ArcherySec
About
ArcherySec is an open-source vulnerability assessment and management tool for developers, penetration testers, and DevOps teams. It scans web applications and networks through supported scanners, then consolidates findings for review and management. Teams can run authenticated web scans and Selenium-based web application scans, with periodic and concurrent scanning available. Findings can be deduplicated, prioritized by severity, and tracked for false positives and remediation. The project lists more than 80 commercial and open-source integrations; documented connectors include OWASP ZAP, Burp, Arachni, OpenVAS, Jira, and email. Its CLI can gate CI/CD pipelines with pass or fail exit codes based on configured scan policies, and REST APIs cover scanning and vulnerability management. Deployment options include Linux, Docker, Vagrant with Ansible, and Windows setup scripts. ArcherySec is self-hosted under the GPL-3.0 license and is free. Supported scanners must be run separately and their endpoints supplied. The project advises restricting signup and avoiding public exposure in production.
Who it is for
ArcherySec suits development, penetration-testing, and DevOps teams that need consolidated vulnerability findings and policy gates. It is a fit for organizations prepared to run supported scanners and manage a self-hosted deployment.
What is good
- Free and open source under GPL-3.0.
- REST APIs cover scanning and vulnerability management.
- CLI returns policy-based pass or fail codes.
- Findings support deduplication and severity prioritization.
- Documented connectors include Jira and OWASP ZAP.
What to know first
- Requires supported scanners and their endpoints.
- Self-hosted deployment requires operational management.
- Signup page should be restricted in production.
Verdict
ArcherySec brings scanner findings, vulnerability management, and CI/CD policy gates into a self-hosted tool. Teams should account for scanner setup and the project’s production exposure cautions.
Compared on application security orchestration platforms
- Finding deduplication
- Yesarcherysec.com
- Risk prioritization
- rules-basedarcherysec.com
- Remediation workflows
- Yesarcherysec.com
- Policy gates
- Yesarcherysec.com
- Ticketing sync
- Yesarcherysec.com
- Deployment model
- self-hostedarcherysec.com
Facts
- Purpose
- ArcherySec is an open-source vulnerability assessment and management tool for developers and penetration testers.docs.archerysec.com · 30 Sept 2026
- Scanning
- It performs web and network vulnerability scans using open-source tools and consolidates scan findings.docs.archerysec.com · 30 Sept 2026
- Authenticated scans
- It supports authenticated web scanning and web application scanning with Selenium.docs.archerysec.com · 30 Sept 2026
- Vulnerability management
- It provides vulnerability management, including prioritization by severity and false-positive tracking.archerysec.com · 30 Sept 2026
- Scanner integrations
- The product site says ArcherySec supports more than 80 commercial and open-source tool integrations.archerysec.com · 30 Sept 2026
- Connectors
- Documented connectors include OWASP ZAP, Burp, Arachni, OpenVAS, Jira, and email.docs.archerysec.com · 30 Sept 2026
- CI/CD
- Its CLI integrates with CI/CD pipelines and returns pass or fail exit codes based on configured scan policy criteria.docs.archerysec.com · 30 Sept 2026
- API
- The documentation describes REST APIs for scanning and vulnerability management.docs.archerysec.com · 30 Sept 2026
- Deployment
- The documentation provides Linux, Docker, and Vagrant with Ansible deployment options.docs.archerysec.com · 30 Sept 2026
- Windows support
- The project README provides Windows setup and run scripts.github.com · 30 Sept 2026
- License
- The documentation says ArcherySec is distributed under the GPL-3.0 license.docs.archerysec.com · 30 Sept 2026
- Security guidance
- The project README says not to expose ArcherySec publicly and recommends restricting the signup page in production.github.com · 30 Sept 2026
- Support
- The Jira connector documentation directs users with questions to [email protected] or to raise an issue.docs.archerysec.com · 30 Sept 2026
- Intended users
- The documentation describes the tool as useful for developers, penetration testers, and DevOps teams managing vulnerabilities.docs.archerysec.com · 30 Sept 2026
- Finding management
- It correlates raw scan data and presents it in a consolidated view for vulnerability management.docs.archerysec.com · 30 Sept 2026
- Automation
- It supports periodic and concurrent scans and can be used in DevOps CI/CD environments.docs.archerysec.com · 30 Sept 2026
- Integrations
- Documented connectors include OWASP ZAP, Burp, Arachni, OpenVAS, Jira, and email.docs.archerysec.com · 30 Sept 2026
- Scanner setup
- Users must run supported scanners and provide ArcherySec with their endpoints.docs.archerysec.com · 30 Sept 2026
- Deployment
- The project README documents Linux and Windows installation, Docker images, Docker Compose, and AWS serverless deployment using Zappa.github.com · 30 Sept 2026
- Deployment caution
- The project README advises restricting the signup page in production and labels the default setup for internal use only.github.com · 30 Sept 2026
- Project maintainer
- The project documentation credits Anand Tiwari and dates the project copyright from 2017 to 2025.docs.archerysec.com · 30 Sept 2026
Company
- Founded
- 2017archerysec.com · 28 Sept 2026
- Headquarters
- Indiaarcherysec.com · 28 Sept 2026
Best ArcherySec alternatives
See all 12
7.3 Conviso Platform $19/mo first paid tier Free plan
7.3 OWASP DefectDojo $100/mo first paid tier Free plan
7.3 ScanDog €19/mo first paid tier Free plan
7.3 Strobes ASPM $2416.67/mo first paid tier Free plan
6.9 OX Security See plans price on the maker's page
6.8 Veracode Risk Manager See plans price on the maker's page Where it ranks on Inferse
Sources
- docs.archerysec.com· checked 30 Sept 2026
- archerysec.com/index.html· checked 30 Sept 2026
- docs.archerysec.com/docs/connectors-basic· checked 30 Sept 2026
- docs.archerysec.com/docs/cicd_scans· checked 30 Sept 2026
- docs.archerysec.com/docs/how-to-get-started· checked 30 Sept 2026
- github.com/archerysec/archerysec· checked 30 Sept 2026
- docs.archerysec.com/docs/jira-connector· checked 30 Sept 2026




