Open Source Security Projects
Discover 166 open source Security repositories from GitHub, each with an analysis of what it does, key features, use cases and alternatives. Security projects here are most often combined with Self Hosted, Python and AI Agents. Last updated October 4, 2026.
166 repositories · updated October 4, 2026

wake: Test and Analyze Solidity Smart Contracts
Wake is a Python-based framework for testing, fuzzing, and static analysis of Solidity smart contracts. It suits Solidity developers and security teams that want automated checks, custom detectors, and IDE support in one tool.

psitransfer: Share Files from Your Own Server
PsiTransfer is a self-hosted file-sharing service for sending files without accounts. It supports resumable transfers, expiring upload buckets, and one-time downloads, making it useful when you want control over where shared files are hosted.

mitaka: Search and Scan OSINT Indicators from Your Browser
Mitaka is a browser extension for looking up and scanning OSINT indicators from selected text. It identifies and refangs common indicators, then routes them to relevant search and scan services.

jumpserver: Manage Secure Access to Privileged Systems
JumpServer is a self-hosted privileged access management platform for DevOps and IT teams. It centralizes secure connections to servers, desktops, Kubernetes, databases, and web applications, with terminal and AI components.

CloakQuest3r: Check for Exposed Origin IP Addresses
CloakQuest3r is a Python security research tool that checks whether websites behind Cloudflare or similar proxies may expose their origin IP. It combines subdomain scanning with historical IP and SSL certificate analysis for authorized defensive assessments.

agentic_security: Scan LLMs and Agent Workflows for Vulnerabilities
Agentic Security is a Python toolkit for probing LLMs and agent workflows with jailbreaks, fuzzing, and multimodal inputs. It fits developers and security teams who want to run configurable scans against an API and use the results in CI.

aliasvault: Manage Passwords and Email Aliases Privately
AliasVault combines an encrypted password manager with disposable email aliases and a built-in email server. It suits people who want cross-platform access and the option to self-host their credentials and alias service.

Sirius: Discover Network Hosts and Scan for Vulnerabilities
Sirius is a self-hosted vulnerability scanner that discovers hosts and services, then identifies CVEs and presents results in a web dashboard. It suits teams that want a Docker-based scanning stack with remote agents and an API for security workflows.

fleet: Manage and Secure Devices Across Operating Systems
Fleet is a device management platform for IT and security teams that need to manage, monitor, and secure computers across operating systems. It offers GUI, API, and GitOps workflows for tasks such as MDM, patching, software deployment, and compliance checks.

teller: Manage Secrets from the Command Line
Teller is a Rust CLI for using secrets from cloud providers and vaults without storing them in shell scripts or local environment files. It also supports secret scanning, redaction, and provider-to-provider copying.

CertoraProver: Formally Verify Smart Contracts
Certora Prover checks smart contracts against formal specifications to find violations before deployment. It targets developers and security teams working with EVM-based chains, Solana, or Stellar who need automated verification.

vuln-bank: Practice Web, API, and AI Security Testing
Vuln Bank is an intentionally vulnerable banking web app for learning application security testing and secure code review. It offers hands-on scenarios across web, API, GraphQL, and AI features, and should only run in an isolated educational environment.