Best Self-hosted Security & Privacy tools in 2026

117 self-hosted open source alternatives in this category

117 services found

BunkerWeb

BunkerWeb

Open-source web application firewall and reverse proxy

10.1k
565
Last commit: 22d ago

BunkerWeb is an open-source WAF and NGINX-based reverse proxy to protect web apps and APIs with HTTPS automation, security policies, and extensible plugins.

Alternative to:
Cloudflare Web Application Firewall (WAF)
Cloudflare Web Application Firewall (WAF)
+10
MyIP (IPCheck.ing)

MyIP (IPCheck.ing)

Open-source IP toolbox for IP, DNS, WebRTC and network diagnostics

9.9k
1.1k
Last commit: 19d ago

MyIP (IPCheck.ing) is an open-source web IP toolbox that detects local/public IPs, runs DNS leak and WebRTC checks, speed/latency/MTR tests, availability and whois lookup...

Alternative to:
WhatIsMyIPAddress.com
WhatIsMyIPAddress.com
+10
Firezone

Firezone

Zero-trust remote access platform built on WireGuard

8.4k
403
Last commit: 10h ago

Firezone is a zero-trust VPN replacement built on WireGuard, providing identity-aware access policies, peer-to-peer encrypted tunnels, and lightweight gateways.

Alternative to:
Tailscale
Tailscale
+11
step-ca

step-ca

Private certificate authority and ACME server for X.509 and SSH

8.3k
532
Last commit: 4d ago

step-ca is a private CA and ACME server for issuing and automating X.509 TLS and SSH certificates, enabling short-lived credentials and secure enrollment for teams.

Alternative to:
HashiCorp Vault
HashiCorp Vault
+7
Graylog

Graylog

Centralized log management and analysis platform

8k
1.1k
Last commit: 1d ago

Graylog is an open source platform for collecting, indexing, searching, and alerting on logs and machine data from many sources in one place.

Alternative to:
Graylog Cloud
Graylog Cloud
+11
iodine

iodine

IPv4-over-DNS tunneling server and client

7.7k
576
Last commit: 5mo ago

iodine is a DNS tunneling tool that forwards IPv4 traffic through DNS queries and replies, providing a TUN interface to route IP traffic when only DNS is allowed.

Alternative to:
Cloudflare Tunnel
Cloudflare Tunnel
+15
Tinyauth

Tinyauth

Lightweight authentication middleware for protecting web apps

7k
222
Last commit: 20h ago

Tinyauth is a lightweight auth middleware that adds a login screen, OAuth, or LDAP authentication in front of your apps via common reverse proxies.

Alternative to:
Cloudflare Access
Cloudflare Access
+17
WatchYourLAN

WatchYourLAN

Lightweight LAN IP scanner with web UI, alerts, and metrics export

6.8k
234
Last commit: 5mo ago

Self-hosted lightweight LAN IP/ARP scanner with web dashboard, new-host notifications, online/offline history, and metrics export to Prometheus or InfluxDB for Grafana.

Alternative to:
Fing
Fing
+9
Pocket ID

Pocket ID

A passkey-only OpenID Connect identity provider

6.8k
202
Last commit: 18h ago

Pocket ID is a simple self-hosted OpenID Connect (OIDC) provider that lets users sign in to apps using passkeys instead of passwords.

Alternative to:
Auth0
Auth0
+19
Warpgate

Warpgate

Transparent bastion and PAM for SSH, HTTPS, MySQL and PostgreSQL

6.6k
239
Last commit: 2d ago

Self-hosted transparent bastion host and PAM for SSH, HTTPS, MySQL and Postgres with RBAC, session recording, and SSO/2FA—no client-side software required.

Alternative to:
Teleport
Teleport
+7
OneUptime

OneUptime

Open-source monitoring, incident management, and observability platform

6.5k
326
Last commit: 19h ago

Self-hostable observability platform for uptime monitoring, alerting, incident management, on-call, status pages, logs, and APM in one integrated suite.

Alternative to:
OneUptime
OneUptime
+19
ClamAV

ClamAV

Open-source antivirus engine for gateway and file scanning

6.3k
834
Last commit: 8d ago

ClamAV is an open-source antivirus toolkit providing a multi-threaded daemon, command-line scanners, and automatic signature updates for mail gateways and file scanning.

Alternative to:
McAfee
McAfee
+8
MeshCentral

MeshCentral

Open-source web-based remote device management and remote desktop server

6.2k
813
Last commit: 11h ago

Self-hosted Node.js server for remote monitoring, web-based remote desktop, terminal, file access and multi-DB device management.

Alternative to:
TeamViewer
TeamViewer
+14
LLDAP

LLDAP

Lightweight LDAP authentication server with a web UI

6k
314
Last commit: 1d ago

LLDAP is a lightweight LDAP server for authentication and user management, providing a simplified LDAP interface, a web admin UI, and SQLite/MySQL/PostgreSQL backends.

Alternative to:
Microsoft Active Directory
Microsoft Active Directory
+2
NetAlertX

NetAlertX

Network device scanner and presence detection with alerts

5.8k
372
Last commit: 1h ago

Self-hosted network visibility and presence scanner that discovers connected devices and alerts on new, unknown, or changed hosts across your LAN/Wi‑Fi.

Alternative to:
Fing
Fing
+8
Cosmos Cloud

Cosmos Cloud

Security-first self-hosting platform with reverse proxy, SSO, and apps

5.7k
208
Last commit: 1d ago

Cosmos Cloud is a security-focused self-hosting platform that provides an app store, reverse proxy with automatic HTTPS, SSO/MFA, container management, backups, and monit...

Alternative to:
Cloudron
Cloudron
+18
Passbolt

Passbolt

Open-source password and secret manager for teams

5.7k
372
Last commit: 1mo ago

Passbolt is an open-source, security-first password and secret manager for teams, with end-to-end encryption, granular sharing permissions, and auditing.

Alternative to:
Passbolt Cloud
Passbolt Cloud
+11
OpenBao

OpenBao

Open source secrets management for keys, certificates, and tokens

5.5k
340
Last commit: 20h ago

OpenBao is an open source secrets management platform to securely store, generate, lease, and revoke secrets, certificates, and encryption keys with auditing and access c...

Alternative to:
HashiCorp Vault
HashiCorp Vault
+3
Cap

Cap

Privacy-first proof-of-work CAPTCHA alternative for web and APIs

5k
298
Last commit: 10h ago

Lightweight, self-hostable CAPTCHA alternative using SHA-256 proof-of-work challenges to protect forms and APIs from bots without tracking or visual puzzles.

Alternative to:
Google reCAPTCHA
Google reCAPTCHA
+8
Pomerium

Pomerium

Identity- and context-aware access proxy for zero trust access

4.7k
321
Last commit: 1d ago

Pomerium is an identity-aware access proxy that provides zero trust, per-request authorization to internal web apps and services without a traditional VPN.

Alternative to:
Cloudflare Access
Cloudflare Access
+12
Kanidm

Kanidm

Simple, secure identity management and SSO provider

4.6k
299
Last commit: 1d ago

Kanidm is a secure identity management platform providing SSO, passkeys (WebAuthn), and integrations like OAuth2/OIDC, RADIUS, and LDAP gateway for legacy apps.

Alternative to:
Okta
Okta
+19
OPNsense

OPNsense

Open source firewall and routing platform for network security

4.3k
915
Last commit: 17h ago

OPNsense is an open source FreeBSD-based firewall and routing platform with a web GUI, API, VPN, traffic shaping, and security features for networks and homelabs.

Alternative to:
Fortinet FortiGate
Fortinet FortiGate
+12
Cerbos

Cerbos

Context-aware authorization and access control policy engine

4.2k
170
Last commit: 2d ago

Cerbos is a scalable, language-agnostic authorization layer for defining and evaluating context-aware access control policies via a dedicated Policy Decision Point (PDP)...

Alternative to:
OSO Cloud
OSO Cloud
+17
OpenZiti

OpenZiti

Open-source zero trust networking overlay for applications

3.9k
236
Last commit: 1d ago

OpenZiti is an open-source zero trust networking platform that builds an identity-based overlay mesh with SDKs, tunnelers, and policy-based access controls.

Alternative to:
Zscaler Private Access
Zscaler Private Access
+14
2FAuth

2FAuth

Web-based TOTP/HOTP authenticator and 2FA account manager

3.8k
274
Last commit: 1mo ago

Open-source web app to manage TOTP/HOTP 2FA accounts: scan QR codes, generate one-time codes, import/export tokens, and protect access with WebAuthn and optional encrypti...

Alternative to:
Google Authenticator
Google Authenticator
+3
WGDashboard

WGDashboard

Web dashboard to manage and monitor WireGuard VPN

3.4k
402
Last commit: 17d ago

Self-hosted web dashboard for WireGuard and AmneziaWG to manage configs, peers, and access with a simple UI and optional 2FA.

Alternative to:
Tailscale
Tailscale
+15
Password Pusher

Password Pusher

Securely share passwords and sensitive data with auto-expiring links.

2.9k
427
Last commit: 5d ago

Open-source app that creates self-deleting secret links with audit logs.

Alternative to:
Onetime Secret
Onetime Secret
+1
GLAuth

GLAuth

Lightweight LDAP authentication server with pluggable backends

2.8k
238
Last commit: 6mo ago

GLAuth is a lightweight LDAP/LDAPS authentication server for development, CI, and homelabs, supporting file, S3, SQL, or LDAP proxy backends and optional 2FA.

Alternative to:
Microsoft Active Directory
Microsoft Active Directory
+5
Canarytokens

Canarytokens

Honeytokens that alert when accessed or executed

2.8k
396
Last commit: 18d ago

Canarytokens generates honeytokens (URLs, files, credentials, docs) that alert you when an attacker touches them, helping detect breaches early.

Alternative to:
Thinkst Canary
Thinkst Canary
+2
Wizarr

Wizarr

User invitation and management system for media servers

2.7k
166
Last commit: 4h ago

Wizarr automates user invitations and onboarding for Plex, Jellyfin, Emby and similar media servers, with SSO, time-limited access, Discord and request-system integration...