
open-sammy
Web-based tool for assessing and tracking software security maturity using the OWASP SAMM and DSOMM models, with Docker support and automated mailing.

Web-based tool for assessing and tracking software security maturity using the OWASP SAMM and DSOMM models, with Docker support and automated mailing.

PHP 8.4+ security library (mirror)


A vulnerability scanner for container images and filesystems

A tool for secrets management, encryption as a service, and privileged access management

Certbot is EFF's tool to obtain certs from Let's Encrypt and (optionally) auto-enable HTTPS on your server. It can also act as a client for any…

ProjectDiscovery's Open Source Tool Manager

CLI tool for inspecting and managing services listening on localhost ports

Static code analysis tool based on Elasticsearch

A terminal based tool for managing secrets with both tui and cli support

MCP is being adopted rapidly. Security guidance is lagging behind. This checklist gives security engineers, platform teams, and technical leaders a…

Secure CLI tool for managing environment secrets using native OS credential stores (macOS Keychain, Linux Secret Service, Windows Credential Manager)

Matt.Net is a simple GUI wrapper around Microsoft's CAT.NET Code Auditing Tool

A unified, security-first wire protocol for tool access and agent coordination. UAP eliminates CVE-2025-49596 and MCP tool-poisoning vulnerabilities…

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

Simple and flexible tool for managing secrets

Fast, open-source static analysis tool for detecting hardcoded secrets like passwords, API keys, and tokens in git repositories, files, and stdin…

Static analysis tool for infrastructure as code that detects cloud misconfigurations, vulnerabilities, and secrets across Terraform, Kubernetes,…