Matomo is a full-featured, open-source web analytics platform that serves as a privacy-focused alternative to Google Analytics, allowing users to host their own data.
Open source. Open possibilities.
Discover quality open-source projects, submit projects anonymously, and claim and edit your own project.
A little curiosity. A world of open source.
THE FIRST COLLECTIONWPScan is a command-line WordPress security scanner that detects vulnerabilities, enumerates plugins, themes, users, and backup folders, and integrates with the WPScan vulnerability database API for real-time security assessments.
An interactive, TLS-capable intercepting HTTP proxy designed for penetration testers and software developers to analyze network traffic.
A transport-agnostic OAuth 2.1 and OpenID Connect server built on OpenIddict and redb.Route, supporting multiple databases, MFA, WebAuthn, SCIM, and in-process direct-vm calls.
Self-hosted GitHub App that publishes a required check accepting human CODEOWNER approval or approval from explicitly enrolled GitHub Apps, with organization and repository policies; pre-release and shadow-mode only.
Dart wrapper for OpenMLS implementing Messaging Layer Security (MLS) protocol for encrypted group messaging, with TreeKEM, encrypted storage, cross‑platform Flutter support, and experimental post‑quantum ciphersuites.
Cilium is an eBPF-based networking, security, and observability solution for Kubernetes. It offers CNI networking, identity-based L3-L7 policies, distributed load balancing that can replace kube-proxy, multi-cluster Cluster Mesh, service mesh with mutual authentication, and Hubble observability. It is a CNCF Graduated project with Apache 2.0-licensed user space code.
Falco is a cloud‑native runtime security tool for Linux that monitors kernel events and container activity, detects anomalies, and alerts on potential threats using customizable rules. It integrates with SIEMs and Kubernetes.
Open-source disassembly framework written in pure C, supporting 20+ architectures including x86, ARM, AArch64, RISC-V, MIPS and PowerPC, with a clean architecture-neutral API, multi-language bindings, and detailed instruction semantics for binary analysis and reverse engineering.
Sniffnet is a free, cross-platform, open-source application for comfortably monitoring network traffic, with real-time charts, host geolocation, service identification, PCAP import/export and customizable notifications.
x64dbg is an open-source user-mode debugger for Windows, aimed at reverse engineering and malware analysis of executables whose source code is unavailable. It ships 32-bit and 64-bit builds, a plugin system, and can be compiled from source by users.
Iris is a local-first MCP server that scores AI agent runs for quality, safety, and cost using 20 built-in deterministic rules, an optional LLM judge, and a web dashboard — all on your machine with no account or telemetry.
An advanced, system-level personal security and anti-coercion suite for Android. Running as a systemless priv-app with LSPosed hooks, it provides duress PINs, hardware tripwires, and remote SMS control.
Sophia Stack is a modern, atomic X11 desktop system designed to replace ambient trust with explicit authority boundaries and isolated namespaces.
Web-Check is an open-source, self-hostable OSINT dashboard for analysing any website. It gathers IP, DNS, SSL, headers, cookies, crawl rules, ports, traceroute, server location, redirects, trackers, performance and carbon footprint data.
GitHub profile README for Sachin, a self-described applied AI architect and engineer. It points to selected open-source projects covering agents, retrieval (RAG), evaluation and reliability tooling, and lists skills, working style, engagement terms and contact details.
Trivy is a comprehensive security scanner used to detect vulnerabilities, misconfigurations, secrets, and SBOMs across various targets including containers, Kubernetes, and code repositories.
A curated collection of Web Application Security payloads and bypasses for pentesting and CTFs, covering vulnerability descriptions, exploitation techniques, and Burp Intruder file sets.
Template-driven vulnerability scanner with a YAML DSL, community templates, and support for HTTP, DNS, TCP, SSL, WHOIS, JavaScript, headless browser, fuzzing, CI/CD integration, and multiple report formats.
Infisical is an open-source platform for secrets management, certificate/PKI lifecycle, key management, and privileged access management. Features include a dashboard, CLI, SDKs and API, secret syncs and rotation, leak scanning, a Kubernetes operator, and self-hosting via Docker.