# Nmap: The Network Mapper and Its Source Repository on GitHub

> Nmap is the Network Mapper, a long-established tool for network discovery and security auditing. The GitHub repository is a read-only mirror of the canonical SVN source at svn.nmap.org, and the primary download point for binary installers is nmap.org, not GitHub.

**nmap/nmap** — Nmap - the Network Mapper. Github mirror of official SVN repository.

- Repository: https://github.com/nmap/nmap
- Website: https://svn.nmap.org/
- Stars: 13,681 · Forks: 2,909
- Language: C
- License: NOASSERTION
- Published: 2026-09-10 · Updated: 2026-09-10 · Language: en
- Canonical page: https://hysenlabs.com/projects/nmap-nmap

## What Nmap Does and Who Uses It

The GitHub repository describes Nmap as "the Network Mapper", and the README describes it as a tool for network discovery and security auditing with binary installers available for Windows, macOS, and Linux. Security professionals use Nmap to identify which hosts are reachable on a network, which ports are open, and what services those ports run. Network administrators use the same capabilities for inventory and change detection.

The first scan example in the README is `nmap scanme.nmap.org`. The scanme.nmap.org host is maintained by the Nmap project specifically for this purpose: it is a target users are permitted to scan while learning the tool. Starting with that host avoids the risk of accidentally scanning a machine the user does not own, which the README addresses through its licensing and legal documentation at nmap.org/book/man-legal.html.

## The GitHub Repository Is a Mirror of the SVN Source

The repository's homepage field points to svn.nmap.org, not to GitHub. The README's title link goes to the Nmap CI workflow on GitHub Actions, suggesting the GitHub repository does run CI. But the authoritative source is the SVN repository.

This distinction matters for teams that want to file issues or submit patches. The README directs questions and suggestions to the Nmap-dev mailing list at nmap.org/mailman/listinfo/dev, and contribution information is in the HACKING and CONTRIBUTING.md files. The repository has no GitHub releases; the latest version is distributed as binary installers from nmap.org/download.html and as source through the SVN mirror. The last push to the GitHub mirror was on 2026-09-17.

For teams using Nmap as a dependency or integrating its scanning capabilities, the distinction between the GitHub mirror and the SVN source matters for license compliance and patch tracking. The GitHub mirror exists for visibility and CI, not as the development hub.

## Building Nmap from Source

The README gives the standard source build sequence for Unix-like systems:

```bash
./configure
make
make install
```

For more detailed compilation, installation, and removal instructions, the README refers to the Nmap Install Guide at nmap.org/book/install.html. The source tree bundles several libraries directly rather than depending on system-installed versions: the top-level repository entries include libdnet-stripped, liblinear, liblua, libnetutil, libpcap, libpcre, libssh2, and libz. This means the build does not require all of those libraries to be installed on the target system, which simplifies cross-platform builds but increases the repository size.

For Windows, macOS, and Linux (RPM) users who do not want to compile from source, the README states that binary installers are available from nmap.org/download.html. Those are the recommended installation method for most users.

## Running the First Nmap Scan

The README describes the starting point: `nmap scanme.nmap.org`. This invokes a default scan against the project's test host. The README notes that running nmap without parameters prints a list of the most common options.

The man page at nmap.org/book/man.html covers every command-line option in depth. The README does not document specific flags inline, pointing readers to the man page and the nmap.org documentation for full coverage.

The test host `scanme.nmap.org` is maintained as a sanctioned target. Scanning it exercises the tool against a real host with real network responses without requiring the user to own a target machine. The README does not describe the scan output format, the specific ports that will show open, or the detection mechanisms used; those details are in the documentation at nmap.org/docs.html.

## Zenmap: The Graphical Front-End for Nmap

The README mentions Zenmap as the included graphical interface for Nmap: "Users who prefer a graphical interface can use the included Zenmap front-end." The Zenmap page is at nmap.org/zenmap/.

Zenmap is relevant for users who find the command-line interface difficult to navigate, particularly when building complex scan options or reading results from multi-host scans. It wraps the same Nmap binary and presents results in a visual layout with a topology map.

The README does not document the differences between specific Zenmap and CLI behaviors, so the practical trade-offs between the two are in the nmap.org documentation. What is stated is that Zenmap is shipped alongside the core Nmap tool, not as a separate project.

## The Nmap License and Its Downstream Implications

The README is explicit about the license: "Nmap is released under a custom license, which is based on (but not compatible with) GPLv2." Two facts follow from this. First, the license allows free usage by end users. Second, companies that want to redistribute Nmap technology with their products must obtain a commercial license.

The custom license is documented at nmap.org/book/man-legal.html. The incompatibility with GPLv2 is significant for open-source projects: a project under the GPL that wants to incorporate Nmap code, or a project that wants to link against Nmap libraries, cannot do so under GPLv2 terms without the commercial license. This makes Nmap unsuitable as a direct dependency for GPL-licensed tools that plan to redistribute the combined work.

For end-user security tools that invoke Nmap as a subprocess rather than linking to it, the free-use clause applies. The distinction between linking and subprocess invocation has practical consequences for tool authors who want to build on Nmap's capabilities.

## Nmap vs Masscan for High-Speed Port Scanning

Masscan is a well-known alternative that focuses specifically on high-speed port discovery across large IP ranges. The difference in approach is scope and speed versus depth. Masscan uses its own TCP/IP stack to send packets at high rates and is built for sweeping large address blocks quickly. It does not perform the service version detection, OS fingerprinting, or scriptable probing that Nmap offers.

Nmap bundles a fingerprint engine (FPEngine.cc and FPModel.cc are in the top-level repository) and a Lua scripting subsystem (liblua and lpeg.c), making it suited for detailed analysis of individual hosts or small networks. The trade-off is throughput: for scanning millions of addresses, the tooling and workflow are different from Nmap's default operating mode.

For teams that need both broad discovery and detailed analysis, the common pattern is to use a fast scanner for initial discovery and Nmap for deeper probing on identified targets. The README does not document this workflow; it is a widely-known usage pattern for network security work.

## Conclusion

Nmap is appropriate for network administrators, penetration testers, and security researchers who need to scan and inventory hosts on networks they are authorized to test. The GitHub repository is a mirror, so teams who want canonical source history should use the SVN repository at svn.nmap.org rather than treating the GitHub clone as authoritative. Before scanning any host, confirm authorization: the Nmap license page at nmap.org/book/man-legal.html covers the legal constraints, and the project has written detailed guidance on what constitutes authorized use. The Nmap license is not compatible with GPLv2, which matters for any downstream project that wants to redistribute Nmap code.

## FAQ

### What is an Nmap scan used for?

The repository describes Nmap as a network discovery and security auditing tool. It scans hosts to identify which ports are open and which services are running. The README points to full documentation at nmap.org/docs.html for details on specific capabilities.

### How do I install Nmap?

Binary installers for Windows, macOS, and Linux (RPM) are available from nmap.org/download.html. To build from source, run ./configure, then make, then make install. The full compilation guide is at nmap.org/book/install.html.

### What is the difference between Nmap and Zenmap?

Nmap is the command-line network scanner. Zenmap is the graphical front-end for Nmap, shipped alongside it. The README describes Zenmap as the option for users who prefer a graphical interface, available at nmap.org/zenmap/.

### What are common Nmap port scanning examples?

The README gives nmap scanme.nmap.org as the introductory scan example. The scanme.nmap.org host is maintained by the Nmap project for users to practice against. Running nmap without arguments prints a list of the most common options.

## Sources

- [Issues](https://github.com/nmap/nmap/issues)
- [nmap/nmap on GitHub](https://github.com/nmap/nmap)
- [Project website](https://svn.nmap.org/)
- [README](https://github.com/nmap/nmap/blob/master/README.md)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/nmap-nmap
