Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
django-DefectDojo — Open-Source Unified Vulnerability Management, DevSecOps & ASPM | Kitploit
Tools/GitHubGitHub/defectdojo/django-defectdojo
Vulnerability ScannersPenetration TestingDevSecOpsTop in DevSecOps #17
GitHubdefectdojo/django-defectdojo

django-DefectDojo

Open-Source Unified Vulnerability Management, DevSecOps & ASPM

View Repository
4.9k1.9k701 day agoReviewed by Kitploit
Website

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

DefectDojo

Open Source Security Index - Fastest Growing Open Source Security Projects

OWASP Flagship GitHub release YouTube Subscribe Twitter Follow

Unit Tests Integration Tests CII Best Practices

DefectDojo is a DevSecOps, ASPM (application security posture management), and vulnerability management tool. DefectDojo orchestrates end-to-end security testing, vulnerability tracking, deduplication, remediation, and reporting.

Demo

Pro Edition: pro.demo.defectdojo.com

OWASP Community Edition: demo.defectdojo.org

Either demo environment can be logged into with username admin and password 1Defectdojo@demo#appsec. Please note that the demos are publicly accessible and reset every day. Do not put sensitive data in the demo. An easy way to test DefectDojo is to upload some sample scan reports.

Quick Start for Docker Compose

git clone https://github.com/DefectDojo/django-DefectDojo && cd django-DefectDojo && docker compose up

This quick start guide will do the following

  • Clone the repository and change directories
  • Start the application
  • Obtain admin credentials in the initializer logs. The first initialization can take up to 3 minutes to run.

if running DefectDojo in detached mode via docker compose up -d, obtain admin credentials from the initializer logs with the command below. Please note, the initializer can take up to 3 minutes to run.

docker compose logs initializer | grep "Admin password:"

Documentation

  • Official Docs
  • REST APIs
  • Client APIs and Wrappers
  • Authentication options:
    • OAuth2/SAML2
    • LDAP
  • Supported tools
  • How to Write Documentation Locally
  • Development

Supported Installation Options

  • Pro - SaaS or self-hosted (via K8s or docker compose). Speak to our team or get Pro from $100/mo
  • OS - docker compose

Community, Getting Involved, and Updates

Dojo Slack LinkedIn Twitter Youtube

Checkout our new Community Portal and join the DefectDojo community on Slack!

Follow DefectDojo on LinkedIn, YouTube, and X for platform updates!

Contributing

Please see our contributing guidelines for details and standards on contributing before considering or submitting a pull request.

Pro Edition

Upgrade to DefectDojo Pro! Pro transcends the do-it-yourself approach of open-source: A new UI, risk-based vulnerability management, incredibile scalability, API connectors, ServiceNow, GitHub, GitLab, Azure DevOps, automatic data enrichment, prioritization, and more! See all the differentiators at the bottom of our pricing page: defectdojo.com/pricing.

Alternatively, for information please email [email protected]

About Us

DefectDojo is maintained by:

  • Greg Anderson (@devGregA | LinkedIn)
  • Matt Tesauro (@mtesauro | LinkedIn | @matt_tesauro)

Core Moderators can help you with pull requests or feedback on dev ideas:

  • Cody Maffucci (@Maffooch | LinkedIn)

Moderators can help you with pull requests or feedback on dev ideas:

  • Blake Owens (@blakeaowens)
Download Tool