ArcherySec is an open-source vulnerability assessment and management tool for developers, penetration testers and DevOps teams. It scans web applications and networks through supported tools, then consolidates findings for review. Users can run authenticated web scans and web application scans with Selenium. Management capabilities include severity-based prioritization, false-positive tracking, finding deduplication and remediation workflows. The project lists more than 80 commercial and open-source tool integrations; documented connectors include OWASP ZAP, Burp, Arachni, OpenVAS, Jira and email. Its command-line interface can run in CI/CD pipelines and return pass or fail exit codes according to configured scan policies. REST APIs cover scanning and vulnerability management. Documentation describes Linux, Docker and Vagrant with Ansible deployment options, while the project also provides Windows setup and run scripts. ArcherySec is self-hosted and distributed under the GPL-3.0 license. Users need to run supported scanners and provide their endpoints. The project advises against public exposure and recommends restricting signup in production.
Who it is for
ArcherySec is intended for developers, penetration testers and DevOps teams managing vulnerabilities. It may suit teams that can self-host the tool and run supported scanners.
What is good
- Consolidates findings from web and network scans
- Supports severity prioritization and false-positive tracking
- CLI supports CI/CD policy pass-or-fail results
- REST APIs cover scans and vulnerability management
- GPL-3.0 licensed and self-hosted
What to know first
- Users must run supported scanners and provide endpoints
- Project advises against public exposure
- Production guidance recommends restricting the signup page
Freedom251 review
ArcherySec: the full review
ArcherySec combines scanner findings with vulnerability management and CI/CD policy gates in a self-hosted, open-source package. Deployment requires supported scanners, and the project specifically cautions users to restrict public access and signup.
Overview
ArcherySec is a self-hosted vulnerability assessment tool for developers and penetration testers who need to bring results from separate scanners into one management workflow. Its strongest fit is a team already running supported scanners and looking to organize findings and apply CI/CD policy checks without a software subscription.
The project dates to 2017, credits Anand Tiwari as maintainer, and is distributed under the GPL-3.0 license. ArcherySec depends on external scanners rather than replacing them, so teams must run supported tools and provide their endpoints.
It sits within Application Security Orchestration Platforms, a category centered on coordinating security-tool results.
Key features
Scanning and vulnerability management
ArcherySec supports web and network vulnerability scans, including authenticated web scanning and web application scanning with Selenium. It correlates scan data into a consolidated view, deduplicates findings, prioritizes risk using rules, and tracks false positives. Remediation workflows give teams a way to manage findings after discovery rather than treating each scan as a standalone report.
Integrations and automation
The project describes more than 80 commercial and open-source tool integrations. Documented connectors include OWASP ZAP, Burp, Arachni, and OpenVAS, plus Jira and email. This breadth can help teams collect results from an existing toolset, though the need to operate scanners separately adds setup and maintenance work.
The CLI integrates with CI/CD pipelines and returns pass or fail exit codes against configured scan-policy criteria. Periodic and concurrent scans support recurring assessment, while REST APIs cover scanning and vulnerability management. These capabilities suit teams seeking to automate checks and connect findings to existing processes.
Deployment and security
Deployment options include Linux, Docker, and Vagrant with Ansible; the project also provides Windows setup and run scripts. The self-hosted model offers control over deployment but puts setup and operational responsibility on the adopting team. ArcherySec's own guidance says the default setup is for internal use only: production users should restrict the signup page and must not expose the application publicly.
Pricing
Open source: 0.00 USD per free. The GPL-3.0-licensed package is self-hosted, with no paid plan or seat and scan quotas stated. It suits teams able to supply and maintain scanners and deployment infrastructure. The tradeoff is that users take on that operational work; questions can be directed to [email protected] or raised as an issue.
Platforms
ArcherySec supports API, Linux, macOS, self-hosted, web, and Windows. Deployment documentation covers Linux, Docker, and Vagrant with Ansible, and the project README includes Windows setup and run scripts.
Who it's for
Developers, penetration testers, and DevOps teams are the natural audience, particularly those already using supported scanners and needing consolidated findings, remediation workflows, and policy gates in CI/CD. It is a weaker fit for organizations seeking a managed service or a scanner that works without separate tools to run and configure.
Pros and cons
- Pros: Combines scan findings, deduplication, severity-based prioritization, false-positive tracking, and remediation workflows in a single vulnerability-management process.
- Pros: CI/CD policy gates, REST APIs, and documented Jira and email connectors support automation and handoff.
- Pros: GPL-3.0 licensing and self-hosting provide a no-subscription option for teams prepared to operate the software.
- Cons: Teams must run supported scanners and configure their endpoints; ArcherySec is not a replacement for those tools.
- Cons: Self-hosting requires deployment and ongoing operational effort, and the project warns against public exposure and unrestricted signup.
Alternatives
- OWASP DefectDojo is worth comparing for a free, open-source community edition with support through OWASP Slack and GitHub; its Community Edition is 0.00 USD per free, billed Free forever, and it also offers a Pay As You Go plan at 100.00 US.
- Conviso Platform may suit teams seeking a freemium option with stated contributor, asset, user, and integration limits on its free plan; its Developers plan is 19.00 USD per month, billed $2,040 charged per year.
- ScanDog is another freemium option, with a free tier capped at 3 products, 10 workflows, 2 users, and 30 AI fixes/month, or a Team plan at 19.00 EUR per month billed annually.
- Strobes ASPM offers a free plan with up to 100 assets, 500 tasks/month, one connector, and community support, making it an option to compare for teams weighing those stated caps.
- Safeguard DAST is a freemium, web-based alternative.
- OX Security is a paid alternative with an OX Code plan spanning SAST, SCA, secrets/PII, SBOM, IaC, CI/CD, container scanning, IDE, and CLI.
- PointGuard AI is a paid, web-based alternative.
- Mend.io is a paid alternative with a Mend Renovate Enterprise plan at 250.00 USD per year for enterprise dependency management.
Verdict
Choose ArcherySec if your team can self-host, already operates supported scanners, and wants a free GPL-3.0 tool to consolidate findings and enforce scan policies in CI/CD. Look elsewhere if you need a managed deployment or want vulnerability scanning without configuring and maintaining separate scanner tools.
ArcherySec plans and pricing
All plansCompared on application security orchestration platforms
- Finding deduplication
- Yes
- Risk prioritization
- rules-based
- Remediation workflows
- Yes
- Policy gates
- Yes
- Ticketing sync
- Yes
- Deployment model
- self-hosted





