About VPS Audit
VPS Audit, from Nuver Labs, is a lightweight Bash script for auditing the security and performance of Linux servers. You download it, make it executable and run it with sudo, and it runs a series of checks, prints color-coded results in the terminal, and writes a detailed report file with recommendations for anything that failed.
Security checks cover SSH configuration such as root login, password authentication and non-default ports, firewall status across UFW, firewalld, iptables and nftables, intrusion prevention with Fail2ban or CrowdSec, failed login attempts, system updates, running services, open ports, sudo logging, password policy and SUID files. Performance checks report disk space, memory, CPU and active internet connections.
The script targets Ubuntu and Debian-based systems and needs root access plus common packages such as ufw, systemd, ss or netstat, grep and awk. It is MIT licensed and runs locally with nothing to install on a server or hosted service. It suits sysadmins and developers who manage their own VPS instances and want a quick baseline hardening check.
Key features
- SSH configuration checks
- Firewall and intrusion prevention checks
- Failed login and update status review
- Open ports and SUID file detection
- Disk, memory, and CPU usage report
- Color-coded results and a saved report file
Good fit for
- →Quick security baseline for a new VPS
- →Periodic server hardening checks
- →Spotting misconfigured Fail2ban or SSH settings
- Built with
- Shell
- Tags
- security-audit
- bash
- linux
- vps
- server-hardening
- monitoring
- devops
- ubuntu
- shell
VPS Audit: questions and answers
- What is VPS Audit used for?
- VPS Audit is a dependency-free Bash script that audits the security and performance of Ubuntu or Debian VPS servers and writes a report with recommendations. It is a good fit for quick security baseline for a new VPS, periodic server hardening checks and spotting misconfigured Fail2ban or SSH settings.
- Is VPS Audit open source?
- Yes. VPS Audit is open source under the MIT licence. Its source code is on GitHub at nuver-labs/vps-audit and is written mainly in Shell.
- Is VPS Audit free?
- Yes. VPS Audit is open source, so the software itself is free to use.
- What are some alternatives to VPS Audit?
- Similar open-source tools in the Security category include acme.sh, osquery and Infisical. SaaS products in the same category include Adverse Monitor, Amazon GuardDuty and AWS Secrets Manager.
- Is VPS Audit actively maintained?
- Yes. The most recent commit to VPS Audit was on 10 August 2026, and the latest release is v0.2.0, published on 10 August 2026. The project has 3.2k stars on GitHub.
Open-source alternatives to VPS Audit
See all
acme.sh
Security
A pure Unix shell script ACME client for SSL / TLS certificate automation
GPL-3.0vs DigiCert★ 48k
osquery
Security
SQL powered operating system instrumentation, monitoring, and analytics.
OSSvs Tanium★ 24k
Infisical
Security
Infisical is the open-source platform for secrets, certificates, and privileged access man
OSSvs Doppler★ 30k
fail2ban
Security
Daemon to ban hosts that cause multiple authentication errors
OSS★ 19k
Certimate
Security
ssl tls https ssl-certificate ssl-certificates ssl-cert https-certificate https-certificat
MITvs Sectigo★ 9.3k
Falco
Security
Cloud Native Runtime Security
Apache-2.0vs Wiz★ 9.4k
SaaS alternatives to VPS Audit
See all
Adverse Monitor
Security
Cyber threat intelligence tool that watches the dark web for incident claims naming your company
SaaS
Amazon GuardDuty
Security
Managed AWS threat detection service for accounts, workloads and data
SaaS
AWS Secrets Manager
Security
Managed service to store, rotate and retrieve database credentials and API keys
SaaS
Beacky
Security
Invisible beacons that alert you when your website is cloned on unauthorized domains
SaaS
Doppler
Security
Secrets management platform that syncs environment variables across apps and teams
SaaS
42Crunch
Security
API security platform that audits OpenAPI definitions and protects APIs at runtime
SaaS

