nowfound

Alternatives

Products that do what Payload Security Suite does

An OOM-safe, lightweight WP Firewall & Malware Scanner

  1. 1

    TypeScript headless CMS + app framework

    2023

  2. 2

    🛡️ Open-source and cloud-native Web Application Firewall (WAF) - bunkerity/bunkerweb

    2024 · github.com

  3. 3

    Free vulnerability scanner to secure your PHP code

    2023

  4. 4
    SecuPress100

    Protect your WordPress website and your data every day

    2016

  5. 5

    Open source API security platform

    2022

  6. 6OO

    Hello everyone. This is Yujong from the Hyprnote team (https://github.com/fastrepl/hyprnote). We built OWhisper for 2 reasons: (Also outlined in https://docs.hyprnote.com/owhisper/what-is-this) (1). While working with on-device, realtime speech-to-text, we found there isn't tooling that exists to download / run the model in a practical way. (2). Also, we got frequent requests to provide a way to plug in custom STT endpoints to the Hyprnote desktop app, just like doing it with OpenAI-compatible LLM endpoints. The (2) part is still kind of WIP, but…

    2025 · docs.hyprnote.com

  7. 7

    The best TypeScript CMS developer experience there is

    2022

  8. 8BT
  9. 9BO

    Hi HN, we’re the co-founders of Bearer, and today we launch an open-source alternative to code security solutions such as Snyk Code, SonarQube, or Checkmarx. Essentially, we help security & engineering teams to discover, filter and prioritize security risks and vulnerabilities in their codebase, with a unique approach through sensitive data (PII, PD, PHI). Our website is at https://www.bearer.com and our GitHub is here: https://github.com/bearer/bearer We are not originally Security experts but have been software developers and engineering leaders for over 15…

    2023

  10. 10

    Developer-first TypeScript & React headless CMS

    2021

  11. 11SS

    Excited to share the project I've been working on for the past 7 months! We've seen nearly weekly attacks against the open source software supply chain. I saw the seeds of this trend start in the mid 2015s as an open source maintainer and I've watched it only get worse over the years. I finally decided to try to solve this problem. Socket is taking an entirely new approach to one of the hardest problems in security in a stagnant part of the industry that has historically been obsessed with just reporting on known vulnerabilities. Unlike other scanning tools, Socket actually analyzes the…

    2022 · socket.dev

  12. 12BB

    This is a simple single-file python program that can find basic XSS (cross-site scripting) vulnerabilities in a target url. Most XSS discovery tools use a payload refelection strategy in which payloads are injected in url parameters and the GET response is inspected for places where the payload content is reflected. This is a very low precision XSS detection strategy because most reflection does not support execution. This program uses a different approach, and instead opens the target url in a browser, tests alert(...) payloads directly in the browser context, and listens for an alert being…

    2024 · github.com

  13. 13

    Patch your WordPress stack

    2021

  14. 14

    Browser-native security workflows

    Jul 2026 · payloadify.com

  15. 15VS
  16. 16
    WPAUDIT86

    Full-stack WordPress pentest tool for ethical hackers

    2025

  17. 17SZ

    We're launching SecureBuild: https://securebuild.com — a new way for open source projects and maintainers to earn revenue by partnering with and endorsing our Zero-CVE container images of their project. We’ve spent the last decade at Replicated (https://news.ycombinator.com/item?id=9841243) helping commercial and open source software vendors securely distribute their apps to enterprise environments. During that time, we saw firsthand how hard it is for maintainers to fund their work, and how increasingly demanding enterprises have become when it comes to demonstrable…

    2025 · securebuild.com

  18. 18

    All-in-one WordPress security: WAF, scanner, 2FA & more

    Jul 2026 · wordsec.net

  19. 19OS

    tl;dr we released openapi.security, an online tool that performs a dozen of security tests on any given openapi/swagger-based API, with no signup or email required. You can try it here: https://openapi.security My team at Escape (YC W23) is mainly focused on securing GraphQL APIs. For this, we developed a new approach called Feedback driven API Exploration. Basically, we infer the right security tests cases to run using the specification and a carefully crafted in house graph traversal algorithm. (It's a bit long to describe here but we published a more in depth explanation of…

    2023 · openapi.security

  20. 20

    Save hours. Boost margin. Scale faster.

    Feb 2026 · zymplio.com

  21. 21

    Built from breach reports. Tuned for WordPress.

    Jun 2026 · securewp.net

  22. 22CF

    A few months ago, a friend asked me to check his WordPress site for vulnerabilities. What I found shocked me – critical flaws exposing sensitive data everywhere. That's why I built CR4SH3R: a focused tool to detect Arbitrary File Download flaws before attackers do Key Features: Lightning-fast multi-threaded scanning, Extracts credentials from exposed files (like wp-config.php), Generates actionable Excel reports, Simple GUI for one-click security checks Would love your feedback!

    2025 · github.com

  23. 23MY

    Metlo - An Open Source API Security Tool Hey folks! Excited to share what we’ve been working on for the last couple months. Metlo is a self hosted, open source first API security platform that inventories, tests and protects your API endpoints: - We inventory your endpoints by scanning API traffic and detecting all your endpoints along with the sensitive data they contain. - We generate information your security team may find useful like Open API Specs and risk scores for each endpoint. - After this we discover vulnerabilities like unauthenticated endpoints returning sensitive data or…

    2022 · github.com

  24. 24

    An open-source, cloud-native WAF you fully control

    Jan 2026 · bunkerweb.io

Ranked by how close each launch is in meaning, then by votes. Refine with a description →