About tfsec
tfsec is a security scanner that uses static analysis of Terraform code to spot potential misconfigurations. It checks infrastructure as code against hundreds of built-in rules for the major cloud providers, so problems such as open storage or weak settings can be caught in review or CI before resources are deployed.
It scans local and remote modules, evaluates HCL expressions, Terraform functions and relationships between resources, works with the Terraform CDK, and applies user-defined Rego policies. Output is available in several formats, including a readable default and JSON. The README announces that tfsec is now part of Trivy, the broader Aqua Security scanner, and encourages users to migrate, with a guide comparing the two tools.
tfsec stays available for the time being, but engineering attention goes to Trivy, which offers more languages and integrations and commercial support from Aqua. tfsec is written in Go and licensed under MIT, and runs locally or in CI with nothing to host. It suits DevSecOps teams with existing Terraform scanning who are planning their move to Trivy.
Key features
- Static analysis of Terraform code
- Hundreds of built-in misconfiguration rules
- Scans local and remote modules
- Custom Rego policy support
- Multiple output formats
- Migration path to Trivy
Good fit for
- →Scanning Terraform in CI pipelines
- →Finding cloud misconfigurations before deployment
- →Planning a move from tfsec to Trivy
- Built with
- Go
- Tags
- terraform
- security
- static-analysis
- iac
- devsecops
- misconfiguration
- scanner
- go
- trivy
tfsec: questions and answers
- What is tfsec used for?
- tfsec is a static analysis scanner for Terraform code that finds cloud misconfigurations, now being folded into Aqua Security's Trivy. It is a good fit for scanning Terraform in CI pipelines, finding cloud misconfigurations before deployment and planning a move from tfsec to Trivy.
- Is tfsec open source?
- Yes. tfsec is open source under the MIT licence. Its source code is on GitHub at aquasecurity/tfsec and is written mainly in Go.
- Is tfsec free?
- Yes. tfsec is open source, so the software itself is free to use.
- What is tfsec an alternative to?
- tfsec is an open-source alternative to Aikido Security, Wiz, Orca Security and Aqua Security. Other open-source alternatives to Aikido Security include Grype, Kubescape and Trivy.
- Is tfsec actively maintained?
- The most recent commit to tfsec was on 25 March 2026, and the latest release is v1.28.14, published on 2 May 2025. The project has 7k stars on GitHub.
Open-source alternatives to tfsec
See all
Grype
Security
A vulnerability scanner for container images and filesystems
Apache-2.0vs Snyk★ 13k
Kubescape
Security
Kubescape is an open-source Kubernetes security platform for your IDE, CI/CD pipelines, an
Apache-2.0vs Wiz★ 12k
Trivy
Security
Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code rep
Apache-2.0vs Snyk★ 38k
Falco
Security
Cloud Native Runtime Security
Apache-2.0vs Wiz★ 9.4k
Horusec
Security
Horusec is an open source tool that improves identification of vulnerabilities in your pro
Apache-2.0vs Checkmarx★ 1.3k
Semgrep
Security
Lightweight static analysis for many languages. Find bug variants with patterns that look
LGPL-2.1vs Snyk★ 17k
SaaS alternatives to tfsec
See all
Aikido Security
Security
All-in-one application security platform for code, cloud and runtime scanning
SaaSWiz
Security
Agentless cloud security platform mapping risk across code, cloud and runtime
SaaS
Orca Security
Security
Agentless cloud security platform for workloads and configurations
SaaS
Aqua Security
Security
Cloud native security platform for containers, Kubernetes and serverless
SaaS
Prisma Cloud
Security
Cloud-native application protection platform from Palo Alto Networks
SaaS
Sysdig
Security
Cloud and container security platform with runtime threat detection
SaaS

