ArcherySec

B
B tier on Application Security Orchestration PlatformsScore 7.4 · #1 of 22
Android app
Not listed
Free plan
Yes
Runs on
api, Linux, Mac, self-hosted, Web, Windows
archerysec.com
The ArcherySec homepage

Summary

ArcherySec is a free, open-source vulnerability assessment and management tool for developers, penetration testers and DevOps teams. It scans web applications and networks using supported open-source tools, then brings findings into a consolidated view. Users can run authenticated web scans and web application scans with Selenium. Management features include severity-based prioritization and false-positive tracking, alongside finding deduplication and remediation workflows. The project lists more than 80 commercial and open-source tool integrations; documented connectors include OWASP ZAP, Burp, Arachni, OpenVAS, Jira and email. Its CLI can run in CI/CD pipelines and return pass or fail exit codes based on configured scan policies. REST APIs cover scanning and vulnerability management. Deployment documentation includes Linux, Docker, and Vagrant with Ansible options; Windows setup and run scripts are also provided. ArcherySec uses the GPL-3.0 license and is self-hosted. Users need to run supported scanners and provide their endpoints. The project advises against public exposure and recommends restricting signup in production.

Who it is for

It is intended for developers, penetration testers and DevOps teams managing vulnerabilities. It may suit teams that can run supported scanners and deploy and operate a self-hosted tool.

What is good

  • Consolidates findings from web and network scans
  • Supports severity prioritization and false-positive tracking
  • CLI can apply configured CI/CD scan policies
  • REST APIs cover scanning and vulnerability management

What to know first

  • Requires users to run supported scanners and provide endpoints
  • Self-hosted deployment requires setup
  • Project advises against public exposure
  • Production signup page should be restricted

Everything Xiaomi review

ArcherySec: the full review

ArcherySec combines scan findings and vulnerability workflows with CI/CD and API options, without a listed price. It requires separately run scanners and self-hosted deployment, and the project cautions against exposing it publicly.

Overview

ArcherySec is an open-source tool for vulnerability assessment and management, aimed at developers, penetration testers, and DevOps teams. It gathers findings from web and network scans performed by supported security tools, then presents those results together for review and management. Finding deduplication, severity prioritization, and false-positive tracking help organize the resulting work.

ArcherySec is self-hosted and distributed under the GPL-3.0 license. The project dates to 2017 and credits Anand Tiwari as maintainer. It depends on external scanners rather than replacing them: users need to run supported scanners and provide their endpoints to ArcherySec. It belongs to the broader Application Security Orchestration Platforms category.

Key features

Scanning and findings management

The tool supports web and network vulnerability scans, authenticated web scanning, and web application scanning with Selenium. It correlates raw scan data into a consolidated view, with rules-based risk prioritization and false-positive tracking. Finding deduplication is supported, and remediation workflows help manage findings beyond initial review.

Integrations and automation

The product site describes more than 80 integrations spanning commercial and open-source tools. Documented connectors include OWASP ZAP, Burp, Arachni, and OpenVAS for scanning, along with Jira and email. ArcherySec can synchronize tickets through its Jira connector.

Periodic and concurrent scans support ongoing vulnerability management. Its CLI can join CI/CD pipelines and return pass or fail exit codes according to configured scan policy criteria, allowing policy gates in an automated workflow. REST APIs are documented for scanning and vulnerability management.

Pricing

ArcherySec is free. The listed Open source plan costs 0.00 USD per free. It is GPL-3.0 licensed and uses self-hosted deployment; there is no paid plan listed in the provided pricing details.

Platforms

ArcherySec lists API, Linux, macOS, self-hosted, web, and Windows support. Deployment documentation covers Linux, Docker, and Vagrant with Ansible options, while the project README provides Windows setup and run scripts. Because ArcherySec relies on external scanners, users need to configure and run supported scanners separately and provide their endpoints.

The README cautions against exposing ArcherySec publicly and recommends restricting the signup page in production. It describes the default setup as intended for internal use only, an important deployment consideration for teams operating a self-hosted instance.

Who it's for

ArcherySec is suited to development, security testing, and DevOps teams that already use supported scanners and want a consolidated place to review vulnerabilities. Its scanner integrations and finding-management tools address the challenge of bringing multiple scan results together, while its CLI policy gates and APIs support teams incorporating vulnerability checks into automation.

It is less appropriate for users seeking a standalone scanner that works without external tools: scanner setup and endpoint configuration are prerequisites. Teams also need to account for the production security guidance when deploying it.

Pros and cons

  • Pros: Open-source GPL-3.0 licensing, self-hosted deployment, and no listed charge.
  • Pros: Consolidated findings, deduplication, severity-based prioritization, and false-positive tracking.
  • Pros: Documented scanner, ticketing, and email connectors, plus REST APIs and CI/CD policy gates.
  • Cons: Requires users to run supported scanners and provide their endpoints.
  • Cons: The README advises against public exposure and calls for signup restrictions in production.

Alternatives

Other options to consider include OWASP DefectDojo, ScanDog, Conviso Platform, Strobes ASPM, OX Security, PointGuard AI, Safeguard DAST, and Mend.io.

Verdict

ArcherySec brings scan results and vulnerability-management tasks into one self-hosted workflow, with integrations, APIs, and CI/CD policy checks for teams that want to automate parts of review. Its free, open-source model may suit teams prepared to operate the service and its scanners themselves. The key trade-off is operational responsibility: users must configure supported scanners and follow the project's guidance for restricting access in production.

ArcherySec plans and pricing

All plans
Open source Free GPL-3.0 licensed · self-hosted deployment docs.archerysec.com · 30 Sept 2026

Compared on application security orchestration platforms

Finding deduplication
Yesarcherysec.com
Risk prioritization
rules-basedarcherysec.com
Remediation workflows
Yesarcherysec.com
Policy gates
Yesarcherysec.com
Ticketing sync
Yesarcherysec.com
Deployment model
self-hostedarcherysec.com

Facts

Purpose
ArcherySec is an open-source vulnerability assessment and management tool for developers and penetration testers.docs.archerysec.com · 30 Sept 2026
Scanning
It performs web and network vulnerability scans using open-source tools and consolidates scan findings.docs.archerysec.com · 30 Sept 2026
Authenticated scans
It supports authenticated web scanning and web application scanning with Selenium.docs.archerysec.com · 30 Sept 2026
Vulnerability management
It provides vulnerability management, including prioritization by severity and false-positive tracking.archerysec.com · 30 Sept 2026
Scanner integrations
The product site says ArcherySec supports more than 80 commercial and open-source tool integrations.archerysec.com · 30 Sept 2026
Connectors
Documented connectors include OWASP ZAP, Burp, Arachni, OpenVAS, Jira, and email.docs.archerysec.com · 30 Sept 2026
CI/CD
Its CLI integrates with CI/CD pipelines and returns pass or fail exit codes based on configured scan policy criteria.docs.archerysec.com · 30 Sept 2026
API
The documentation describes REST APIs for scanning and vulnerability management.docs.archerysec.com · 30 Sept 2026
Deployment
The documentation provides Linux, Docker, and Vagrant with Ansible deployment options.docs.archerysec.com · 30 Sept 2026
Windows support
The project README provides Windows setup and run scripts.github.com · 30 Sept 2026
License
The documentation says ArcherySec is distributed under the GPL-3.0 license.docs.archerysec.com · 30 Sept 2026
Security guidance
The project README says not to expose ArcherySec publicly and recommends restricting the signup page in production.github.com · 30 Sept 2026
Support
The Jira connector documentation directs users with questions to [email protected] or to raise an issue.docs.archerysec.com · 30 Sept 2026
Intended users
The documentation describes the tool as useful for developers, penetration testers, and DevOps teams managing vulnerabilities.docs.archerysec.com · 30 Sept 2026
Finding management
It correlates raw scan data and presents it in a consolidated view for vulnerability management.docs.archerysec.com · 30 Sept 2026
Automation
It supports periodic and concurrent scans and can be used in DevOps CI/CD environments.docs.archerysec.com · 30 Sept 2026
Integrations
Documented connectors include OWASP ZAP, Burp, Arachni, OpenVAS, Jira, and email.docs.archerysec.com · 30 Sept 2026
Scanner setup
Users must run supported scanners and provide ArcherySec with their endpoints.docs.archerysec.com · 30 Sept 2026
Deployment caution
The project README advises restricting the signup page in production and labels the default setup for internal use only.github.com · 30 Sept 2026
Project maintainer
The project documentation credits Anand Tiwari and dates the project copyright from 2017 to 2025.docs.archerysec.com · 30 Sept 2026

Company

Founded
2017archerysec.com · 28 Sept 2026
Headquarters
Indiaarcherysec.com · 28 Sept 2026

Best ArcherySec alternatives

See all 12

Where it ranks on Everything Xiaomi

Is ArcherySec yours?

Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.

Sources