ArcherySec
No phone app
in Application Security Orchestration Platforms
- Recognised40% of the score20
- Phone app26% of the score0
- Documented20% of the score97
- Free plan14% of the score100
- Free plan
- Yes
- Runs on
- api, Linux, Mac, self-hosted, Web, Windows
Summary
ArcherySec is an open-source vulnerability assessment and management tool for developers, penetration testers, and DevOps teams. It scans web applications and networks using supported scanners, then brings their findings together for review. Management tools include severity-based prioritization, false-positive tracking, finding deduplication, and remediation workflows. Authenticated web scans and web application scanning with Selenium are supported, along with periodic and concurrent scans. The project lists more than 80 commercial and open-source integrations; documented connectors include OWASP ZAP, Burp, Arachni, OpenVAS, Jira, and email. Its command-line interface can run within CI/CD pipelines and return pass or fail codes based on configured scan policies. REST APIs cover scanning and vulnerability management. Deployment documentation describes Linux, Docker, and Vagrant with Ansible, while Windows setup and run scripts are also provided. ArcherySec is licensed under GPL-3.0 and is self-hosted. Users must run supported scanners and supply their endpoints. The project advises keeping the service from public exposure and restricting signup in production. The open-source plan is free.
Who it is for
It suits development, penetration testing, and DevOps teams that want consolidated vulnerability findings and policy-based pipeline checks. It is intended for teams prepared to operate supported scanners and a self-hosted deployment.
What is good
- Consolidates findings from web and network scans.
- Prioritizes by severity and tracks false positives.
- CLI returns policy-based pass or fail codes in CI/CD.
- Documented connectors include OWASP ZAP, Burp, Jira, and email.
What to know first
- Requires users to run scanners and provide their endpoints.
- Self-hosted deployment requires operational setup.
- Project advises restricting public exposure and production signup.
Samsung Mobile US Press review
ArcherySec: the full review
ArcherySec combines scanning workflows with finding management, integrations, and CI/CD policy gates under a GPL-3.0 license. Its self-hosted model and scanner setup requirements are important considerations before adoption.
Overview
ArcherySec is a self-hosted application security tool for teams that need to bring vulnerability findings from multiple scanners into one workflow. It suits developers, penetration testers, and DevOps teams comfortable operating their own scanners and deployment; its main appeal is open-source finding management rather than an all-in-one scanner.
Its place is among Application Security Orchestration Platforms: the value comes from correlating scan results and managing follow-up, while scanner setup and production hardening remain the operator’s responsibility.
Key features
Scanning and finding management
ArcherySec supports web and network vulnerability scans, authenticated web scanning, and web application scanning with Selenium. It consolidates raw findings, supports deduplication, prioritizes risk through rules, and tracks false positives. That combination is useful when teams face overlapping results from several tools, though it does not remove the need to run those scanners and connect their endpoints.
The product describes more than 80 commercial and open-source tool integrations. Documented connectors include OWASP ZAP, Burp, Arachni, and OpenVAS, plus Jira and email. The breadth may help teams keep existing tools in their workflow, while connector documentation specifically directs questions to [email protected] or an issue report.
Automation and deployment
Periodic and concurrent scans support recurring assessment work. The CLI can run in CI/CD pipelines and return pass-or-fail exit codes against configured scan policies, making it practical to enforce team-defined gates. REST APIs cover scanning and vulnerability management for teams that need programmatic access.
Linux, Docker, and Vagrant with Ansible deployment options are documented, and the project provides Windows setup and run scripts. ArcherySec is self-hosted, so teams must plan for deployment and scanner operations. The project warns against public exposure and recommends restricting signup in production; its default setup is intended for internal use. That caution makes security configuration part of adoption, not an optional finishing touch.
Pricing
Open source: 0.00 USD per free. The plan is GPL-3.0 licensed and self-hosted, with no paid tier or seat or scan quota stated. It suits teams able to provide their own infrastructure and scanner tools. The trade-off for a zero-cost license is operational responsibility, including deployment, scanner setup, and production safeguards.
Platforms
ArcherySec supports API, Linux, macOS, web, and Windows, with self-hosted deployment. Linux, Docker, and Vagrant with Ansible are documented deployment routes; Windows setup and run scripts are provided. Teams should distinguish platform support from a hosted service: the deployment model is self-hosted.
Who it's for
Choose ArcherySec if developers, penetration testers, or DevOps staff need a consolidated view across supported scanners, finding prioritization and remediation workflows, and policy gates in CI/CD. It is a weaker fit for teams seeking a managed service, a scanner that works without external tools, or a deployment that needs no security administration.
Pros and cons
Pros
- Consolidated finding workflow: Correlation, deduplication, false-positive tracking, and remediation workflows help turn multiple scan outputs into manageable work.
- Pipeline policy gates: CLI pass-or-fail results let teams apply configured scan criteria in CI/CD.
- Open-source self-hosting: The GPL-3.0 plan costs 0.00 USD per free and allows teams to operate the tool on their own infrastructure.
- Broad integration scope: More than 80 integrations are described, with named connectors spanning scanners, Jira, and email.
Cons
- External scanner dependency: Teams must run supported scanners and supply their endpoints, adding setup and ongoing operational work.
- Production hardening is essential: The project advises against public exposure and recommends restricting signup, so a default internal-use setup should not be treated as production-ready.
- Self-hosting requires ownership: Teams must manage deployment rather than rely on a hosted ArcherySec service.
Alternatives
ScanDog is worth considering for teams seeking a freemium API and web option with a defined Free tier: 3 products, 10 workflows, 2 users, and 30 AI fixes per month. Its Team plan is 19.00 EUR per month, billed annually, for up to 10 products, 200 workflows, and up to 30 users. Pick ArcherySec instead when self-hosting and GPL-3.0 licensing matter more than those stated workflow and user caps.
Conviso Platform offers a freemium API and web option. Its Free plan includes up to 5 contributing developers, 5 assets, 10 users, and 2 integrations; choose it when those explicit limits fit better than operating ArcherySec and its external scanners.
OWASP DefectDojo has a freemium API, Linux, self-hosted, and web offering. Its Community Edition is free forever, open source, and supported through OWASP Slack and GitHub; pick it if that stated support route is preferable to ArcherySec’s self-managed scanner setup. A Pay As You Go plan is also offered at 100.00 US.
Strobes ASPM offers a freemium API, self-hosted, and web option. Its Free plan is billed forever and caps use at 100 assets, 500 tasks per month, and 1 connector, while including ASM, RBVM, ASPM, and community support. Consider it when those limits and included capabilities suit the team better than ArcherySec’s scanner-centered setup.
PointGuard AI is a paid web alternative.
ClearAnts ASOC is a paid alternative.
OX Security is a paid option with API, extension, Linux, macOS, self-hosted, web, and Windows platforms. Its OX Code plan covers SAST, SCA, secrets and PII, SBOM, IaC, CI/CD, container scanning, IDE, and CLI; choose it when that stated code-security scope is the priority.
Seemplicity Application Security is a paid alternative.
Verdict
ArcherySec is a strong fit for technically capable teams that want a GPL-3.0, self-hosted hub for scanner findings, remediation workflows, and CI/CD policy gates. Its decisive advantage is bringing multiple tool results into a manageable process without a license charge. Look elsewhere if you need hosted operation or want to avoid running and securing scanners and the platform yourself.
ArcherySec plans and pricing
All plansCompared on application security orchestration platforms
- Finding deduplication
- Yesarcherysec.com
- Risk prioritization
- rules-basedarcherysec.com
- Remediation workflows
- Yesarcherysec.com
- Policy gates
- Yesarcherysec.com
- Ticketing sync
- Yesarcherysec.com
- Deployment model
- self-hostedarcherysec.com
Facts
- Purpose
- ArcherySec is an open-source vulnerability assessment and management tool for developers and penetration testers.docs.archerysec.com · 30 Sept 2026
- Scanning
- It performs web and network vulnerability scans using open-source tools and consolidates scan findings.docs.archerysec.com · 30 Sept 2026
- Authenticated scans
- It supports authenticated web scanning and web application scanning with Selenium.docs.archerysec.com · 30 Sept 2026
- Vulnerability management
- It provides vulnerability management, including prioritization by severity and false-positive tracking.archerysec.com · 30 Sept 2026
- Scanner integrations
- The product site says ArcherySec supports more than 80 commercial and open-source tool integrations.archerysec.com · 30 Sept 2026
- Connectors
- Documented connectors include OWASP ZAP, Burp, Arachni, OpenVAS, Jira, and email.docs.archerysec.com · 30 Sept 2026
- CI/CD
- Its CLI integrates with CI/CD pipelines and returns pass or fail exit codes based on configured scan policy criteria.docs.archerysec.com · 30 Sept 2026
- API
- The documentation describes REST APIs for scanning and vulnerability management.docs.archerysec.com · 30 Sept 2026
- Deployment
- The documentation provides Linux, Docker, and Vagrant with Ansible deployment options.docs.archerysec.com · 30 Sept 2026
- Windows support
- The project README provides Windows setup and run scripts.github.com · 30 Sept 2026
- License
- The documentation says ArcherySec is distributed under the GPL-3.0 license.docs.archerysec.com · 30 Sept 2026
- Security guidance
- The project README says not to expose ArcherySec publicly and recommends restricting the signup page in production.github.com · 30 Sept 2026
- Support
- The Jira connector documentation directs users with questions to [email protected] or to raise an issue.docs.archerysec.com · 30 Sept 2026
- Intended users
- The documentation describes the tool as useful for developers, penetration testers, and DevOps teams managing vulnerabilities.docs.archerysec.com · 30 Sept 2026
- Finding management
- It correlates raw scan data and presents it in a consolidated view for vulnerability management.docs.archerysec.com · 30 Sept 2026
- Automation
- It supports periodic and concurrent scans and can be used in DevOps CI/CD environments.docs.archerysec.com · 30 Sept 2026
- Integrations
- Documented connectors include OWASP ZAP, Burp, Arachni, OpenVAS, Jira, and email.docs.archerysec.com · 30 Sept 2026
- Scanner setup
- Users must run supported scanners and provide ArcherySec with their endpoints.docs.archerysec.com · 30 Sept 2026
- Deployment caution
- The project README advises restricting the signup page in production and labels the default setup for internal use only.github.com · 30 Sept 2026
- Project maintainer
- The project documentation credits Anand Tiwari and dates the project copyright from 2017 to 2025.docs.archerysec.com · 30 Sept 2026
Company
- Founded
- 2017archerysec.com · 28 Sept 2026
- Headquarters
- Indiaarcherysec.com · 28 Sept 2026
Best ArcherySec alternatives
See all 12Where it ranks on Samsung Mobile US Press
Is ArcherySec yours?
Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.
Sources
- docs.archerysec.com· checked 30 Sept 2026
- archerysec.com/index.html· checked 30 Sept 2026
- docs.archerysec.com/docs/connectors-basic· checked 30 Sept 2026
- docs.archerysec.com/docs/cicd_scans· checked 30 Sept 2026
- docs.archerysec.com/docs/how-to-get-started· checked 30 Sept 2026
- github.com/archerysec/archerysec· checked 30 Sept 2026
- docs.archerysec.com/docs/jira-connector· checked 30 Sept 2026





