Self-hosted service
DefectDojo/django-DefectDojo avatar
DefectDojo/django-DefectDojo

DefectDojo: a Django vulnerability management hub for scanner output

Open-Source Unified Vulnerability Management, DevSecOps & ASPM

4,974 stars1,953 forksPythonBSD-3-Clause

At a glance

What is it?
DefectDojo collects findings from many security scanners into one Django application, deduplicates them and tracks remediation. Here is how it installs, how the data model works, and where the open source edition stops.
Who is it for?
Adopt DefectDojo if you already run several scanners and need one place to deduplicate their output and track fixes; skip it if you have a single scanner whose own dashboard is enough, or if you need the risk-based prioritisation and connectors that only the Pro edition lists. Before committing, import one real scan report into the demo at demo.defectdojo.org, then read the parser documentation for that tool at docs.defectdojo.com to confirm your report format is supported.
Can I use it commercially?
Yes. BSD-3-Clause is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
Is it still maintained?
Yes. The repository received new commits within the last day.
What is it written in?
Mainly Python, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on September 30, 2026, and from our analysis. They are not legal advice.

Editorial analysis

What DefectDojo is for

The README describes DefectDojo as a DevSecOps, ASPM and vulnerability management tool that orchestrates end-to-end security testing, vulnerability tracking, deduplication, remediation and reporting. The problem it addresses is fragmentation: a team running a static analyser, a dependency scanner and a dynamic scanner ends up with three dashboards, three severity vocabularies and no shared record of what was fixed. DefectDojo sits in the middle as the system of record.

The audience is application security engineers and the developers they hand findings to. The repository is a Django project with a REST API, and the documentation lists parsers for many scanner formats, so the intended workflow is import, triage, assign, close. It is not a scanner itself. Nothing in the README claims DefectDojo finds vulnerabilities; it consumes reports produced elsewhere.

The data model behind deduplication

The search interest in the DefectDojo data model is justified, because deduplication only makes sense once you know how records relate. The project is built on Django, and the dependency list shows django-polymorphic, django-tagulous and django-auditlog, which point to a model where findings have types and tags, and where changes are recorded. Scanner output is imported as findings attached to a product and an engagement, which is the unit that groups a test run.

Deduplication is the mechanism that keeps the same issue from being counted repeatedly when it reappears in a later scan. The README states that deduplication is part of what DefectDojo orchestrates, but it does not spell out the matching algorithm on the front page; that detail lives in the official documentation at docs.defectdojo.com. Treat the deduplication settings as something to verify against your own scanner output rather than something to assume.

The stack around the model matters for operations. The requirements file pins Django 5.2.16, djangorestframework, celery with the SQS extra, psycopg[c] for PostgreSQL and redis, and the compose file adds a valkey service. That is a conventional Django deployment: a web tier behind uWSGI and nginx, a worker tier for asynchronous imports, PostgreSQL for storage and Redis or valkey for the queue. Large scans are therefore processed in the background, not during the HTTP request.

Installing DefectDojo with Docker Compose

The README gives one quick start for the open source edition and it is Docker Compose. The command clones the repository, changes into it and starts the stack. The first initialization can take up to three minutes, and the README says the admin credentials appear in the initializer logs.

bash
git clone https://github.com/DefectDojo/django-DefectDojo && cd django-DefectDojo && docker compose up

If you run in detached mode, the README gives a second command to pull the generated admin password out of the initializer container's logs. Run it after the initializer finishes; before that, the log line will not be there yet.

bash
docker compose logs initializer | grep "Admin password:"

The compose file publishes the nginx service on port 8080 by default and a TLS port on 8443, both overridable through the DD_PORT and DD_TLS_PORT variables. The compose file's own header states that it is fully functional for evaluating DefectDojo locally but is not intended for production use without customising it first. That is an unusually direct warning and worth taking literally: the default configuration is an evaluation setup.

For a first real use, the README suggests uploading sample scan reports from the unittests/scans directory in the repository, or testing against the public demo at demo.defectdojo.org, which is reset daily and should not receive sensitive data. Uploading one of those sample reports is the fastest way to see how a scanner format maps onto findings before you point DefectDojo at your own pipeline.

Where the open source edition stops

The README is explicit that there are two editions. The community edition is OWASP and installs through Docker Compose. The Pro edition is offered as SaaS or self-hosted via Kubernetes or Docker Compose, and the pricing page is where the README sends readers for the differences.

The listed differentiators are concrete: a new UI, risk-based vulnerability management, API connectors, ServiceNow, GitHub, GitLab and Azure DevOps integrations, automatic data enrichment and prioritisation. If your requirement is a ServiceNow ticket created automatically from a finding, that is described as Pro territory, not community. The same applies to risk-based prioritisation as a feature rather than a manual severity field.

A second limitation is operational. The compose file is an evaluation configuration, so a production deployment means writing your own compose overrides or using the helm directory, plus sizing PostgreSQL and the worker tier for your scan volume. The README does not document a rollback procedure for an upgrade, and the release cadence shown in the repository is frequent, with 3.3.100 and 3.3.200 published a week apart in September 2026. Upgrading often is the norm here, and each upgrade needs a database migration you should test on a copy first.

DefectDojo is also the wrong tool if your only source of findings is one scanner. You would be adding a Django application, a database and a worker queue to reproduce a dashboard you already have.

How it compares with a generic issue tracker

The obvious alternative is pushing scanner output straight into Jira or GitHub Issues. The difference is the shape of the data. An issue tracker stores a ticket with a description; DefectDojo stores a finding with a scanner type, a severity, a product and engagement, and a deduplication identity, which is what lets a re-scan update an existing record instead of creating a duplicate. The requirements file shows a jira dependency, so the two are not mutually exclusive: DefectDojo is designed to sit upstream and push out.

The other alternative is a commercial ASPM platform. The README positions Pro as exactly that, with connectors and enrichment the community edition does not list. The trade is control and cost against integration work: the community edition is BSD-3-Clause and self-hosted, and you supply the connectors yourself through the REST API documented at docs.defectdojo.com.

Licence and upgrade cost

The repository is licensed BSD-3-Clause, with a LICENSE.md and a NOTICE file at the top level. That is a permissive licence, so self-hosting and modification are permitted; the NOTICE file is the place to check for attribution requirements, and the project's own documentation is the authority on how the licence applies. Nothing here is legal advice, and if you redistribute DefectDojo inside a product, have counsel read LICENSE.md and NOTICE rather than a review article.

The upgrade cost is real and mostly operational. Releases are frequent, the migration path runs through Django migrations, and the compose file warns against using the default configuration in production. Budget for a staging copy of the database where you rehearse the upgrade, and for reading the release notes for each version you skip.

Maintenance is not in question: the last push to the default branch was on 2026-09-22, and the repository is not archived. The activity is current, and the release tags show a regular cadence rather than a burst.

Editorial conclusion

Adopt DefectDojo if you already run several scanners and need one place to deduplicate their output and track fixes; skip it if you have a single scanner whose own dashboard is enough, or if you need the risk-based prioritisation and connectors that only the Pro edition lists. Before committing, import one real scan report into the demo at demo.defectdojo.org, then read the parser documentation for that tool at docs.defectdojo.com to confirm your report format is supported.

Frequently asked questions

What does DefectDojo do?

It is a DevSecOps, ASPM and vulnerability management tool that orchestrates security testing, vulnerability tracking, deduplication, remediation and reporting. It imports scan reports from supported tools and keeps them as findings rather than scanning code itself.

How much does DefectDojo cost?

The README lists an open source community edition installed through Docker Compose and a Pro edition available as SaaS or self-hosted, with pricing on the defectdojo.com pricing page. It does not state a price for the community edition.

What is the data model used in DefectDojo?

It is a Django application, and the pinned dependencies include django-polymorphic, django-tagulous and django-auditlog, so findings carry types and tags and changes are logged. Scanner output is imported as findings grouped under a product and an engagement, and the exact deduplication rules are documented at docs.defectdojo.com rather than in the README.

Official sources

  1. DefectDojo/django-DefectDojo on GitHub
  2. License: BSD-3-Clause
  3. Project website
  4. README
  5. Releases
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/defectdojo-django-defectdojo.svg)](https://hysenlabs.com/projects/defectdojo-django-defectdojo)