cfn-nag

Input—per 1M tokens
Output—per 1M tokens
Context—tokens
WeightsClosed

About

cfn-nag is ranked #12 of 27 in infrastructure testing tools on Inferse. It runs on Linux, macOS, Self-hosted. There is a free plan.

Compared on infrastructure testing tools

Free plan
Yesgithub.com
Terraform analysis
Nogithub.com
Kubernetes analysis
Nogithub.com
CloudFormation analysis
Yesgithub.com
Custom policies
Yesgithub.com
Secrets detection
Yesgithub.com

Facts

Purpose
cfn-nag scans CloudFormation templates for patterns that may indicate insecure infrastructure.github.com · 3 Oct 2026
Checks
The project lists checks for overly permissive IAM and security group rules, disabled access logs or encryption, and password literals.github.com · 3 Oct 2026
Install
The project documents installation with RubyGems and Homebrew, and requires Ruby 2.5 or later for gem installation.github.com · 3 Oct 2026
Template inputs
The scanner processes JSON, .template, YAML, and YML files and recursively scans subdirectories when given a directory.github.com · 3 Oct 2026
Output
Results go to standard output; JSON output is available, and failures return a non-zero exit code while warnings return success.github.com · 3 Oct 2026
Docker
A Dockerfile is provided, and the project says its image is published as stelligent/cfn_nag on Docker Hub.github.com · 3 Oct 2026
Integrations
The project documents running cfn-nag in GitHub Actions workflows and deploying it in AWS CodePipeline through the AWS Serverless Application Repository.github.com · 3 Oct 2026
Rule customization
Users can filter checks with profiles and deny lists, suppress rules per resource, and develop custom rules distributed as gems or loaded from S3.github.com · 3 Oct 2026
Template analysis limit
Static analysis cannot see parameter values supplied at deployment unless users provide those values through a JSON file.github.com · 3 Oct 2026
Conditional analysis limit
By default, cfn-nag substitutes the true outcome for Fn::If, so rules do not inspect false outcomes unless condition values are provided.github.com · 3 Oct 2026
Offline use
The gem specification describes cfn-nag as a static analysis tool that must work without network connectivity, while noting S3 rule retrieval is optional.github.com · 3 Oct 2026
License
The project uses the MIT License, which grants permission to use, copy, modify, merge, publish, distribute, sublicense, and sell the software subject to its terms.github.com · 3 Oct 2026
Support
The project directs users to submit bug reports and feature requests through its GitHub issue tracker.github.com · 3 Oct 2026

Best cfn-nag alternatives

See all 12