Best Self-hosted Security & Privacy tools in 2026

117 self-hosted open source alternatives in this category

117 services found

PocketBase

PocketBase

Lightweight open-source realtime backend with embedded SQLite

56.4k
3.1k
Last commit: 4d ago

Open-source Go backend providing embedded SQLite, realtime (SSE) subscriptions, auth (JWT/OAuth2), file storage, admin UI and REST-style APIs for web and mobile apps.

Alternative to:
PocketBase Cloud
PocketBase Cloud
+17
Pi-hole

Pi-hole

Network-wide DNS sinkhole for ad and tracker blocking

55.9k
3k
Last commit: 8d ago

Pi-hole is a network-wide DNS sinkhole that blocks ads and trackers for all devices on your network, with a web dashboard, query logs, and optional DHCP server.

Alternative to:
AdGuard
AdGuard
+7
Vaultwarden

Vaultwarden

Bitwarden-compatible password manager server written in Rust

55.7k
2.6k
Last commit: 2d ago

Vaultwarden is a lightweight, Bitwarden-compatible password manager server in Rust, designed for self-hosting with official Bitwarden clients.

Alternative to:
Bitwarden
Bitwarden
+9
Headscale

Headscale

Self-hosted control server for Tailscale-based WireGuard networks

35.8k
1.9k
Last commit: 5d ago

Headscale is an open source, self-hosted implementation of the Tailscale control server for managing a private tailnet, nodes, keys, IPs, and routes.

Alternative to:
Tailscale
Tailscale
+9
Keycloak

Keycloak

Open-source identity and access management with SSO

33k
8.1k
Last commit: 14h ago

Keycloak is an open-source IAM server providing single sign-on, user federation, and centralized authentication and authorization using OIDC, OAuth 2.0, and SAML.

Alternative to:
Okta
Okta
+19
AdGuard Home

AdGuard Home

Network-wide DNS server that blocks ads, trackers, phishing and malware

32.8k
2.3k
Last commit: 7h ago

Open-source DNS-based ad & tracker blocking server for networks. Offers per-device rules, parental controls, encrypted upstream DNS (DoH/DoT/DNSCrypt), web UI and API.

Alternative to:
AdGuard
AdGuard
+5
Web-Check

Web-Check

All-in-one OSINT tool for analyzing any website.

32.1k
2.5k
Last commit: 25d ago

Comprehensive on-demand OSINT to analyze a website's security, architecture, and tech stack.

Alternative to:
Shodan
Shodan
+8
Authelia

Authelia

Self-hosted IAM with SSO and multi-factor authentication

26.9k
1.3k
Last commit: 14h ago

Authelia is an open-source IAM and authentication server providing SSO, MFA, and access control for web apps, with OpenID Connect/OAuth 2.0 and reverse-proxy integration.

Alternative to:
Auth0
Auth0
+16
KeePassXC

KeePassXC

Cross-platform offline password manager using encrypted KDBX databases

26k
1.7k
Last commit: 1mo ago

KeePassXC is a secure, cross-platform password manager that stores credentials and sensitive notes in encrypted KeePass-compatible KDBX files with autofill and browser in...

Alternative to:
KeePassXC
KeePassXC
+10
Infisical

Infisical

Open-source platform for secrets, PKI certificates, and privileged access

25.1k
1.7k
Last commit: 9h ago

Infisical is an open-source platform to manage and deliver app secrets, certificates (PKI), SSH credentials, and encryption keys across teams and infrastructure.

Alternative to:
HashiCorp Vault
HashiCorp Vault
+9
Ente

Ente

End-to-end encrypted cloud for photos and 2FA

24.8k
1.5k
Last commit: 10h ago

Open-source, end-to-end encrypted platform for private photo backup, sharing, and authenticator (2FA) sync across devices, with optional self-hosting.

Alternative to:
Google Photos
Google Photos
+14
wg-easy

wg-easy

WireGuard VPN server with a web-based admin interface

24.7k
2.4k
Last commit: 2d ago

Run a WireGuard VPN server with an easy web admin UI to manage clients, generate configs and QR codes, and monitor connections and traffic.

Alternative to:
Tailscale
Tailscale
+14
NetBird

NetBird

WireGuard-based overlay network with SSO/MFA and granular access controls.

23.1k
1.1k
Last commit: 1d ago

Open-source zero-trust networking platform delivering a WireGuard-based private network with centralized access control, SSO/MFA, and cross-platform clients.

Alternative to:
Tailscale
Tailscale
+17
SafeLine

SafeLine

Self-hosted WAF and reverse proxy for securing web apps

20.8k
1.3k
Last commit: 3mo ago

SafeLine is a self-hosted Web Application Firewall (WAF) and reverse proxy that defends web apps from SQL injection, XSS, bot abuse, and DDoS using ML-powered threat dete...

Alternative to:
Cloudflare Web Application Firewall (WAF)
Cloudflare Web Application Firewall (WAF)
+7
authentik

authentik

Open-source Identity Provider (IdP) for SSO, OIDC, and SAML

20.3k
1.5k
Last commit: 9h ago

Open-source IdP delivering SSO, OAuth2/OIDC, SAML2, LDAP, RADIUS, MFA, WebAuthn, conditional access and application-proxy capabilities for self-hosted deployments.

Alternative to:
Okta
Okta
+19
Teleport

Teleport

Identity-aware access proxy for infrastructure and internal apps

19.9k
2k
Last commit: 9h ago

Secure access platform for servers, Kubernetes, databases, desktops, and web apps with SSO/MFA, short-lived certificates, and full session auditing.

Alternative to:
Twingate
Twingate
+16
Pangolin

Pangolin

Identity-aware VPN and reverse proxy for secure remote access

19.2k
578
Last commit: 18h ago

Open-source identity-based remote access platform combining WireGuard VPN and tunneled reverse proxy access with granular zero-trust controls.

Alternative to:
Cloudflare Access
Cloudflare Access
+16
Bitwarden

Bitwarden

Open-source password manager with zero-knowledge security and self-hosting.

18.1k
1.5k
Last commit: 8h ago

Bitwarden is an open-source password manager that stores, shares, and autofills credentials with zero-knowledge encryption; supports cloud or self-hosted deployments.

Alternative to:
1Password
1Password
+9
Anubis

Anubis

Web AI firewall utility that challenges and blocks scraper bots

17.2k
506
Last commit: 6d ago

Anubis is a lightweight web AI firewall that protects sites from AI crawlers and scraping bots using configurable request challenges and bot policies.

Alternative to:
Cloudflare Web Application Firewall (WAF)
Cloudflare Web Application Firewall (WAF)
+10
Fail2Ban

Fail2Ban

Log-monitoring daemon that bans abusive IPs via firewall rules

17k
1.5k
Last commit: 13d ago

Fail2Ban monitors service logs for repeated failures and automatically bans abusive IP addresses by updating firewall rules for a configurable time.

Alternative to:
CrowdSec
CrowdSec
OAuth2 Proxy

OAuth2 Proxy

Reverse proxy and middleware for OAuth2/OIDC authentication

13.9k
2k
Last commit: 6d ago

OAuth2 Proxy is a reverse proxy and middleware that protects web apps with OAuth2/OIDC login and forwards authenticated user identity to upstream services.

Alternative to:
Cloudflare Access
Cloudflare Access
+14
Bytebase

Bytebase

Database DevSecOps platform for schema change and access governance

13.8k
915
Last commit: 15h ago

Open-source database DevSecOps tool for managing schema migrations, SQL review, audit logging, access control, and data masking across multiple databases.

Alternative to:
Datical (Liquibase Enterprise)
Datical (Liquibase Enterprise)
+5
OpenVPN

OpenVPN

Open-source VPN daemon for TLS-based secure tunneling

13.3k
3.3k
Last commit: 1d ago

OpenVPN is a widely used open-source VPN daemon providing TLS/SSL-based secure tunneling, flexible client-server and site-to-site modes, and cross-platform support.

Alternative to:
OpenVPN CloudConnexa
OpenVPN CloudConnexa
+18
Cloudflared

Cloudflared

Cloudflare Tunnel client to expose local services via Cloudflare's edge network.

13.2k
1.2k
Last commit: 1d ago

CLI tool to create Cloudflare Tunnels and route traffic through Cloudflare’s edge.

Alternative to:
ngrok
ngrok
+10
ZITADEL

ZITADEL

API-first identity and access management platform for applications

13.1k
947
Last commit: 10h ago

ZITADEL is an open source IAM/CIAM platform providing SSO, MFA, OIDC/OAuth2, SAML, user management, and multi-tenant organizations with audit logging.

Alternative to:
Auth0
Auth0
+19
Casdoor

Casdoor

UI-first IAM and SSO platform for modern authentication

13.1k
1.6k
Last commit: 1d ago

Casdoor is an open-source, UI-first IAM/SSO platform supporting OAuth 2.0, OIDC, SAML, LDAP, SCIM, WebAuthn and MFA, with an admin web UI and SDKs.

Alternative to:
Okta
Okta
+19
CrowdSec

CrowdSec

Crowdsourced IDS/IPS and WAF with shared malicious IP intelligence

12.6k
576
Last commit: 1d ago

CrowdSec is an open-source security engine that detects attacks from logs and blocks malicious IPs using bouncers and community-curated threat intelligence.

Alternative to:
Fail2Ban
Fail2Ban
+10
Logto

Logto

Authentication and authorization platform for apps and APIs

11.6k
713
Last commit: 19h ago

Open-source authentication and authorization infrastructure with OIDC/OAuth 2.1, SAML SSO, multi-tenancy, MFA, and RBAC for SaaS and AI apps.

Alternative to:
Auth0
Auth0
+19
Nginx UI

Nginx UI

Web UI for managing Nginx configurations, certificates, and logs

10.7k
777
Last commit: 7d ago

Self-hosted web interface to manage Nginx configs, reload safely, issue Let’s Encrypt certificates, view logs, monitor server stats, and manage multiple nodes.

Alternative to:
NGINX Management Suite
NGINX Management Suite
+4
Amnezia

Amnezia

Cross-platform client to deploy and use your own VPN server

10.2k
720
Last commit: 1d ago

Open-source VPN client for desktop and mobile that can automatically set up a private VPN server and connect using WireGuard, OpenVPN, IKEv2, and obfuscated modes.

Alternative to:
NordVPN
NordVPN
+15