ArcherySec
- Android app
- Not listed
- Free plan
- Yes
- Runs on
- api, Linux, Mac, self-hosted, Web, Windows

Summary
ArcherySec is a free, open-source vulnerability assessment and management tool for developers, penetration testers and DevOps teams. It scans web applications and networks using supported open-source tools, then brings findings into a consolidated view. Users can run authenticated web scans and web application scans with Selenium. Management features include severity-based prioritization and false-positive tracking, alongside finding deduplication and remediation workflows. The project lists more than 80 commercial and open-source tool integrations; documented connectors include OWASP ZAP, Burp, Arachni, OpenVAS, Jira and email. Its CLI can run in CI/CD pipelines and return pass or fail exit codes based on configured scan policies. REST APIs cover scanning and vulnerability management. Deployment documentation includes Linux, Docker, and Vagrant with Ansible options; Windows setup and run scripts are also provided. ArcherySec uses the GPL-3.0 license and is self-hosted. Users need to run supported scanners and provide their endpoints. The project advises against public exposure and recommends restricting signup in production.
Who it is for
It is intended for developers, penetration testers and DevOps teams managing vulnerabilities. It may suit teams that can run supported scanners and deploy and operate a self-hosted tool.
What is good
- Consolidates findings from web and network scans
- Supports severity prioritization and false-positive tracking
- CLI can apply configured CI/CD scan policies
- REST APIs cover scanning and vulnerability management
What to know first
- Requires users to run supported scanners and provide endpoints
- Self-hosted deployment requires setup
- Project advises against public exposure
- Production signup page should be restricted
Everything Xiaomi review
ArcherySec: the full review
ArcherySec combines scan findings and vulnerability workflows with CI/CD and API options, without a listed price. It requires separately run scanners and self-hosted deployment, and the project cautions against exposing it publicly.
Overview
ArcherySec is an open-source tool for vulnerability assessment and management, aimed at developers, penetration testers, and DevOps teams. It gathers findings from web and network scans performed by supported security tools, then presents those results together for review and management. Finding deduplication, severity prioritization, and false-positive tracking help organize the resulting work.
ArcherySec is self-hosted and distributed under the GPL-3.0 license. The project dates to 2017 and credits Anand Tiwari as maintainer. It depends on external scanners rather than replacing them: users need to run supported scanners and provide their endpoints to ArcherySec. It belongs to the broader Application Security Orchestration Platforms category.
Key features
Scanning and findings management
The tool supports web and network vulnerability scans, authenticated web scanning, and web application scanning with Selenium. It correlates raw scan data into a consolidated view, with rules-based risk prioritization and false-positive tracking. Finding deduplication is supported, and remediation workflows help manage findings beyond initial review.
Integrations and automation
The product site describes more than 80 integrations spanning commercial and open-source tools. Documented connectors include OWASP ZAP, Burp, Arachni, and OpenVAS for scanning, along with Jira and email. ArcherySec can synchronize tickets through its Jira connector.
Periodic and concurrent scans support ongoing vulnerability management. Its CLI can join CI/CD pipelines and return pass or fail exit codes according to configured scan policy criteria, allowing policy gates in an automated workflow. REST APIs are documented for scanning and vulnerability management.
Pricing
ArcherySec is free. The listed Open source plan costs 0.00 USD per free. It is GPL-3.0 licensed and uses self-hosted deployment; there is no paid plan listed in the provided pricing details.
Platforms
ArcherySec lists API, Linux, macOS, self-hosted, web, and Windows support. Deployment documentation covers Linux, Docker, and Vagrant with Ansible options, while the project README provides Windows setup and run scripts. Because ArcherySec relies on external scanners, users need to configure and run supported scanners separately and provide their endpoints.
The README cautions against exposing ArcherySec publicly and recommends restricting the signup page in production. It describes the default setup as intended for internal use only, an important deployment consideration for teams operating a self-hosted instance.
Who it's for
ArcherySec is suited to development, security testing, and DevOps teams that already use supported scanners and want a consolidated place to review vulnerabilities. Its scanner integrations and finding-management tools address the challenge of bringing multiple scan results together, while its CLI policy gates and APIs support teams incorporating vulnerability checks into automation.
It is less appropriate for users seeking a standalone scanner that works without external tools: scanner setup and endpoint configuration are prerequisites. Teams also need to account for the production security guidance when deploying it.
Pros and cons
- Pros: Open-source GPL-3.0 licensing, self-hosted deployment, and no listed charge.
- Pros: Consolidated findings, deduplication, severity-based prioritization, and false-positive tracking.
- Pros: Documented scanner, ticketing, and email connectors, plus REST APIs and CI/CD policy gates.
- Cons: Requires users to run supported scanners and provide their endpoints.
- Cons: The README advises against public exposure and calls for signup restrictions in production.
Alternatives
Other options to consider include OWASP DefectDojo, ScanDog, Conviso Platform, Strobes ASPM, OX Security, PointGuard AI, Safeguard DAST, and Mend.io.
Verdict
ArcherySec brings scan results and vulnerability-management tasks into one self-hosted workflow, with integrations, APIs, and CI/CD policy checks for teams that want to automate parts of review. Its free, open-source model may suit teams prepared to operate the service and its scanners themselves. The key trade-off is operational responsibility: users must configure supported scanners and follow the project's guidance for restricting access in production.
ArcherySec plans and pricing
All plansCompared on application security orchestration platforms
- Finding deduplication
- Yesarcherysec.com
- Risk prioritization
- rules-basedarcherysec.com
- Remediation workflows
- Yesarcherysec.com
- Policy gates
- Yesarcherysec.com
- Ticketing sync
- Yesarcherysec.com
- Deployment model
- self-hostedarcherysec.com
Facts
- Purpose
- ArcherySec is an open-source vulnerability assessment and management tool for developers and penetration testers.docs.archerysec.com · 30 Sept 2026
- Scanning
- It performs web and network vulnerability scans using open-source tools and consolidates scan findings.docs.archerysec.com · 30 Sept 2026
- Authenticated scans
- It supports authenticated web scanning and web application scanning with Selenium.docs.archerysec.com · 30 Sept 2026
- Vulnerability management
- It provides vulnerability management, including prioritization by severity and false-positive tracking.archerysec.com · 30 Sept 2026
- Scanner integrations
- The product site says ArcherySec supports more than 80 commercial and open-source tool integrations.archerysec.com · 30 Sept 2026
- Connectors
- Documented connectors include OWASP ZAP, Burp, Arachni, OpenVAS, Jira, and email.docs.archerysec.com · 30 Sept 2026
- CI/CD
- Its CLI integrates with CI/CD pipelines and returns pass or fail exit codes based on configured scan policy criteria.docs.archerysec.com · 30 Sept 2026
- API
- The documentation describes REST APIs for scanning and vulnerability management.docs.archerysec.com · 30 Sept 2026
- Deployment
- The documentation provides Linux, Docker, and Vagrant with Ansible deployment options.docs.archerysec.com · 30 Sept 2026
- Windows support
- The project README provides Windows setup and run scripts.github.com · 30 Sept 2026
- License
- The documentation says ArcherySec is distributed under the GPL-3.0 license.docs.archerysec.com · 30 Sept 2026
- Security guidance
- The project README says not to expose ArcherySec publicly and recommends restricting the signup page in production.github.com · 30 Sept 2026
- Support
- The Jira connector documentation directs users with questions to [email protected] or to raise an issue.docs.archerysec.com · 30 Sept 2026
- Intended users
- The documentation describes the tool as useful for developers, penetration testers, and DevOps teams managing vulnerabilities.docs.archerysec.com · 30 Sept 2026
- Finding management
- It correlates raw scan data and presents it in a consolidated view for vulnerability management.docs.archerysec.com · 30 Sept 2026
- Automation
- It supports periodic and concurrent scans and can be used in DevOps CI/CD environments.docs.archerysec.com · 30 Sept 2026
- Integrations
- Documented connectors include OWASP ZAP, Burp, Arachni, OpenVAS, Jira, and email.docs.archerysec.com · 30 Sept 2026
- Scanner setup
- Users must run supported scanners and provide ArcherySec with their endpoints.docs.archerysec.com · 30 Sept 2026
- Deployment caution
- The project README advises restricting the signup page in production and labels the default setup for internal use only.github.com · 30 Sept 2026
- Project maintainer
- The project documentation credits Anand Tiwari and dates the project copyright from 2017 to 2025.docs.archerysec.com · 30 Sept 2026
Company
- Founded
- 2017archerysec.com · 28 Sept 2026
- Headquarters
- Indiaarcherysec.com · 28 Sept 2026
Best ArcherySec alternatives
See all 12Where it ranks on Everything Xiaomi
Is ArcherySec yours?
Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.
Sources
- docs.archerysec.com· checked 30 Sept 2026
- archerysec.com/index.html· checked 30 Sept 2026
- docs.archerysec.com/docs/connectors-basic· checked 30 Sept 2026
- docs.archerysec.com/docs/cicd_scans· checked 30 Sept 2026
- docs.archerysec.com/docs/how-to-get-started· checked 30 Sept 2026
- github.com/archerysec/archerysec· checked 30 Sept 2026
- docs.archerysec.com/docs/jira-connector· checked 30 Sept 2026





