Discover
Find tools for your stack. Pick an audience — we handle the noise.
Discover picks for Vulnerability Scanning
See all tools in Vulnerability Scanning →On Hacker News
Ranked by discussion
tailscale
HealthyThe easiest, most secure way to use WireGuard and 2FA.
CyberChef
MixedThe Cyber Swiss Army Knife - a web app for encryption, encoding, compression and data analysis
caddy
At RiskFast and extensible multi-platform HTTP/1-2-3 web server with automatic HTTPS
netbird
MixedConnect your devices into a secure WireGuard®-based overlay network with SSO, MFA and granular access controls.
pocketbase
HealthyOpen Source realtime backend in 1 file
opensnitch
At RiskOpenSnitch is a GNU/Linux interactive application firewall inspired by Little Snitch.
pangolin
HealthyIdentity-aware VPN and proxy for remote access to anything, anywhere.
Maigret
Mixed♂ Collect a dossier on a person by username from 3000+ sites
certificates
MixedA private certificate authority (X.509 & SSH) & ACME server for secure automated certificate management, so you can use TLS everywhere & SSO for SSH.
keycloak
HealthyOpen Source Identity and Access Management For Modern Applications and Services
mitmproxy
HealthyAn interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.
headscale
At RiskAn open source, self-hosted implementation of the Tailscale control server
Trending now
See all →-
3
msaad00/agent-bom
AI supply chain security scanner with 18 MCP tools. Auto-discovers 20 MCP clients, scans dependencies for CVEs (OSV/NVD/EPSS/CISA KEV), maps blast radius from vulnerabilities to exposed credentials and tools, runs CIS benchmarks, generates CycloneDX/SPDX SBOMs, and enforces compliance across OWASP LLM Top 10, MITRE ATLAS, NIST AI RMF, and EU AI Act.
Healthy -
2
Pompelmi
Open-source file upload security for Node.js. Scan files before storage to detect malware, MIME spoofing, and risky archives.
Healthy -
1
trufflehog
Find, verify, and analyze leaked credentials
Healthy -
1
gebalamariusz/cloud-audit
Open-source AWS security scanner with attack chain detection, breach cost estimation, and copy-paste remediation (CLI + Terraform). 47 checks, 16 attack chain rules. First free standalone AWS security MCP server.
Healthy -
1
Secrover
Open-source security reports — no paywalls, just actionable insights.
Mixed -
1
grype
A vulnerability scanner for container images and filesystems
Mixed -
1
Trivy
Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more
At Risk -
0
is-website-vulnerable
finds publicly known security vulnerabilities in a website's frontend JavaScript libraries
Healthy -
0
Bearer
Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.
Mixed -
ajitpratap0/GoSQLX
7 SQL tools (validate, format, parse, lint, security scan, metadata extraction, full analysis) over Streamable HTTP. Public remote server at mcp.gosqlx.dev - no install needed. 1.25M+ ops/sec, 6 SQL dialects.
Healthy -
Tsunami
Tsunami is a general purpose network security scanner with an extensible plugin system for detecting high severity vulnerabilities with high confidence.
At Risk -
Deepfence ThreatMapper
Open Source Cloud Native Application Protection Platform (CNAPP)
At Risk