Security and PKI
33 services with free tiers in the Security and PKI category. Synced daily from the community-maintained free-for-dev list.
33 of 33
aikido.dev
aikido.devAll-in-one appsec platform covering SCA, SAST, CSPM, DAST, Secrets, IaC, Malware, Container scanning, EOL,... Free plan includes two users, scanning of 10 repos, 1 cloud, 2 containers & 1 domain.
(opens in a new tab)CertKit
certkit.ioManage SSL Certificate issuance, renewal, and monitoring. Search the Certificate Transparency Logs. Free for 3 certificates and 1 user after the beta.
(opens in a new tab)Corgea
corgea.comFree autonomous security platform that finds, validates and fixes insecure code and packages across +20 languages and frameworks. Free plan includes 1 user and 2 repos.
(opens in a new tab)crypteron.com
crypteron.comCloud-first, developer-friendly security platform prevents data breaches in .NET and Java applications
(opens in a new tab)CyberChef
gchq.github.ioA simple, intuitive web app for analyzing and decoding/encoding data without dealing with complex tools or programming languages. Like a Swiss army knife of cryptography & encryption. All features are free to use, with no limit. Open source if you wish to self-host.
(opens in a new tab)Datree
datree.ioOpen Source CLI tool to prevent Kubernetes misconfigurations by ensuring that manifests and Helm charts follow best practices as well as your organization’s policies
(opens in a new tab)Dependabot
dependabot.comAutomated dependency updates for Ruby, JavaScript, Python, PHP, Elixir, Rust, Java (Maven and Gradle), .NET, Go, Elm, Docker, Terraform, Git Submodules, and GitHub Actions.
(opens in a new tab)DJ Checkup
djcheckup.comScan your Django site for security flaws with this free, automated checkup tool. Forked from the Pony Checkup site.
(opens in a new tab)Doppler
doppler.comUniversal Secrets Manager for application secrets and config, with support for syncing to various cloud providers. Free for five users with basic access controls.
(opens in a new tab)Dotenv
dotenv.orgSync your .env files, quickly & securely. Stop sharing your .env files over insecure channels like Slack and email, and never lose an important .env file again. Free for up to 3 teammates.
(opens in a new tab)GitGuardian
gitguardian.comKeep secrets out of your source code with automated secrets detection and remediation. Scan your git repos for 350+ types of secrets and sensitive files - Free for individuals and teams of 25 developers or less.
(opens in a new tab)HasMySecretLeaked
gitguardian.comSearch across 20 million exposed secrets in public GitHub repositories, gists, issues,and comments for Free
(opens in a new tab)Have I been pwned?
haveibeenpwned.comREST API for fetching the information on the breaches.
(opens in a new tab)hostedscan.com
hostedscan.comOnline vulnerability scanner for web applications, servers, and networks. Ten free scans per month.
(opens in a new tab)Infisical
infisical.comOpen source platform that lets you manage developer secrets across your team and infrastructure: everywhere from local development to staging/production 3rd-party services. Free for up to 5 developers.
(opens in a new tab)Internet.nl
internet.nlTest for modern Internet Standards like IPv6, DNSSEC, HTTPS, DMARC, STARTTLS and DANE
(opens in a new tab)IntoDNS.ai
intodns.aiDNS and email security analyzer that checks SPF, DKIM, DMARC, DNSSEC, BIMI, MTA-STS, and 40+ blacklists with AI-powered explanations and fix suggestions. 100% free, no signup required.
(opens in a new tab)letsencrypt.org
letsencrypt.orgFree SSL Certificate Authority with certs trusted by all major browsers
(opens in a new tab)meterian.io
meterian.ioMonitor Java, Javascript, .NET, Scala, Ruby, and NodeJS projects for security vulnerabilities in dependencies. Free for one private project, unlimited projects for open source.
(opens in a new tab)Mozilla Observatory
observatory.mozilla.orgFind and fix security vulnerabilities in your site.
(opens in a new tab)Otterwatch
otterwatch.devDaily SSL/TLS certificate monitoring: expiry alerts (30/7/1 day), chain and OCSP revocation checks, and certificate transparency issuance history. Free forever for 5 domains, no credit card.
(opens in a new tab)Protectumus
protectumus.comFree website security check, site antivirus, and server firewall (WAF) for PHP. Email notifications for registered users in the free tier.
(opens in a new tab)Public Cloud Threat Intelligence
cloudintel.himanshuanand.comHigh confidence Indicator of Compromise(IOC) targeting public cloud infrastructure, A portion is available on github (https://github.com/unknownhad/AWSAttacks). Full list is available via API
(opens in a new tab)pyup.io
pyup.ioMonitor Python dependencies for security vulnerabilities and update them automatically. Free for one private project, unlimited projects for open source.
(opens in a new tab)qualys.com
qualys.comFind web app vulnerabilities, audit for OWASP Risks
(opens in a new tab)SikkerKey
sikkerkey.comMachine authenticated secrets manager, includes 2 projects, 2 bootstrapped machines, 20 secrets and 7 days audit log retention for free.
(opens in a new tab)Smart Grow Vault
vault.smart-grow.appSecure Enterprise-grade platform for managing environment variables and secrets. Free tier includes up to 3 applications and 150 secrets per project.
(opens in a new tab)Socket
socket.devFree supply chain security for individual developers, small teams, and open source projects. Includes a free app and firewall CLI tool to protect your code from vulnerable and malicious dependencies. Detects 70+ indicators of supply chain risk.
(opens in a new tab)SOOS
soos.ioFree, unlimited SCA scans for open-source projects. Detect and fix security threats before release. Protect your projects with a simple and effective solution.
(opens in a new tab)ssllabs.com
ssllabs.comIntense analysis of the configuration of any SSL web server
(opens in a new tab)Sucuri SiteCheck
sitecheck.sucuri.netFree website security check and malware scanner
(opens in a new tab)TestTLS.com
testtls.comTest an SSL/TLS service for secure server configuration, certificates, chains, etc. Not limited to HTTPS.
(opens in a new tab)Virgil Security
virgilsecurity.comTools and services for implementing end-to-end encryption, database protection, IoT security, and more in your digital solution. Free for applications with up to 250 users.
(opens in a new tab)Attribution
Data sourced from ripienaar/free-for-dev (CC-BY-SA). Synced every 24 hours.