getapp-logo

App comparison

Add up to 4 apps below to see how they compare. You can also use the "Compare" buttons while browsing.

GetApp offers objective, independent research and verified user reviews. We may earn a referral fee when you visit a vendor through our links. 

Top Rated Penetration Testing Software with Github

Last updated: September 2026

1 filter applied

Features

No filters available


Integrated with


Pricing model


Devices supported


Organization types


User rating


15 software options

Astra Pentest logo

Continuous Pentests (VAPT) that scales with your dev velocit

learn more
AI Powered offensive Pentest Platform

Read more about Astra Pentest

Users also considered
Xora logo

AppSec isn't a one-time event, Pentests shouldn't be either

learn more
Imagine a solution that actually found and fixed security issues within code before it ever shipped?

Xora is modern code security for the AI era. It bridges the gap from "found" to "fixed and verified" so that security leaders can sleep at night knowing their application is secure.

Read more about Xora

Users also considered
Pentest-Tools.com logo

Discover what's possible. Prove what's real.

learn more
From vulnerability scans to proof, Pentest-Tools.com gives 2,000+ security teams in 119 countries the speed, accuracy, and coverage to confidently validate and mitigate risks across their infrastructure (network, cloud, web apps, APIs).

Read more about Pentest-Tools.com

Users also considered
Invicti logo

Proof-based application security testing platform

learn more
Invicti is a web application and API security platform that provides proof-based vulnerability scanning with DAST, SAST, and ASPM capabilities. The platform discovers and tests websites, applications, and APIs while correlating security findings from multiple tools to prioritize real vulnerabilities. It integrates with CI/CD pipelines and offers AI-powered remediation guidance to help development teams address security issues efficiently.

Read more about Invicti

Users also considered
HackerOne logo

Cybersecurity platform to identify and fix vulnerabilities

learn more
HackerOne is a web-based cybersecurity platform designed to help businesses across various industry verticals such as education, telecom, aviation, media, financial services, and more eliminate vulnerabilities by securing continuous development processes.

Read more about HackerOne

Users also considered
Acunetix logo

Cloud-based and automated web application security solution

learn more
Acunetix is a cybersecurity solution offering automatic web security testing technology that enables organizations to scan and audit complex, authenticated, HTML5 and JavaScript-heavy websites to detect vulnerabilities such as XSS, SQL Injection, and more.

Read more about Acunetix

Users also considered
Strobes PTaaS logo

Continuous and On-Demand Pentesting Platform

learn more
Strobes PTaaS is a cloud-based and on-premise vulnerability scanner that is designed for businesses in banking, network security, healthcare, telecommunications, and other sectors. Platform-enabled pentesting from the best white hats gives you faster collaboration and better results. By transitioning from ad-hoc penetration testing to continuous, on-demand pentesting, you will be able to level up your delivery.

Read more about Strobes PTaaS

Users also considered
Gordon VAPT logo

Automated vuln scanning & penetration testing

learn more
Gordon VAPT is a vulnerability assessment and penetration testing platform that combines continuous automated scanning with expert-led security testing. The solution performs automated vulnerability detection across web applications, APIs, cloud infrastructure, network devices, and endpoints using DAST, SAST, and SCA scanning methods. It includes manual penetration testing conducted by CERT-In empanelled security researchers who validate findings and test for business logic flaws.

Read more about Gordon VAPT

Users also considered
Sn1per logo

Get an attacker’s view of your organization!

learn more
Introducing Sn1per Professional – the leading security scanning solution to discover hidden vulnerabilities and assets in your environment.

Read more about Sn1per

Users also considered
Blacklock logo

Cybersecurity testing and monitoring platform

learn more
BlackLock offers a Penetration Testing as a Service (PTaaS) platform combining automated vulnerability scanning with CREST-certified manual testing. It features continuous security monitoring, vulnerability orchestration via a dashboard, and integration with development workflows for DevSecOps. BlackLock provides actionable reports for various audiences and AI-enabled remediation assistance for vulnerabilities.

Read more about Blacklock

Users also considered
TurboPentest logo

Blockchain-attested collaborative agentic pentesting

learn more
TurboPentest delivers agentic AI penetration testing powered by P4L4D1N AI. Up to 20 autonomous agents orchestrate 15 tools including Nmap, OWASP ZAP, Nuclei, Semgrep, Trivy, OpenVAS. PDF report, blockchain attestation, attack surface map, threat model. Results in up to 4 hours. From $99/target.

Read more about TurboPentest

Users also considered
Beagle Security logo

Secure your web apps & APIs from the latest vulnerabilities

learn more
Beagle Security helps you to identify security weaknesses and vulnerabilities on your web apps & APIs before hackers harm you in any way.

Read more about Beagle Security

Users also considered
Cobalt logo

(previously CrowdCurity) Pen Testing as a Service

learn more
Cobalt - previously CrowdCurity - is a modern application security platform that supports a complete find-to-fix workflow for all penetration testing and vulnerability assessments throughout an organization

Read more about Cobalt

Users also considered
YesWeHack logo

Offensive Security & Exposure Management Platform

learn more
YesWeHack is a leading Offensive Security and Exposure Management platform delivering integrated, API-based solutions to secure organisations’ growing attack surfaces. Its human-in-the-loop model combines Bug Bounty, Autonomous Pentesting, Continuous Pentesting and unified vulnerability management.

Read more about YesWeHack

Users also considered
Akto logo

API Security Platform for Modern Appsec teams

learn more
Akto is an industry-leading solution for API discovery, API security posture management, sensitive data exposure, API security testing.

Read more about Akto

Users also considered