ul sortează mii de proiecte open source selectate în funcție de relevanță.

Find more with AI search
  • ambionics/phpggcAvatar ambionics

    ambionics/phpggc

    3,832Vezi pe GitHub↗

    phpggc is a security assessment utility and command-line tool designed for the automated generation, obfuscation, and wrapping of serialized object chains. It functions as a gadget chain framework used to identify and verify remote code execution vectors by testing for PHP object injection vulnerabilities. The project provides a modular system for constructing complex serialized object sequences and includes a dedicated payload obfuscator to transform byte streams for bypassing web application firewalls and security filters. It also features a generator for wrapping serialized data into archi

    PHP
    Vezi pe GitHub↗3,832
  • anchore/grypeAvatar anchore

    anchore/grype

    12,423Vezi pe GitHub↗

    Grype is a command-line security scanner designed to identify known vulnerabilities within container images, filesystems, and software manifests. It functions as a software composition analysis tool that detects security flaws in application components and open-source libraries to support supply chain security. The tool distinguishes itself by reconstructing the final state of container images through layered filesystem inspection and normalizing diverse package formats into a unified dependency graph. It maintains a local cache of security advisories synchronized from multiple upstream sourc

    Gocontainer-imagecontainerscyclonedx
    Vezi pe GitHub↗12,423
  • ajinabraham/libsastAvatar ajinabraham

    ajinabraham/libsast

    136Vezi pe GitHub↗

    Generic SAST Library

    Python
    Vezi pe GitHub↗136
  • aquasecurity/kube-hunterAvatar aquasecurity

    aquasecurity/kube-hunter

    5,064Vezi pe GitHub↗

    Kube-hunter is a security scanner and vulnerability hunter for Kubernetes clusters. It operates as a cloud-native penetration tool designed to identify security weaknesses, infrastructure misconfigurations, and exploitable gaps by simulating attacker techniques. The tool distinguishes itself through a dual-mode scanning engine that executes both remote external probes and internal network scans. It features identity-based impersonation, allowing it to use service account tokens and pod identities to simulate security access from specific cluster roles and determine the potential blast radius

    Python
    Vezi pe GitHub↗5,064
  • bridgecrewio/checkovAvatar bridgecrewio

    bridgecrewio/checkov

    8,798Vezi pe GitHub↗

    Checkov is a static analysis tool and security scanner designed to identify misconfigurations in infrastructure as code, container images, and Kubernetes configurations. It functions as a cloud security posture tool, an SCA vulnerability scanner, and a secret scanning utility to prevent security breaches and version control leaks. The project distinguishes itself through deep graph analysis and variable resolution, allowing it to map relationships between interconnected resources and evaluate the final state of infrastructure attributes. It provides extensibility for defining custom security

    Python
    Vezi pe GitHub↗8,798
  • aquasecurity/trivyAvatar aquasecurity

    aquasecurity/trivy

    36,462Vezi pe GitHub↗

    Trivy is a comprehensive security scanner designed to identify vulnerabilities and misconfigurations across container images, filesystems, and infrastructure as code files. It functions as a software composition analysis tool and an infrastructure security scanner, providing automated checks for CI/CD pipelines and cloud environments to ensure the integrity of the software supply chain. The tool distinguishes itself through a modular, plugin-based architecture that allows for the independent inspection of diverse targets. It utilizes a declarative policy engine to evaluate configurations agai

    Gocontainersdevsecopsdocker
    Vezi pe GitHub↗36,462
  • arpsyndicate/kenzerA

    ARPSyndicate/kenzer

    0Vezi pe GitHub↗
    Vezi pe GitHub↗0
  • barrracud4/image-upload-exploitsB

    barrracud4/image-upload-exploits

    0Vezi pe GitHub↗
    Vezi pe GitHub↗0
  • bearer/bearerAvatar Bearer

    Bearer/bearer

    2,566Vezi pe GitHub↗

    Bearer is a static analysis security testing tool and privacy compliance auditor. It identifies security vulnerabilities, hard-coded secrets, and privacy risks in source code through static analysis and data flow tracing. The tool distinguishes itself by tracking the movement of sensitive data through code to identify leaks and by mapping personal and health-related information flows to generate evidence for privacy impact assessments. It also provides differential scanning for pull requests and uses fingerprint-based suppression to exclude known false positives from reports. The platform co

    Goappseccode-qualitycompliance
    Vezi pe GitHub↗2,566
  • bishopfox/gitgotAvatar BishopFox

    BishopFox/GitGot

    1,563Vezi pe GitHub↗

    Semi-automated, feedback-driven tool to rapidly search through troves of public data on GitHub for sensitive secrets.

    Pythonfuzzy-matchinggist-searchgists
    Vezi pe GitHub↗1,563
  • bishopfox/h2csmugglerAvatar BishopFox

    BishopFox/h2csmuggler

    780Vezi pe GitHub↗
    Pythonbugbountyinfosecsecurity-research
    Vezi pe GitHub↗780
  • brannondorsey/dns-rebind-toolkitAvatar brannondorsey

    brannondorsey/dns-rebind-toolkit

    501Vezi pe GitHub↗

    A front-end JavaScript toolkit for creating DNS rebinding attacks.

    JavaScript
    Vezi pe GitHub↗501
  • appsecco/spaces-finderAvatar appsecco

    appsecco/spaces-finder

    157Vezi pe GitHub↗

    Non-Standard Python Libraries:

    Python
    Vezi pe GitHub↗157
  • brompwnie/botbB

    brompwnie/botb

    0Vezi pe GitHub↗
    Vezi pe GitHub↗0
  • checkmarx/kicsAvatar checkmarx

    checkmarx/kics

    2,649Vezi pe GitHub↗

    Find security vulnerabilities, compliance issues, and infrastructure misconfigurations early in the development cycle of your infrastructure-as-code with KICS by Checkmarx.

    Open Policy Agent
    Vezi pe GitHub↗2,649
  • chvancooten/bugbountyscannerAvatar chvancooten

    chvancooten/BugBountyScanner

    921Vezi pe GitHub↗
    Shellbug-bounty-reconnaissancebugbountydocker-image
    Vezi pe GitHub↗921
  • danmar/cppcheckAvatar danmar

    danmar/cppcheck

    6,512Vezi pe GitHub↗
    C++cc-plus-pluscpp
    Vezi pe GitHub↗6,512
  • david-a-wheeler/flawfinderAvatar david-a-wheeler

    david-a-wheeler/flawfinder

    572Vezi pe GitHub↗

    This is "flawfinder" by David A. Wheeler.

    Python
    Vezi pe GitHub↗572
  • deepfence/secretscannerAvatar deepfence

    deepfence/SecretScanner

    3,270Vezi pe GitHub↗

    SecretScanner is a security tool designed to search filesystems and container images for unprotected passwords, API keys, and other sensitive data. It functions as a static secret detector and container image scanner that identifies hardcoded credentials by matching content against a database of known secret types. The tool inspects container image layers to find secrets hidden within the filesystem hierarchy and parses local directories and host-mounted paths. It provides the ability to export scan findings in machine-readable JSON format for automated analysis and processing. The scanning

    Gocontainersdevsecopsdocker
    Vezi pe GitHub↗3,270
  • deepfence/threatmapperAvatar deepfence

    deepfence/ThreatMapper

    5,282Vezi pe GitHub↗

    ThreatMapper is a cloud native application protection platform and infrastructure security scanner. It functions as a vulnerability management system and cloud workload telemetry collector designed to monitor workloads and detect security risks across cloud and container environments. The platform distinguishes itself through a network traffic visualizer that uses machine learning to classify communication patterns and a graph-based attack mapping system to identify high-risk paths between vulnerabilities and network dependencies. Its broader capabilities cover cloud infrastructure complianc

    TypeScriptcloud-nativecloudsecuritycnapp
    Vezi pe GitHub↗5,282
  • defectdojo/django-defectdojoAvatar DefectDojo

    DefectDojo/django-DefectDojo

    4,528Vezi pe GitHub↗

    DefectDojo is a vulnerability management system and application security orchestration tool. It serves as a centralized platform for importing, deduplicating, and tracking security findings from multiple scanners and tools to manage an organization's overall security posture. The system distinguishes itself by aggregating findings from various security tools into a single report and normalizing that data to prioritize remediation. It provides specific workflows for vulnerability triage and deduplication to reduce noise and redundant manual work across the software development lifecycle. The

    HTMLanalyticsappsecautomation
    Vezi pe GitHub↗4,528
  • delvelabs/tachyonD

    delvelabs/tachyon

    0Vezi pe GitHub↗
    Vezi pe GitHub↗0
  • delvelabs/vane2D

    delvelabs/vane2

    0Vezi pe GitHub↗
    Vezi pe GitHub↗0
  • designsecurity/progpilotAvatar designsecurity

    designsecurity/progpilot

    362Vezi pe GitHub↗

    A static analysis tool for security

    PHP
    Vezi pe GitHub↗362
  • doyensec/inqlAvatar doyensec

    doyensec/inql

    1,782Vezi pe GitHub↗

    InQL is a robust, open-source Burp Suite extension for advanced GraphQL testing, offering intuitive vulnerability detection, customizable scans, and seamless Burp integration.

    Kotlin
    Vezi pe GitHub↗1,782
  • dstotijn/hettyAvatar dstotijn

    dstotijn/hetty

    11,485Vezi pe GitHub↗

    Hetty is an HTTP intercepting proxy and web security research toolkit used to capture, inspect, and modify traffic between a browser and a server. It functions as an HTTP request editor for creating and replaying manual requests to test server behavior and as a project-based traffic logger that isolates network logs across different security research engagements. The tool provides a request-response interception loop that pauses outgoing requests and incoming responses in transit, allowing for manual editing or cancellation. It includes a manual request replay engine to construct and transmit

    Go
    Vezi pe GitHub↗11,485
  • ajinabraham/nodejsscanAvatar ajinabraham

    ajinabraham/nodejsscan

    2,563Vezi pe GitHub↗

    nodejsscan is a static analysis security tool and vulnerability detection engine designed to scan Node.js source code for security flaws and common coding vulnerabilities. It functions as a static application security testing tool that analyzes code without executing the program. The tool operates as a security linter that can be integrated into continuous integration pipelines to block insecure code from merging into main branches. It automates the auditing process through rule-based detection and pattern-based static analysis. The project provides capabilities for vulnerability alert autom

    CSScode-analysiscode-reviewdevsecops
    Vezi pe GitHub↗2,563