HTML Python Shell CSS JavaScript XSLT Nginx
Latest commit fa21f32 Aug 17, 2017 @devGregA devGregA committed on GitHub Merge pull request #343 from no-sec-marko/wrap_pre_tag
wrap pre-tags in the finding view
Failed to load latest commit information.
ansible Add models, views and forms for system settings located in db Jun 30, 2017
components Fixes #289 Jul 18, 2017
doc/img Delete May 23, 2017
docker Credential support to the finding level and endpoint support for csv Mar 27, 2017
docs Merge pull request #319 from patriknordlen/nmap Jul 12, 2017
dojo Merge pull request #343 from no-sec-marko/wrap_pre_tag Aug 17, 2017
sample_deployments/nginx Sample Nginx and supervisord installation Jan 10, 2017
scripts Set initial data for system settings model Jul 1, 2017
tests Updated endpoint meta data url. Nov 17, 2016
.gitignore Travis files Sep 19, 2016
.travis.yml Merge pull request #326 from devGregA/master Jul 17, 2017 Update May 18, 2017 Create Mar 23, 2017
Dockerfile Fix for Travis Oct 26, 2016 Update Mar 21, 2017 Updated Readme to reflect Ubuntu 16.04.2 as dependency issues may exi… Jun 29, 2017
Vagrantfile Renaming and rebranding to DefectDojo. This commit updates every refe… Mar 24, 2015
app.json Slack and speed improvements Oct 26, 2016 Added Credential Manager Mar 8, 2017 Update to make compatible with Django 1.7 Mar 24, 2015 Partially fixes #331 Aug 1, 2017
run_dojo.bash Fixes #140 and #141 Jul 17, 2017
setup.bash removed -y to prevent automatically uninstalling conflicting libraries Aug 17, 2017 Update Jun 19, 2017 Fixes #312 and #139 Jul 9, 2017
wsgi_params Fixes #312 and #139 Jul 9, 2017


Screenshot of DefectDojo

DefectDojo is a security program and vulnerability management tool. DefectDojo allows you to manage your application security program, maintain product and application information, schedule scans, triage vulnerabilities and push findings into defect trackers. Consolidate your findings into one source of truth with DefectDojo.

Build Status


If you'd like to check out a demo of DefectDojo before installing it, you can check out our PythonAnywhere demo site.

You can log in as an administrator like so:


You can also log in as a product owner / non-staff user:

Product owner

Additional Documentation

For additional documentation you can visit our Read the Docs site.

One-Click Installations

Deploy to Docker Cloud. (Login first to Docker Cloud before clicking the install button.)

Deploy to Docker Cloud

Installation Options

Debian, Ubuntu (16.04.2+) or RHEL-based Install Script

Docker - There are currently a number of bugs in the Docker image that we're working to address. Please use the regular install script to avoid issues.

Vagrant (deprecated)

Getting Started

We recommend checking out the about document to learn the terminology of DefectDojo, and the getting started guide for setting up a new installation. We've also created some example workflows that should give you an idea of how to use DefectDojo for your own team.

DefectDojo Client API's

  • DefectDojo Python API: pip install defectdojo_api or clone the repository.

Getting Involved

Get Access. Realtime discussion is done in the OWASP Slack Channel, #defectdojo.

DefectDojo Twitter Account tweets project updates and changes.

Available Plugins

Engagement Surveys - A plugin that adds answerable surveys to engagements.

LDAP Integration

SAML Integration

About Us

DefectDojo is maintained by:


We greatly appreciate all of our contributors.

We would also like to highlight the contributions from Michael Dong and Fatimah Zohra who contributed to DefectDojo before it was open source.

Swag Rewards

If you fix an issue with the 'swag reward' tag we'll send you a shirt and some stickers!

Cash Rewards

We also are offer monetary rewards for issues tagged as such
Sorry Maintainers you are not elgible for cash rewards ;)


Proceeds are used for testing, infrastructure, etc.




Interested in becoming a sponsor and having your logo displayed? Please email


DefectDojo is licensed under the BSD Simplified license