Open Source Security Projects
Discover 166 open source Security repositories from GitHub, each with an analysis of what it does, key features, use cases and alternatives. Security projects here are most often combined with Self Hosted, Python and AI Agents. Last updated October 4, 2026.
166 repositories · updated October 4, 2026

hakoriginfinder: Find Origin Hosts Behind Reverse Proxies
hakoriginfinder compares responses from supplied IP addresses with a target hostname to help identify an origin host behind a reverse proxy. It is a Go command-line tool for authorized security testing and network reconnaissance.

promptfoo: Evaluate and Red-Team LLM Applications
Promptfoo is a CLI and library for evaluating prompts, comparing models, and testing LLM applications for security risks. It suits developers who want repeatable quality and vulnerability checks locally or in CI/CD.

Zero: A Self-Hosted AI Email App
Zero is an open-source email app for managing accounts from providers such as Gmail and Outlook, with AI features and a focus on privacy. It suits people who want a customizable inbox they can self-host.

cryptpad: Collaborate on Documents with End-to-End Encryption
CryptPad is a browser-based collaboration suite for editing documents and other content together in real time. It encrypts user data in the browser before sending it to the server, and can be run as a self-hosted service.

logto: Build Authentication and Authorization for Apps
Logto is an identity platform for SaaS and AI applications, built around OIDC and OAuth 2.1. It provides sign-in flows, multi-tenancy, enterprise SSO, and authorization capabilities for teams building user-facing apps and APIs.

defguard: Manage Secure VPN and Identity Access
Defguard is a self-hosted platform for managing WireGuard VPN access, identity, and multi-factor authentication. It suits organizations that want centralized control over network access and authentication inside their own infrastructure.

Addon: Remove Tracking from Browser URLs
ClearURLs is a browser add-on for Firefox and some Chromium-based browsers that strips tracking parameters from URLs. It suits people who want cleaner links and less URL-based tracking without manually editing addresses.

certbot: Obtain and Deploy HTTPS Certificates
Certbot is a command-line client for obtaining certificates from Let's Encrypt and other ACME-compliant certificate authorities. It can also configure supported web servers to use HTTPS and automate certificate management.

obfuscator-io-deobfuscator: Make Obfuscated JavaScript Easier to Read
A TypeScript tool that reverses several common transformations used by Obfuscator.io, making scripts easier to inspect. Use it from a browser or CLI when analyzing code, with processing designed not to execute the input script.

reactor-ca: Manage and Deploy Homelab TLS Certificates
ReactorCA is a Go command-line tool for managing a private CA and issuing TLS certificates for homelab and small-office services. It encrypts private keys with age and can export certificates and run deployment scripts.

mkcertWeb: Manage Local Development Certificates in a Web UI
mkcertWeb is a self-hosted web interface for generating and managing locally trusted development certificates with mkcert. It suits developers and small teams that want browser-based certificate workflows, device enrollment, and optional authentication or expiry alerts.

Azure-Sentinel: Security Detections and Hunting Content
Azure-Sentinel is a community repository of security content for Microsoft Sentinel and Microsoft 365 Defender. Security teams can use its detections, KQL queries, workbooks, and playbooks to onboard, monitor environments, and investigate threats.