vuls.io
Mature OSS scanner, agentless or agent-based, OS-package focused.
Price: Free, OSS (GPL-3.0)
StackPatch is live — CVE patch ops for indie SaaS, $99 lifetime founder seat (50 only).See product
vuls.io · Trivy · Grype · Snyk · StackPatch
Five tools, one decision. This is the page we'd want to read before paying us anything. We list our competitors first, link to their docs, and tell you when each one is the right call. Long-form side-by-sides for each are linked below.
One line per scanner. Skip to the matching scenario below if you already know your constraint.
Mature OSS scanner, agentless or agent-based, OS-package focused.
Price: Free, OSS (GPL-3.0)
Aqua's OSS scanner — strongest at containers, IaC, and Kubernetes.
Price: Free, OSS (Apache-2.0)
Anchore's OSS scanner, file/SBOM-first.
Price: Free, OSS (Apache-2.0)
Enterprise dev-time + container + IaC security, per-developer pricing.
Price: Free tier (limited); Team $25/dev/mo; Enterprise custom
Hosted CVE patch ops for live Linux VPSes — install in 5 sec, alerts by default.
Price: $99 lifetime founder seat (3 servers); monthly tiers $19+
Find the row that matches your constraint. The right call usually pops out from one sentence about your situation.
Best for: Engineering team that wants a self-hosted scanner and time to wire alerting + cron themselves.
Not for: Solo founder who wants the answer in 5 minutes and a public audit URL by default.
Read the long comparisonBest for: Teams that ship container images and want to fail CI on vulnerable layers.
Not for: A solo founder whose problem is keeping a live VPS patched.
Read the long comparisonBest for: Pipelines that already produce SBOMs (via Syft) and want CVE scanning bolted on.
Not for: Anyone who hasn't already standardized on SBOM-driven workflows.
Read the long comparisonBest for: Series A+ teams with a real security org, dev-time scanning needs, and budget.
Not for: A 1-person SaaS shop running 1–10 Linux servers.
Read the long comparisonReads only your distro / kernel / package list. Source rendered as plain text so you can read before piping. No account, no card, no email gate.
We use essential cookies to run the site. With your consent we also load analytics + ads cookies. See our Cookie Policy and Privacy Policy.