About DefectDojo
DefectDojo is a DevSecOps, application security posture management and vulnerability management tool. It orchestrates end-to-end security testing, tracks vulnerabilities, removes duplicate findings, supports remediation work and produces reports, giving security teams one place to see what scanners across the pipeline have found.
A simple way to try it is uploading sample scan reports, and the project provides Docker Compose instructions for a quick start plus public demo environments for both the commercial Pro edition and the OWASP Community Edition, which reset daily and should not hold sensitive data. Repository topics include vulnerability correlation, security automation and orchestration. It is built with Python and Django and can be deployed on Kubernetes.
The community edition is licensed under BSD-3-Clause and is run on your own infrastructure, while the vendor sells a Pro edition with additional features. It suits AppSec and product security teams consolidating results from many scanners.
Key features
- Vulnerability tracking and reporting
- Deduplication of scanner findings
- Import of security scan reports
- Remediation workflow management
- Docker Compose and Kubernetes deployment
- REST integration into DevSecOps pipelines
Good fit for
- →Consolidating results from security scanners
- →Application security program reporting
- →Tracking remediation across teams
- Tags
- vulnerability-management
- devsecops
- appsec
- aspm
- security
- django
- owasp
- python
Open-source alternatives to DefectDojo
See all
OpenVAS
Security
This repository contains the scanner component for Greenbone Community Edition.
GPL-2.0vs Tenable★ 4.8k
Wazuh
Security
Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints a
OSSvs Splunk★ 17k
Security Onion
Security
Security Onion is a free and open platform for threat hunting, enterprise security monitor
OSSvs Splunk★ 4.9k
Graylog
Monitoring & Observability
Free and open log management
OSSvs Splunk★ 8.2k
Dependency-Track
Security
Dependency-Track is an intelligent Component Analysis platform that allows organizations t
Apache-2.0vs Snyk★ 4.3k
fail2ban
Security
Daemon to ban hosts that cause multiple authentication errors
OSS★ 19k
SaaS alternatives to DefectDojo
See all
Tenable
Security
Vulnerability management and exposure assessment, maker of the Nessus scanner
SaaSRapid7
Security
Vulnerability management, SIEM and managed detection tools for security teams
SaaS
Qualys
Security
Cloud platform for vulnerability management, compliance and asset inventory
SaaS
Censys
Security
Internet scanning data and attack surface management platform
SaaS
Intruder
Security
Cloud-based vulnerability scanner for external attack surface
SaaS
Pentera
Security
Automated penetration testing and security validation platform
SaaS

