
Gixy-Next: NGINX Configuration Security Scanner & Performance Checker
Gixy-Next (Gixy) is an open-source NGINX configuration security scanner and hardening tool that statically analyzes your nginx.conf to detect security misconfigurations, hardening gaps, and common performance pitfalls before they reach production. It is an actively maintained fork of Yandex's Gixy. Gixy-Next's source code is available on GitHub.
Gixy-Next can also be run in the browser on this page. No download is needed; you can scan your configurations on the website (locally, using WebAssembly).
Gixy-Next (the gixy or gixy-next CLI) is distributed on PyPI. You can install it with pip or uv:
# pip
pip3 install gixy-next
# uv
uv pip install gixy-next
You can then run it:
# gixy defaults to reading /etc/nginx/nginx.conf
gixy
# But you can also specify a path to the configuration
gixy /opt/nginx.conf
You can also export your NGINX configuration to a single dump file (see nginx -T Live Configuration Dump):
# Dumps the full NGINX configuration into a single file (including all includes)
nginx -T > ./nginx-dump.conf
# Scan the dump elsewhere (or via stdin):
gixy ./nginx-dump.conf
# or
cat ./nginx-dump.conf | gixy -
Instead of downloading and running Gixy-Next locally, you can use this webpage and scan a configuration from your web browser (locally, using WebAssembly).
Gixy-Next is available as a Docker image from Docker Hub or GitHub Registry.
Scan a local config file by mounting it into the container:
# Use Github Registry
docker run --pull=always --rm -v "$PWD/nginx.conf:/nginx.conf:ro" ghcr.io/megamansec/gixy-next /nginx.conf
# Or Docker Hub
docker run --pull=always --rm -v "$PWD/nginx.conf:/nginx.conf:ro" megamansec/gixy-next /nginx.conf
Scan an NGINX live configuration dump:
# Dumps the full NGINX configuration into a single file (including all includes)
nginx -T > ./nginx-dump.conf
# Use Github Registry
docker run --pull=always --rm -v "$PWD/nginx-dump.conf:/nginx-dump.conf:ro" ghcr.io/megamansec/gixy-next /nginx-dump.conf
# Or Docker Hub
docker run --pull=always --rm -v "$PWD/nginx-dump.conf:/nginx-dump.conf:ro" megamansec/gixy-next /nginx-dump.conf
Scan from stdin:
# Use Github Registry
nginx -T | docker run --pull=always --rm -i ghcr.io/megamansec/gixy-next gixy-next -
# Or Docker Hub
nginx -T | docker run --pull=always --rm -i megamansec/gixy-next gixy-next -
Gixy-Next can detect a wide range of NGINX security and performance misconfigurations across nginx.conf and included configuration files. The following plugins are supported:
error_log set to offkeepalive_requestsworker_processesproxy_bufferingproxy_pass path normalization issuestry_files directive is evil without open_file_cacheworker_rlimit_nofile must be at least twice worker_connectionsSomething not detected? Please open an issue on GitHub with what's missing!
gixy defaults to reading a system's NGINX configuration from /etc/nginx/nginx.conf. You can also specify the location by passing it to gixy:
# Analyze the configuration in /opt/nginx.conf
gixy /opt/nginx.conf
You can run a focused subset of checks with --tests: