cfn-nag
Input—per 1M tokens
Output—per 1M tokens
Context—tokens
WeightsClosed
About
cfn-nag is ranked #12 of 27 in infrastructure testing tools on Inferse. It runs on Linux, macOS, Self-hosted. There is a free plan.
Compared on infrastructure testing tools
- Free plan
- Yesgithub.com
- Terraform analysis
- Nogithub.com
- Kubernetes analysis
- Nogithub.com
- CloudFormation analysis
- Yesgithub.com
- Custom policies
- Yesgithub.com
- Secrets detection
- Yesgithub.com
Facts
- Purpose
- cfn-nag scans CloudFormation templates for patterns that may indicate insecure infrastructure.github.com · 3 Oct 2026
- Checks
- The project lists checks for overly permissive IAM and security group rules, disabled access logs or encryption, and password literals.github.com · 3 Oct 2026
- Install
- The project documents installation with RubyGems and Homebrew, and requires Ruby 2.5 or later for gem installation.github.com · 3 Oct 2026
- Template inputs
- The scanner processes JSON, .template, YAML, and YML files and recursively scans subdirectories when given a directory.github.com · 3 Oct 2026
- Output
- Results go to standard output; JSON output is available, and failures return a non-zero exit code while warnings return success.github.com · 3 Oct 2026
- Docker
- A Dockerfile is provided, and the project says its image is published as stelligent/cfn_nag on Docker Hub.github.com · 3 Oct 2026
- Integrations
- The project documents running cfn-nag in GitHub Actions workflows and deploying it in AWS CodePipeline through the AWS Serverless Application Repository.github.com · 3 Oct 2026
- Rule customization
- Users can filter checks with profiles and deny lists, suppress rules per resource, and develop custom rules distributed as gems or loaded from S3.github.com · 3 Oct 2026
- Template analysis limit
- Static analysis cannot see parameter values supplied at deployment unless users provide those values through a JSON file.github.com · 3 Oct 2026
- Conditional analysis limit
- By default, cfn-nag substitutes the true outcome for Fn::If, so rules do not inspect false outcomes unless condition values are provided.github.com · 3 Oct 2026
- Offline use
- The gem specification describes cfn-nag as a static analysis tool that must work without network connectivity, while noting S3 rule retrieval is optional.github.com · 3 Oct 2026
- License
- The project uses the MIT License, which grants permission to use, copy, modify, merge, publish, distribute, sublicense, and sell the software subject to its terms.github.com · 3 Oct 2026
- Support
- The project directs users to submit bug reports and feature requests through its GitHub issue tracker.github.com · 3 Oct 2026
Best cfn-nag alternatives
See all 12
7.2 AWS CloudFormation Free free plan, no paid price published Free plan
7.2 Chef InSpec Free free plan, no paid price published Free plan
6.8 CIS-CAT Pro Assessor $200/mo first paid tier
6.0 Conftest Free free plan, no paid price published Free plan
6.0 Sonobuoy See plans price on the maker's page
6.0 Terratest Free free plan, no paid price published Free plan Where it ranks on Inferse
Sources
- github.com/stelligent/cfn_nag· checked 3 Oct 2026
- github.com/stelligent/cfn_nag/blob/master/cfn-nag.· checked 3 Oct 2026
- github.com/stelligent/cfn_nag/blob/master/LICENSE.· checked 3 Oct 2026


