7,363 open-source and SaaS tools, with GitHub stats refreshed every day.

11 alternatives ranked by real activity

Open-source Aikido Security alternatives

A curated, ranked list of the 11 best open-source alternatives to Aikido Security.

The best open-source alternative to Aikido Security is Trivy. If that doesn't suit you, other good options are Gitleaks, TruffleHog, Semgrep and Grype.

Aikido Security alternatives are mainly security tools, but some are also developer tools. 10 of them shipped code in the last 30 days, 11 can be self-hosted, and 8 use a permissive licence.

Last updated October 2, 2026 · ranked by GitHub stars, growth and recent commits

Trivy

A security scanner that finds vulnerabilities, misconfigurations, secrets and license issues in container images, filesystems, Git repositories and Kubernetes.

GitHub stars
38k
Last commit
today
Latest release
v0.75.0
Licence
Apache-2.0
trivy.devTrivy homepage screenshot

Trivy is a security scanner from Aquasec, written in Go and released under the Apache-2.0 license. It has scanners that look for different security issues and targets where those issues can be found. The README describes it as comprehensive and versatile, and it covers the major programming languages, operating systems and platforms.

Targets include container images, filesystems, remote Git repositories, virtual machine images and Kubernetes. Scanners look for OS packages and software dependencies in use, which produces an SBOM, known vulnerabilities (CVEs), infrastructure-as-code issues and misconfigurations, sensitive information and secrets, and software licenses. Its topics reference DevSecOps and vulnerability scanning.

Trivy is available through most common channels, including Homebrew, a Docker image and downloadable binaries, and integrates with platforms such as GitHub Actions, a Kubernetes operator and a VS Code plugin. Canary builds are produced with each push to the main branch. It suits developers, platform teams and security engineers who want to scan images and code in CI pipelines.

Key features

  • Scans container images and filesystems
  • Scans Git repositories and Kubernetes
  • Known vulnerability (CVE) detection
  • IaC misconfiguration and secret detection
  • SBOM generation and license scanning
  • GitHub Actions and VS Code integrations

Pricing: Free and open source under the Apache-2.0 license.

Read more about TrivyWebsite GitHub

Gitleaks

Gitleaks is a command-line scanner that finds hardcoded passwords, API keys and tokens in git repositories, files and piped input.

GitHub stars
30k
Last commit
3 days ago
Latest release
v8.30.1
Licence
MIT
gitleaks.ioGitleaks homepage screenshot

Gitleaks is a tool for detecting secrets such as passwords, API keys and tokens in git repositories, in files, and in anything you pipe to it through standard input. It is written in Go, released under the MIT license, and aimed at DevSecOps, CI/CD and data-loss-prevention use. A maintainer warning in the README says it is feature complete, that future releases will be security patches only, and that the author is shifting focus to a successor project called Betterleaks.

Gitleaks can be installed with Homebrew, Docker or Go, and binaries for many platforms are on the releases page. It can run as a pre-commit hook and has a GitHub Action for CI use. The detection engine is built on regular expressions, and the author has written about how that approach works. It does not need a hosted service, because scans run wherever you execute the binary, including in CI pipelines.

Key features

  • Scans git history, files and stdin
  • Detects passwords, API keys and tokens
  • Runs as a pre-commit hook
  • GitHub Action for CI scanning
  • Install via Homebrew, Docker or Go
  • Maintenance now limited to security patches

Pricing: Free and open source under the MIT license.

Read more about GitleaksWebsite GitHub

TruffleHog

TruffleHog finds, classifies and verifies leaked credentials across Git, chats, wikis, logs, filesystems and cloud storage.

GitHub stars
28k
Last commit
today
Latest release
v3.97.9
Licence
AGPL-3.0
Self-hosted
Yes
trufflesecurity.comTruffleHog homepage screenshot

TruffleHog is a tool for discovering, classifying, validating and analyzing secrets, meaning credentials a machine uses to authenticate to another machine, such as API keys, database passwords and private keys. It is written in Go and released under the AGPL-3.0 license. It can be used from the command line and in pre-commit and CI scans as part of DevSecOps work.

Discovery reaches into Git repositories, chat tools, wikis, log files, API testing platforms, object stores and filesystems. Classification identifies more than 800 secret types and maps each to the identity it belongs to. Validation attempts to log in with the found secret to confirm whether it is still live, and analysis for roughly twenty common credential types sends further requests to learn who created the secret and what it can access. Truffle Security also sells an enterprise product that monitors systems such as Git, Jira, Slack and Confluence.

Key features

  • Scans Git, chats, wikis, logs and filesystems
  • Classifies over 800 secret types
  • Validates whether a found secret is live
  • Analyzes permissions of common credential types
  • Runs from the CLI and in pre-commit checks
  • Enterprise monitoring product available separately

Pricing: The open-source edition is free. Enterprise adds a dashboard, integrations, SSO and priority support, with pricing available by contacting the vendor.

Read more about TruffleHogWebsite GitHub

Semgrep

Semgrep is a fast, open-source static analysis tool that finds bugs and enforces security and coding standards across 30+ languages.

GitHub stars
17k
Last commit
yesterday
Latest release
v1.179.0
Licence
LGPL-2.1
Self-hosted
Yes
Hosted version
Available
semgrep.devSemgrep homepage screenshot

Semgrep is a lightweight static analysis tool that searches code, finds bugs and enforces secure guardrails and coding standards. It supports more than 30 languages and can run in an IDE, as a pre-commit check or inside CI/CD workflows. The core engine is released under the LGPL-2.1 license.

It works like a semantic grep for code. Rules are written to look like the source code developers already write, so matching a pattern does not require abstract syntax trees, regular expressions or a separate query language, and a search for a value can match code that computes it. The aim is to find variants of a known bug quickly.

The Community Edition analyzes code within a single function or file, which the maintainers note means it will miss many true positives for security work. For SAST, software composition analysis and secrets scanning they recommend the commercial Semgrep AppSec Platform, which adds cross-file and data-flow analysis, AI-assisted triage and managed rule sets.

Key features

  • Pattern-based code search that looks like code
  • Support for 30+ programming languages
  • Runs in IDEs, pre-commit hooks and CI/CD
  • Custom rules without ASTs or regex
  • SAST, SCA and secrets scanning via AppSec Platform

Pricing: Free for up to 10 contributors. Teams starts at $30 per contributor per month (Secrets $15); Enterprise is custom.

Read more about SemgrepWebsite GitHub

Grype

Command-line vulnerability scanner that checks container images, filesystems and SBOMs for known security issues in OS and language packages.

GitHub stars
13k
Last commit
today
Latest release
v0.120.0
Licence
Apache-2.0

Grype is an open-source vulnerability scanner for container images and filesystems. You point it at an image, a directory or a software bill of materials (SBOM), and it reports known vulnerabilities in the packages it finds, so teams can catch risky dependencies before software ships.

It covers major operating system package ecosystems such as Alpine, Debian, Ubuntu, RHEL, Oracle Linux and Amazon Linux, as well as language packages for Ruby, Java, JavaScript, Python, .NET, Go, PHP and Rust. Docker, OCI and Singularity image formats are supported. Results can be prioritized with EPSS, KEV and risk scoring, and OpenVEX documents can filter or augment findings.

Grype is written in Go and released under the Apache-2.0 license. It can be installed through Homebrew, Docker, Chocolatey, MacPorts and other routes, and the documentation includes a getting started guide, CLI reference and configuration reference. Development is sponsored by Anchore, which also handles commercial support requests for Grype and its companion tool Syft.

Key features

  • Scans container images, filesystems and SBOMs
  • OS package support for Alpine, Debian, Ubuntu, RHEL
  • Language package support including Python, Go, Java
  • Docker, OCI and Singularity image formats
  • EPSS, KEV and risk-score prioritization
  • OpenVEX filtering of scan results

Pricing: Free and open source under the Apache-2.0 license; commercial support is available from Anchore.

Read more about GrypeGitHub

Kubescape

Open-source Kubernetes security platform covering misconfiguration scanning, image vulnerabilities, compliance checks and runtime monitoring.

GitHub stars
12k
Last commit
today
Latest release
v4.0.15
Licence
Apache-2.0
Self-hosted
Yes
kubescape.ioKubescape homepage screenshot

Kubescape is an open-source Kubernetes security platform that covers the lifecycle from development to runtime. It was created by ARMO and is a Cloud Native Computing Foundation incubating project. It works in an IDE, in CI/CD pipelines and against running clusters, with the aim of saving administrators time on risk analysis and compliance work.

Misconfiguration scanning checks clusters, YAML files and Helm charts against NSA-CISA guidance, MITRE ATT&CK and CIS Benchmarks. Image vulnerability scanning detects CVEs using Grype, image patching uses Copacetic, and auto-remediation can fix manifest issues. Admission control uses Validating Admission Policies, runtime monitoring is eBPF-based through Inspektor Gadget, and an MCP server connects AI assistants.

Kubescape is written in Go and released under the Apache-2.0 license. It installs through options such as Homebrew and Krew, and an in-cluster operator is available for continuous scanning. Results include an overview of control plane status, access control risks, workload misconfigurations, network policy gaps and compliance scores.

Key features

  • Misconfiguration scanning against NSA-CISA, MITRE, CIS
  • Image vulnerability scanning with Grype
  • Automatic image patching with Copacetic
  • Auto-remediation for Kubernetes manifests
  • eBPF-based runtime security monitoring
  • In-cluster operator and MCP server

Pricing: Free and open source under the Apache-2.0 license.

Read more about KubescapeWebsite GitHub

SonarQube

Static code analysis platform that finds bugs, vulnerabilities and maintainability problems in code, in IDEs, pull requests and CI.

GitHub stars
11k
Last commit
yesterday
Latest release
26.9.0.129388
Licence
LGPL-3.0
Self-hosted
Yes
sonarqube.orgSonarQube homepage screenshot

SonarQube is a code quality and security platform. Its static analysis uses techniques such as symbolic execution and data and control flow analysis to inspect source code, find bugs and vulnerabilities, and explain what to fix and why. Results appear in the IDE, in pull requests and in CI pipelines.

This repository holds the source of the SonarQube Community Build, the free, open-source edition that shares the analysis used across the product line. It reports reliability bugs, security vulnerabilities and security hotspots, maintainability and structural issues, and coverage on new code. More than 40 programming languages and frameworks are covered, and the same code always produces the same findings.

The project positions itself as a verification step for code written by people or by AI agents before it merges. SonarQube is written in Java and licensed under LGPL-3.0. Commercial editions from SonarSource add further features, while the Community Build can be run on your own servers.

Key features

  • Static analysis for bugs and vulnerabilities
  • Security hotspot review guidance
  • Maintainability and structural issue detection
  • Coverage tracking on new code
  • Support for 40+ languages and frameworks
  • Feedback in IDE, pull requests and CI

Pricing: A free tier covers private projects up to 50k lines of code and an open-source Community Build is available. The Team plan starts at $34 a month for up to 100k lines of code; Enterprise is quoted.

Read more about SonarQubeWebsite GitHub

Falco

Cloud native runtime security tool that monitors Linux kernel events and alerts on abnormal behavior and threats in real time.

GitHub stars
9.4k
Last commit
2 days ago
Latest release
0.45.0
Licence
Apache-2.0
Self-hosted
Yes
falco.orgFalco homepage screenshot

Falco is a cloud native runtime security tool for Linux. It detects and alerts on abnormal behavior and potential security threats in real time. At its core it is a kernel monitoring and detection agent that watches events such as system calls and evaluates them against custom rules.

Falco can enrich events with metadata from the container runtime and from Kubernetes, and the collected events can be analyzed off-host in SIEM or data lake systems. The project is split across repositories in the falcosecurity organization: the main repo holds the Falco binary, while others hold the core libraries and kernel drivers, the official ruleset, and plugins that extend detection beyond syscalls and container events.

Falco was originally created by Sysdig and is a graduated project of the Cloud Native Computing Foundation, used in production by various organizations. It is written in C++ and released under the Apache-2.0 license, with a change log and detailed documentation on falco.org. Topics in the repository mention eBPF-based collection.

Key features

  • Kernel-level syscall monitoring
  • Custom detection rules
  • Container and Kubernetes metadata enrichment
  • Official ruleset for common threats
  • Plugins for additional event sources
  • Export to SIEM or data lake systems

Pricing: Free and open source under the Apache-2.0 license.

Read more about FalcoWebsite GitHub

Dependency-Track

An OWASP component analysis platform that uses SBOMs to identify and reduce risk in the software supply chain, with vulnerability tracking across projects.

GitHub stars
4.3k
Last commit
today
Latest release
5.1.1
Licence
Apache-2.0
Self-hosted
Yes
dependencytrack.orgDependency-Track homepage screenshot

Dependency-Track is a component analysis platform from the OWASP community that helps organizations identify and reduce risk in their software supply chain. It takes an approach built on the Software Bill of Materials (SBOM), analyzing the components listed for each project.

Repository topics show how it works with CycloneDX SBOMs, Package URLs, the National Vulnerability Database and OSS Index to detect known vulnerabilities in components, supporting software composition analysis, DevSecOps and security automation. A Docker Compose quickstart lets you get a local instance running in a few minutes.

Version 5 is the current line, while version 4 is in maintenance mode on the 4.14.x branch and reaches end-of-life in December 2026, with a migration guide provided. The frontend, documentation and Helm charts live in separate repositories, a monthly community meeting is open to users, and the project is written in Java under the Apache-2.0 license.

Key features

  • SBOM-based component analysis
  • CycloneDX and Package URL support
  • Vulnerability data from NVD and OSS Index
  • Software supply chain risk tracking
  • Docker Compose quickstart
  • Helm charts for deployment

Pricing: Free and open source under the Apache-2.0 licence.

Horusec

Horusec is a static application security testing tool that scans code in many languages for vulnerabilities and leaked secrets with one command.

GitHub stars
1.3k
Last commit
6 days ago
Latest release
v2.8.0
Licence
Apache-2.0
Self-hosted
Yes

Horusec is an open-source tool for static code analysis focused on security. It scans a project for security flaws during development, and can also search for leaked keys and credentials in project files and in Git history, so issues are found before they reach production.

It supports a wide range of languages and formats, including Java, Kotlin, Python, Ruby, Go, JavaScript, TypeScript, PHP, C#, Dart, Elixir, Shell, Terraform, Kubernetes manifests and Nginx configuration. It orchestrates multiple analysis tools, which is why Docker is recommended, although a flag allows running without it at the cost of analysis power. It can be used from the command line by developers, in CI/CD pipelines by DevSecOps teams, through a web application and in Visual Studio Code.

Horusec is written in Go and licensed under Apache-2.0, with installers for Mac, Linux and Windows and documentation listing every supported tool and language. It runs on your own machines or build servers. It suits development teams that want free SAST scanning in their pipelines.

Key features

  • Static analysis across many languages
  • Secret and key leak detection
  • Scanning of Git history
  • CLI and CI/CD pipeline usage
  • Horusec-Web application
  • Visual Studio Code integration

Pricing: Free and open source under the Apache-2.0 licence.

Read more about HorusecWebsite GitHub

1 more Aikido Security alternative

Aikido Security alternatives: questions

What is the best open-source alternative to Aikido Security?
Trivy is the top-ranked open-source alternative to Aikido Security on Enlisted: A security scanner that finds vulnerabilities, misconfigurations, secrets and license issues in container images, filesystems, Git repositories and Kubernetes. Other strong options are Gitleaks, TruffleHog, Semgrep and Grype.
Are these Aikido Security alternatives free?
All 11 are open source, so the code is free to use under its licence, and all of them can be self-hosted on your own server or computer. 1 also offers a paid or managed cloud version if you'd rather not host it yourself.
How is this list of Aikido Security alternatives ranked?
By a score built from GitHub stars, star growth over the last 30 days and how recently the code changed. 10 of these projects shipped code in the last 30 days. Data is refreshed daily, and nobody can pay to move up.

People also look for alternatives to…

View all