The AFL++ homepage
Score6.6
Rank#47 of 78
From€1666.67/mo
Free planYes
Runs onAndroid, Linux, macOS, Self-hosted, Windows

Summary

AFL++ is a free, coverage-guided fuzzer that changes program inputs and checks whether a target binary reaches previously unseen execution paths. Its afl-cc compiler supports LTO, LLVM, and GCC_PLUGIN instrumentation. The project also lists collision-free coverage, AFLfast++ power schedules, MOpt mutators, laf-intel, and redqueen. Documentation covers fuzzing programs with available source, binary-only targets, network services, and GUI programs. Builds can target source-only fuzzing, binary-only fuzzing, or a distribution containing both. A Docker image is provided for x86_64 and arm64, with an example that mounts target source at /src. On Linux, the installation guide recommends LLVM 18 or newer and gives LLVM 14 as the minimum. macOS build guidance covers x86_64 and arm64, but says afl-clang-lto, afl-gcc-fast, and qemu_mode do not work there. The project warns that fuzzing can tax hardware, use substantial memory or disk, and create heavy filesystem activity. The combined afl-fuzz program is AGPL-licensed; modified versions offered as network services must provide users the corresponding source. A commercial license is listed at 20000.00 EUR per year.

Who it is for

AFL++ is for developers and security practitioners fuzzing source-available software, binary-only targets, network services, or GUI programs. Users should be comfortable with its AGPL obligations or the separately listed commercial license.

What is good

  • Supports multiple compiler instrumentation modes.
  • Covers source, binary, network, and GUI targets.
  • Docker image supports x86_64 and arm64.
  • Free under AGPL-3.0-or-later.
  • Includes guidance for crash triage and coverage.

What to know first

  • Fuzzing can consume substantial memory or disk.
  • Fuzzing can create heavy filesystem activity.
  • Several listed modes do not work on macOS.
  • Modified network services must offer corresponding source under AGPL.

Verdict

AFL++ offers a broad set of fuzzing targets and instrumentation options, with a free AGPL license. Review the license obligations, platform-specific limitations, and resource demands before using it.

AFL++ plans and pricing

All plans
AGPL-3.0-or-later Free Use, study, modify, and distribute under AGPL terms · modified network services must offer corresponding source github.com · 28 Sept 2026
Commercial license €20,000/yr Donation to EFF or CCC; license lasts one year and can be renewed by donating again For organizations that cannot or do not want to comply with AGPL · proof of donation must be emailed github.com · 28 Sept 2026

Compared on game mod managers

Free plan
Yesgithub.com
Input generation methods
mutationgithub.com
Target types
source-code targets, binary-only targets, file inputs, stdin inputs, Android native libraries, Win32 PE binariesgithub.com
Coverage guidance
Yesgithub.com
Crash triage
Yesgithub.com
Execution mode
localgithub.com
Supported languages
C, C++, Python, Rustgithub.com
CI/CD support
Yesgithub.com

Facts

Purpose
AFL++ is a coverage-guided fuzzer that mutates input and checks whether it reaches a new path in the target binary.github.com · 28 Sept 2026
Compiler instrumentation
Its central afl-cc compiler supports LTO, LLVM, and GCC_PLUGIN instrumentation modes.github.com · 28 Sept 2026
Mutation and coverage
The project lists collision-free coverage, AFLfast++ power schedules, MOpt mutators, laf-intel, and redqueen among its features.github.com · 28 Sept 2026
Build modes
Build targets include source-only fuzzing, binary-only fuzzing, or a distribution build with both.github.com · 28 Sept 2026
Container image
The project provides a Docker image for x86_64 and arm64, with the target source mounted at /src in its example command.github.com · 28 Sept 2026
Linux requirements
The installation guide recommends LLVM 18 or newer and gives LLVM 14 as the minimum.github.com · 28 Sept 2026
macOS support
The guide documents building on macOS x86_64 and arm64, but says afl-clang-lto, afl-gcc-fast, and qemu_mode do not work there.github.com · 28 Sept 2026
License obligations
The combined afl-fuzz program is AGPL as a whole, and modified versions offered as network services must offer users the corresponding source.github.com · 28 Sept 2026
License exceptions
Individual source files marked Apache-2.0 may be reused under that license, while bundled third-party components retain their own licenses.github.com · 28 Sept 2026
Hardware and storage limits
The project warns that fuzzing can strain hardware, consume large amounts of memory or disk, and generate heavy filesystem I/O.github.com · 28 Sept 2026
Support
The maintainers direct users to GitHub issues for AFL++ defects, the FAQ and best practices, and the Fuzzing Zulip server.github.com · 28 Sept 2026
Release channels
The stable branch is described as the stability-focused default, while dev is bleeding edge and may fail to compile or contain bugs.github.com · 28 Sept 2026

Company

Founded
2019github.com · 28 Sept 2026

Best AFL++ alternatives

See all 12

Where it ranks on Everything Xiaomi

Is AFL++ yours?

Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.

Sources