DefectDojo is an OWASP flagship open-source platform for vulnerability management, DevSecOps automation, and ASPM, with a Pro tier from $300/month.
Category
Security
Pricing
Free/Open Source with paid Pro tier, from Free
Verified
Not yet
Last updated
July 18, 2026
Founded
2013
Free PlanWeb AppAPIOpen SourceFreemiumSelf-Hosted
Overview
DefectDojo is an open-source vulnerability management and ASPM platform that aggregates, deduplicates, and tracks findings from 200+ security testing tools, maintained as an OWASP Flagship Project since its 2013-2015 origins.
Written in Python/Django and licensed under BSD 3-Clause, DefectDojo reports adoption by more than 10,000 organizations and over 45 million downloads of its Community Edition.
Key Features
The platform normalizes scanner output into products, engagements, tests, and findings, applies deduplication logic across tools and scan runs, and tracks remediation SLAs and compliance reporting.
A commercial Pro tier, available as cloud-hosted SaaS or on-premises from around $300/month, adds the AI-assisted DefectDojo Sensei module, Model Context Protocol support, a tunable deduplication rules engine, and enterprise scanner connectors.
Pricing
The Community Edition is completely free and self-hosted, making DefectDojo accessible to teams of any size without per-seat licensing costs.
Organizations that need AI-assisted triage, enterprise scanner integrations, or managed hosting can upgrade to DefectDojo Pro, which is also offered with a two-week trial.
Key Features
Findings Aggregation — Ingest results from 200+ security tools into a single data model.
Deduplication Engine — Merge duplicate findings across different scanners and scan runs.