DefectDojo

An open source, self-hosted vulnerability management platform that collects and tracks findings from security scanners.

These buttons open the developer's own site, repository or store listing in a new tab. wares.gg does not host downloads.

About DefectDojo

DefectDojo is a vulnerability management platform that came out of the OWASP community. Teams run it on their own servers to import results from security tools through parsers and integrations, then track and manage the findings in one place. It also has an API for automation.

The Community Edition is published on GitHub and maintained in the open, with an active Slack. A commercial Pro edition adds further features.

Strengths

  • Imports findings from many security tools through community parsers
  • Self-hosted, with an API for automation
  • Active open development and frequent releases

Limitations

  • Some features are reserved for the paid Pro edition
  • Requires running and maintaining your own server

Details

Pricing
FreemiumCommunity Edition is free and open source; a paid Pro edition is available.
License
Open source, license not stated
Developer
The DefectDojo contributors
Platforms
Web, Self-hosted
How it runs
Self-hosted
Best suited for
Security teams consolidating scanner findings on their own infrastructure
Last verified
Added
Provenance
Selected from the TechWalrus Resource Hub (Enterprise & Workplace IT); facts checked against the developer's own pages, 2 sources on file.

Report a wrong fact or a dead link on this listing