nowfound

Dev tools · alternatives · 2026

24 alternatives to Virus Total

Analyze suspicious files and URLs to detect types of viruses

Below are 24 products that do a similar job, ranked by how close each is in meaning and then by launch-day votes. Virus Total launched in 2021; newer entries below may have overtaken it.

  1. 1

    Analyze suspicious files and URLs.

    2017 · its alternatives →

  2. 2

    Search for Malicious Files and Urls easily from your browser

    2025 · chromewebstore.google.com · its alternatives →

  3. 3

    Report suspicious sites to Google

    2019 · its alternatives →

  4. 4
    CyberWise▲101

    Detect phishing, adware and malware on websites

    2023 · its alternatives →

  5. 5
    Virusdie▲100

    Clean and protect your websites like a security expert

    2016 · its alternatives →

  6. 6ST
  7. 7

    All your malware analysis tools in one place

    2021 · its alternatives →

  8. 8BB

    This is a simple single-file python program that can find basic XSS (cross-site scripting) vulnerabilities in a target url. Most XSS discovery tools use a payload refelection strategy in which payloads are injected in url parameters and the GET response is inspected for places where the payload content is reflected. This is a very low precision XSS detection strategy because most reflection does not support execution. This program uses a different approach, and instead opens the target url in a browser, tests alert(...) payloads directly in the browser context, and listens for an alert being…

    2024 · github.com · its alternatives →

  9. 9

    Broken link checker with malware and parked domain detection

    2018 · its alternatives →

  10. 10MS

    I noticed the growing security concerns around MCP (https://news.ycombinator.com/item?id=43600192) and built an open source tool that can detect several patterns of tool poisoning attacks, exfiltration channels and cross-origin manipulations. MCP-Shield scans your installed servers (Cursor, Claude Desktop, etc.) and shows what each tool is trying to do at the instruction level, beyond just the API surface. It catches hidden instructions that try to read sensitive files, shadow other tools' behavior, or exfiltrate data. Example of what it detects: - Hidden instructions…

    2025 · github.com · its alternatives →

  11. 11

    Giving you the power to defeat advanced malware threats

    2022 · its alternatives →

  12. 12

    A tool to check if a URL is on Reddit and going viral

    2016 · its alternatives →

  13. 13
    Plague▲118

    Spread content like a virus

    2014 · its alternatives →

  14. 14

    Hey HN, I built an automated system that tracks malicious Chrome/Edge extensions daily. The database updates automatically by monitoring chrome-stats for removed extensions and scanning security blogs. Currently tracking 1000+ known malicious extensions with extension IDs, names, and dates. I'm working on detection tools (GUI + CLI) to scan locally installed extensions against this database, but wanted to share the raw data first since maintained threat intelligence lists like this are hard to find. The automation runs 24/7 and pushes updates to GitHub. Free to use for research,…

    Feb 2026 · github.com · its alternatives →

  15. 15

    hey guys, wanted to show one of my side projects i just made public. the idea is basically another osint tool for pentesters and bug bounty hunters. it watches certificate transparency logs and checks newly-seen domains for exposed stuff like .env files, open .git dirs, config files, db dumps and so on, and puts whatever it finds into a searchable db. you just search a domain (or part of one) and see what's exposed. it's read-only and free. one thing i've been thinking about adding is a way to register for certain keywords and get notified when something new shows up for that search. would…

    Jul 2026 · search.cerast-intelligence.com · its alternatives →

  16. 16RT
  17. 17IB

    I built a GitHub app that detects it in pull requests, notifies or blocks them. Alongside it, I published a Semgrep ruleset for any stage of the CI/CD. I started this after getting frustrated by all the FUD around malicious code - lots of noise, little effort to solve it. Having said that, it's still a major attack vector - a stored RCE, with the codebase itself as the sink. Feedback is appreciated. The app, PRevent - https://github.com/apiiro/PRevent The ruleset: https://github.com/apiiro/malicious-code-ruleset The research:…

    2025 · github.com · its alternatives →

  18. 18

    Malicious Link AI‑powered URL scanning API

    2025 · linkshieldapi.com · its alternatives →

  19. 19KD

    I built this after seeing multiple teams accidentally ship API keys in their frontend code. The problem: Modern web development moves fast. You're vibe-coding, shipping features, and suddenly your AWS keys are sitting in a tag visible to anyone who opens DevTools. I've personally witnessed this happen to at least 3-4 production apps in the past year alone. KeyLeak Detector runs through your site (headless browser + network interception) and checks for 50+ types of leaked secrets: AWS/Google keys, Stripe tokens, database connection strings, LLM API keys (OpenAI, Claude, etc.), JWT…

    Nov 2025 · github.com · its alternatives →

  20. 20

    Free malware analysis service for the community

    2022 · its alternatives →

  21. 21
    ANY.RUN▲11

    Interactive online malware sandbox

    2025 · any.run · its alternatives →

  22. 22
    GitHub▲13

    Prevent merging of malicious code in pull requests and CI/CD

    2025 · github.com · its alternatives →

  23. 23VV

    Hi all, here is a side project I've just launched which might come in handy for certain situations. It's a very simple and free "do one thing and do it well" online service with exactly one feature: you upload a file, and it tells you — based on a ClamAV check — if that file contains a virus or not. I'm not having any ambitious plans with this project, but thanks to very low operational costs, I thought I can as well put it out there and keep it alive — maybe it's even useful for some people every now and then (just today, one of my coworkers forwarded me a fishy-looking email with an…

    2022 · app.virusaas.com · its alternatives →

  24. 24

Also compare

Ranked by how close each launch is in meaning, then by votes. Prices were read from each product’s own site when checked and can change. Refine with your own description →