Open Source Security Projects
Discover 166 open source Security repositories from GitHub, each with an analysis of what it does, key features, use cases and alternatives. Security projects here are most often combined with Self Hosted, Python and AI Agents. Last updated October 4, 2026.
166 repositories · updated October 4, 2026

captcha: Generate Image and Audio CAPTCHAs
captcha is a Python library for generating image and audio CAPTCHAs, with built-in voice and font data and support for custom assets. It suits applications that need to create their own CAPTCHA challenges and save them as image or audio files.

awesome-api-security: Find API Security Tools and Resources
A curated directory of API security tools, guidance, and learning materials for developers and security practitioners. Use it to find resources for API testing, hardening, research, and hands-on training.

KeepChatGPT: Customize and Protect the ChatGPT Web Experience
KeepChatGPT is a JavaScript userscript that adds privacy, data-safety, and workflow features to ChatGPT in the browser. It is for users who want more control over the chat interface and need to install a userscript manager.

udp2raw: Tunnel UDP Traffic Through Raw Packets
udp2raw wraps UDP traffic in encrypted UDP, simulated TCP, or ICMP packets to help it pass through networks that block or degrade UDP. It is aimed at Linux users who can configure raw sockets and want to carry UDP-based VPN traffic across restrictive links.

opengrep: Find Security Issues with Static Code Analysis
Opengrep is an OCaml static analysis engine that searches code for patterns and security issues using customizable rules. It suits developers and security teams who want Semgrep-compatible scanning, taint analysis, and JSON or SARIF output under an LGPL-2.1 license.

vulnapi: Scan APIs for Security Vulnerabilities
VulnAPI is a Go-based dynamic security scanner for APIs. It can discover exposed API-related resources and scan targets using curl-like requests or OpenAPI contracts, helping developers and security teams identify common weaknesses.

hexora: Scan Python Code for Malicious Patterns
Hexora analyzes Python source for suspicious behavior using static rules and a machine-learned file score. It is intended for security teams and developers reviewing packages, dependencies, and scripts for potential threats.

nebula: Build Secure Peer-to-Peer Overlay Networks
Nebula connects hosts across networks through an encrypted, certificate-based overlay, with group-based traffic rules and peer discovery. It suits teams that need secure connectivity across cloud, datacenter, and endpoint environments without relying on a fixed addressing scheme.

databag: Self-Host a Federated Messenger
Databag is a lightweight messenger that connects users across self-hosted nodes, with topic-based conversations and end-to-end encryption. It suits people and communities who want control over their messaging infrastructure and are prepared to operate a server.

nexus-zkvm: Prove Rust Program Execution with Zero Knowledge
Nexus zkVM is a Rust-based virtual machine for generating zero-knowledge proofs of program execution. It is aimed at developers exploring verifiable computation who need a modular, publicly specified system and can work with experimental software.

mcphub: Connect and Manage MCP Servers Through One Gateway
MCPHub is a self-hosted gateway and control plane for connecting MCP clients to local and remote MCP servers. It centralizes routing, access controls, credentials, logs, and health monitoring.

Peergos: Store and Share Files on a Private Peer-to-Peer Web
Peergos is a peer-to-peer platform for encrypted file storage, sharing, messaging, and private social features. It suits people who want control over their data and are willing to use a hosted service or run a server themselves.