OpenHack

OpenHack

Open-source AI security agent that finds, verifies, and fixes vulnerabilities in your code and live apps.

75/100Safe BetFree planFreemium

OpenHack earns its place because it verifies instead of guessing — its Papermark CVE-2026-36755 writeup and 37-package npm typosquat campaign show the engine finds things in real software, not synthetic benchmarks. The free tier gives you one project, five PR reviews a month, one full scan, and local CLI access, so you can evaluate it on your own repo before paying anything. Named alternatives like Snyk and Semgrep occupy the traditional SAST slot, while proprietary AI pentest agents bill per seat or per engagement and outprice small teams. OpenHack's Enterprise tier is custom-priced, so budget-conscious buyers should compare against Snyk's published per-developer rates before committing.

Verified 5d ago · liveness 75/100 · cite: rightaichoice.com/tools/openhack

Best for
  • Solo developers who want exploit-verified security scanning at no cost via the local CLI
  • Small teams that need AI codebase scanning plus pentest coverage without per-seat pricing
  • Security engineers triaging logic flaws, IDORs, auth bypasses, and race conditions
  • Startups preparing for enterprise customer security reviews and audit reports
Not ideal for
  • Teams that need deep infrastructure, cloud configuration, or network scanning
  • Mobile app security testing (iOS/Android binaries and app store surfaces)
  • Projects that cannot install Python or CLI dependencies
Visit Website

IntermediateCLI users get first value in minutes: pipx install, connect a model provider, and run a scan on a local repository. GitHub-connected teams typically see PR reviews on the next pull request after install. Enterprise deployment — SSO, data residency, on-premise, or BYOK — depends on procurement and infrastructure provisioning, so plan on a guided onboarding rather than a same-day cutover.Web · CLINo public APIVerified 5d ago
Pricing
Free plan
FreemiumFree tier2 plans4 hidden costs
Learning curve
Intermediate
CLI users get first value in minutes: pipx install, connect a model provider, and run a scan on a local repository. GitHub-connected teams typically see PR reviews on the next pull request after install. Enterprise deployment — SSO, data residency, on-premise, or BYOK — depends on procurement and infrastructure provisioning, so plan on a guided onboarding rather than a same-day cutover.
Runs on
WebCLI
No public API · 5 integrations
Who it's for
Solo developer or open-source maintainerSmall engineering teamSecurity engineer at an enterprise
Live sentiment
Is OpenHack actually worth it?

We scan live Reddit threads, YouTube comments, X posts, G2 reviews and other communities — and hand you an honest verdict in under a minute.

  • Honest verdict, not marketing
  • Real pros & cons from real users
  • Attributed quotes with receipts
Run a free scan

3 free scans · no card needed

Skip it if

Skip OpenHack if you need infrastructure, cloud-config, or mobile-binary scanning, or if you want a fully self-serve paid tier without a custom-quoted Enterprise contract.

The 30-second take
Biggest gripe

The free tier caps you at 5 PR security reviews per month and a single one-time full scan, so a second repository or a re-scan pushes you toward a paid plan.

Price reality

Free at $0 covers one project with 5 PR reviews a month and a one-time full scan, which suits a solo developer or an open-source maintainer. Enterprise is custom-quoted with pooled AI credits — that fits mid-size and large teams with compliance requirements, and lands below per-seat AI pentest engagements but above self-hosted OSS SAST tools you run yourself.

In short

OpenHack — Open-source AI security agent that finds, verifies, and fixes vulnerabilities in your code and live apps. Best for Solo developers who want exploit-verified security scanning at no cost via the local CLI, Small teams that need AI codebase scanning plus pentest coverage without per-seat pricing, Security engineers triaging logic flaws, IDORs, auth bypasses, and race conditions. Free to use.

What's new in OpenHack

Checked 5 days ago

Across the latest 2 updates: 2 news mentions.

What people actually say about OpenHack — is it worth it?

We scanned public community sources for OpenHack on Sep 23, 2026 and could not establish that the discussion we found is about this tool rather than something else sharing its name. Only 1 of the posts we fetched could be positively tied to OpenHack. Rather than publish a sentiment score built on the wrong subject, we publish nothing here and re-run the scan.

Viability Score

75/100
Safe Bet

How well maintained and how widely used is OpenHack? Built from what the vendor actually publishes (docs, changelog, tutorials, integrations, pricing), whether the site is live, and how much real users discuss it. How we calculate this

Recent activity
90
Traction
100
Site health
95
User sentiment
49
What the vendor publishes
40

Last calculated: October 2026

How we score →

Key Features

  • Autonomous AI pentests against live web applications
  • AI codebase scanning with proof-of-concept verified findings
  • Vulnerability validation in a sandbox or browser before reporting
  • Chains findings to demonstrate full attack paths
  • Business-impact prioritization (internet-facing, payment, production)
  • AI Autofix pull requests ready for review
  • Continuous scanning across repositories
  • PR security reviews on pull requests
  • Secret scanning across code and Git history
  • Malicious dependency detection and supply chain analysis
  • SBOM export and compliance reports
  • SAST and supply chain reports
  • CLI install via pipx, runs locally
  • Bring any AI model from any provider, including self-hosted open models
  • Slack and Linear workflows for assigning fixes

About OpenHack

FreemiumIntermediateNo APIWeb · CLI

OpenHack is an AI security engineer that scans your codebase and pentests live applications, then proves each finding is real by building a working proof of concept and reproducing it in a sandbox or browser before it reports anything. It targets developers, small security teams, and open-source maintainers who are tired of scanner output they have to manually disprove. Beyond standard flaws it reasons across findings to chain them into attack paths, so you see how a missing await in an upload handler turns into cross-account data access rather than a pile of unrelated rows. The CLI installs via pipx and runs locally, and you can connect any model from any provider, including self-hosted open models. Coverage spans JavaScript, TypeScript, Python, Go, Java, and Ruby, plus frameworks like Next.js, Django, Flask, Rails, Express, and FastAPI. A managed platform adds continuous scanning across repositories, business-impact prioritization that ranks by whether an asset is internet-facing, payment-related, or production, AI Autofix pull requests, secret scanning across code and Git history, malicious dependency detection, supply chain analysis, SBOM export, and Slack and Linear workflows. Pricing runs from a free pay-as-you-go tier to a custom-quoted Enterprise plan.

Behind the Verdict

What separates OpenHack from the SAST cohort is the verification step. Traditional scanners produce a ranked list you then spend engineering hours disproving; OpenHack builds a working proof of concept and reproduces the issue in a sandbox or browser before it writes a finding, and the homepage claims near-zero false positives from that auto-verification. The vulnerability classes it advertises are the ones static analysis typically handles badly: business logic flaws, race conditions, timing attacks, IDORs, authentication bypasses. Its published research is the honest signal here — an unauthenticated-upload bug in Papermark and a correlated 37-package npm typosquatting campaign are concrete outputs, not marketing. The model story is unusually flexible. The CLI lets you connect any provider and self-hosted open models, which means you can keep inference inside your own environment, and the managed platform offers custom data residency. That combination matters for regulated buyers who cannot send source code to a US-hosted inference endpoint. The flat pricing is the other draw: the free tier covers one project with five PR reviews a month and a one-time full scan, and Enterprise is quoted custom with pooled AI credits across the organization. Where it does not fit: this is application-layer security. Infrastructure, cloud configuration, network scanning, and mobile app binaries are outside scope, and a team wanting one platform to replace an entire scanner suite on day one will still need other tools. If you cannot install Python or CLI dependencies, the local path is closed. Enterprise buyers also need to run a sales cycle — that tier is described as custom with SSO/SAML, audit logs, advanced RBAC, on-premise, and BYOK. Try the free tier on a real repository first; the CLI makes that a same-afternoon experiment.

Researching OpenHack? Get your full AI stack in 60 seconds.

Free, no signup — tell us your goal and get tools matched to your budget & existing stack.

Real-world workflow fit

Concrete scenarios for the personas OpenHack actually fits — and what changes day-one when you adopt it.

Solo developer or open-source maintainer

Install the CLI via pipx, point it at a repository, and let it scan and verify findings locally while you work.

Outcome: Verified findings with proof of concept, no code leaving the environment beyond inference requests, and no bill on the free tier.

Small engineering team

Connect GitHub, let OpenHack run PR security reviews, and route fixes through Linear issues so an engineer picks up a ready pull request.

Outcome: Findings arrive with a fix attached instead of a ticket to investigate, and logic flaws get caught before merge.

Security engineer at an enterprise

Run AI pentests against a live staging environment, then use business-impact prioritization to rank the results before the release window.

Outcome: A ranked remediation list where revenue-path and internet-facing assets surface first, with SBOM and audit reports available for compliance.

Use Cases

Models Under the Hood

DeepSeek V3.1 TerminusDeepSeek V3.2DeepSeek V4 FlashDeepSeek V4 Flash 0731Gemini 3 FlashGemma 3 12BGemma 3 27BGemma 4 26B A4BGemma 4 31BGLM 5.1GLM 5.2GLM 5.3

as of 2026-10-02

Limitations

  • OpenHack is an AI security agent focused on codebase scanning, AI pentesting, vulnerability management, secret scanning, and supply chain analysis — not infrastructure, cloud configuration, network, or mobile binary testing.
  • The free pay-as-you-go tier is tightly bounded: 1 project, 5 free PR reviews per month, a single one-time full scan, and basic SCA.
  • Many capabilities carry an asterisk on the pricing page (AI Vulnerability Management, Business-Impact Prioritization, False Positive Filtering, AI Autofix, Vulnerability-Fix Pull Requests, AI Assistant) and are listed under Enterprise, so confirm which of these your tier actually includes.
  • Enterprise is custom-quoted, requires a demo, and its AI credits are pooled across the organization with custom rates — expect a procurement cycle and negotiated allowances.

as of 2026-10-03

Verification history

We have re-verified OpenHack 8 times since . Each pass re-reads the vendor's own pages and re-checks every listed field against that evidence; passes where nothing had changed are marked as such.

  1. — re-verified summary, description, our verdict, our analysis, pricing model, pricing tiers, features, integrations, who it suits, who should skip it
  2. — re-verified summary, description, our verdict, our analysis, pricing model, pricing tiers, features, integrations, who it suits, who should skip it
  3. — re-verified summary, description, our verdict, our analysis, pricing model, pricing tiers, features, integrations, who it suits, who should skip it
  4. — re-verified summary, description, our verdict, our analysis, pricing model, pricing tiers, features, integrations, who it suits, who should skip it
  5. — re-verified summary, description, our verdict, our analysis, pricing model, pricing tiers, features, integrations, who it suits, who should skip it
  6. — re-checked, vendor evidence unchanged

Showing the 6 most recent of 8 verification passes.

Free to cite with attribution — this page re-verifies continuously.

12-month cost

Project the real annual outlay, including the implied monthly cost when only an annual tier is published.

Annual total
Free
Over 12 months
Effective monthly
Free
Billed monthly

Vendor list price only. Add-on usage, seat overages, and contract minimums are surfaced under Hidden costs & gotchas.

Plans compared

For each published OpenHack tier: who it actually fits, and what it adds vs. the previous tier. Cross-reference the cost calculator above for projected annual outlay.

Free (Pay as you go)

$0/mo

Ideal for

Solo developer or open-source maintainer evaluating OpenHack on one repository, or trialling the CLI before committing budget.

What this tier adds

Free entry point at $0 with 1 project, 5 PR reviews a month, 1 one-time full scan, basic SCA, and CLI access.

Enterprise

Custom

Ideal for

Mid-size to large engineering organizations needing compliance reporting, on-premise or BYOK deployment, and dedicated support.

What this tier adds

Custom-quoted tier adding unlimited repositories and projects, SSO/SAML, audit logs, advanced RBAC, data residency, on-premise deployment, SBOM export, and priority support.

Hidden costs & gotchas

What the public pricing page doesn't put in bold. Captured from pricing-page footnotes, contract terms, and recurring complaints.

  • The free tier caps you at 5 PR security reviews per month and a single one-time full scan, so a second repository or a re-scan pushes you toward a paid plan.
  • Enterprise AI credits are pooled across your organization with custom rates and custom allowances, so heavy scanning months are negotiated, not listed.
  • Several headline capabilities — AI Vulnerability Management, Business-Impact Prioritization, False Positive Filtering, AI Autofix, and the AI Assistant — carry an asterisk tied to the Enterprise plan, so budget for a
  • Enterprise 'unlimited' projects and read-only users are tied to whatever PR review rates you negotiate, which is where the real cost sits.

Where the pricing makes sense

The company stage and team size where OpenHack's pricing actually pencils out — and where peers do it cheaper.

Free at $0 covers one project with 5 PR reviews a month and a one-time full scan, which suits a solo developer or an open-source maintainer. Enterprise is custom-quoted with pooled AI credits — that fits mid-size and large teams with compliance requirements, and lands below per-seat AI pentest engagements but above self-hosted OSS SAST tools you run yourself.

Setup time & first value

How long it actually takes to get something useful out of OpenHack — broken out by persona, not the marketing-page minute.

CLI users get first value in minutes: pipx install, connect a model provider, and run a scan on a local repository. GitHub-connected teams typically see PR reviews on the next pull request after install. Enterprise deployment — SSO, data residency, on-premise, or BYOK — depends on procurement and infrastructure provisioning, so plan on a guided onboarding rather than a same-day cutover.

Switching to or from OpenHack

How to bring data in from common predecessors and how to get it back out — written for the switcher, not the buyer.

Migrating in
  • →From a traditional SAST tool: run the OpenHack CLI on the same repositories to compare findings, then add PR reviews via GitHub.
  • →From manual pentest engagements: point AI pentesting at a staging environment to cover the gap between annual tests.
  • →From a dependency scanner: enable supply chain analysis and malicious dependency detection alongside existing SCA.
  • →From spreadsheet triage: move findings into Slack and Linear so remediation has an owner and a pull request.
Migrating out
  • ↗To Semgrep or Snyk: export findings and SBOM reports, then re-establish rules or policies in the target scanner.
  • ↗To a manual pentest firm: use OpenHack's verified proof-of-concept evidence as the starting brief for the engagement.
  • ↗To an in-house SAST pipeline: keep the CLI's verified findings as a regression baseline while you build internal rules.

Integrations

GitHubGitLabSlackLinearVanta

Resources & Guides

Tutorials & Learning

YouTube returned 6 videos for “OpenHack”, and we withheld 6: 6 could not be judged, because “OpenHack” is a single word that other videos use for other things. We are showing none, because we could not prove any of them are about OpenHack.

Official links

Tools that pair well with OpenHack

Common stack mates teams adopt alongside OpenHack, with the specific reason each pairing earns its keep.

Featured Head-to-Head Comparisons

Alternatives to OpenHack

View all
Prbl

Prbl

AI code security scanner that finds vulnerabilities in AI-generated code and fixes them with verified diffs.

FreemiumTry
Snyk DeepCode AI

Snyk DeepCode AI

Snyk DeepCode AI finds, autofixes and prioritizes vulnerabilities in human-written and AI-generated code.

FreemiumTry
Endor Labs

Endor Labs

AI-native application security that governs coding agents and verifies reachable vulnerabilities before agents ship them.

FreemiumTry

Frequently Asked Questions

Used OpenHack? Help shape our editorial sentiment research.