ArcherySec

  • Free to practise onyes
  • Free trialnot on record
  • Well documentedyes
  • Runs where you workyes

Runs on api, Linux, Mac, self-hosted, Web, Windows.

ArcherySec is a self-hosted, open-source tool for assessing and managing vulnerabilities. It scans web applications and networks using supported scanners, then brings scan results into a consolidated view for review. Teams can run authenticated web scans and web application scans with Selenium, and manage findings through severity-based prioritization, false-positive tracking, deduplication, and remediation workflows. Its project lists more than 80 commercial and open-source tool integrations; documented connectors include OWASP ZAP, Burp, Arachni, OpenVAS, Jira, and email. A command-line interface can run in CI/CD pipelines and return pass or fail exit codes against configured scan policies. REST APIs cover scanning and vulnerability management. Deployment documentation includes Linux, Docker, and Vagrant with Ansible, while Windows setup and run scripts are also available. ArcherySec is distributed under the GPL-3.0 license. Users must run supported scanners and supply their endpoints. The project advises against public exposure and recommends restricting signup in production.

Who it is for

ArcherySec suits developers, penetration testers, and DevOps teams that need to consolidate vulnerability findings and manage them in a self-hosted environment. It can also fit teams integrating scan policy checks into CI/CD pipelines.

What is good

  • Consolidates findings from web and network scans.
  • Tracks severity, false positives, and remediation.
  • CLI policy gates return pass or fail results.
  • REST APIs cover scanning and vulnerability management.

What to know first

  • Users must run supported scanners and provide endpoints.
  • The project advises against public exposure.
  • Production deployments should restrict the signup page.

Verdict

ArcherySec combines scan aggregation with vulnerability management and CI/CD policy checks. Its self-hosted setup requires scanner configuration, and the project cautions against public exposure.

ArcherySec plans and pricing

All plans
Open source Free GPL-3.0 licensed · self-hosted deployment docs.archerysec.com · 30 Sept 2026

Compared on application security orchestration platforms

Finding deduplication
Yes
Risk prioritization
rules-based
Remediation workflows
Yes
Policy gates
Yes
Ticketing sync
Yes
Deployment model
self-hosted

Best ArcherySec alternatives

See all 12