Open-source pentest platform trusted by 1,000s

Self-hosted collaboration and reporting from 25+ security tools. No vendor lock-in. Battle-tested over 17 years, with active community support.
Loading...

Or go straight to download

Join 1,000's of Security Teams Using Dradis Community Edition

1,000+ clones each month, 744+ ⭐️s on , an active forum and Slack community.
17 years of history and strong daily development.

Included In:

Built for Security Teams

Dradis CE is an extensible, cross-platform, open-source security framework designed to streamline collaboration, deliver consistent and accurate results, and automate pentest reporting, saving you hours on every project. Built by leading security experts, generate professional reports - without vendor lock-in or licensing costs.

Create Reports with One Click

Combine the output of your favourite security scanning tools, manual findings, and notes to generate consistent reports in a fraction of the time of writing them manually.

Screenshot showing generated reports in Word and Excel

Collaborate Seamlessly

Track the progress of your project, split tasks, and comment on findings with other team members. Centralized project details keeps everyone on the same page.

Screenshot of Dradis' Project Summary page showing Issues, Team, and Methodology progress

25+ Integrations, No Vendor Lock-In

Import findings from Burp, Nessus, Nmap, Qualys, and more. And if we don't have an integration for your favorite tool, it's easy to create one!

See all integrations
  • Nessus logo
  • Nexpose logo
  • Nikto logo
  • Nmap logo
  • Burp Pro logo
  • Qualys logo
  • w3af logo
  • Zed Attack Proxy (ZAP) logo
  • MediaWiki logo
  • OpenVAS logo
  • Open Source Vulnerability Database (OSVDB) logo

Join An Active Community

Dradis CE is a platform independent web application with 17 years of daily development and an active community.

Get support from the community forum, contribute to the codebase, or extend functionality - no vendor restrictions.

Ready to save hours on each engagement? Get started by installing Dradis CE today.

Loading...

Or go straight to download

Screenshot of Dradis' Project node properties

Mastering Dradis: 7-lesson email quickstart

New to Dradis? Install Community Edition and follow a short email course that walks you through the key workflows so you can start saving time on real projects.

  • Import results from your favorite tools and generate your first automated report.
  • Use templates, checklists, and a findings library to keep reports consistent.
  • Archive projects safely so you can spend more time on actual hacking.

The course is free for CE users and delivered over 7 short lessons.

Start With CE, Upgrade When Ready

Experience Dradis with your actual workflows and tools. Upgrade to Pro anytime for advanced features.

Two Ways to Use Community Edition

Evaluate Dradis

Test the platform risk-free with your security tools and workflows before committing to Pro. No time limits, full functionality.

Use Long-Term

Core features may be all you need. Start with CE and upgrade only if your requirements grow beyond what CE has to offer.

See how DeepBlue automated enterprise Dradis CE deployment with Docker and Kubernetes, to scale operations at zero cost

Loading...

Or go straight to download

Max Duijsens

CTO & Founder

DeepBlue Security & Intelligence

"The combination of Dradis CE and our Docker/Kubernetes infrastructure gives us enterprise-level security assessment capabilities without any licensing overhead.

We can spin up isolated environments for each client engagement while maintaining operational standards. Our private registry approach means we apply security patches once and they automatically propagate to all client containers."

Read the case study

Featured On



Trusted by over 1,154 InfoSec teams in 75 countries.

Dradis has been making your day easier since 2007.

Is the Community Edition Right for Your Team?

Dradis CE provides core reporting and collaboration for free. If your team needs advanced features for scaling or client delivery you should consider Dradis Pro.

Perfect for Community Edition

  • Small consultancies or solo practitioners
  • Security teams with basic reporting needs
  • Teams wanting zero licensing costs
  • Evaluating Dradis before committing to Pro

Upgrade to Pro for Advanced Features

Pro retains all CE benefits: open-source foundation, self-hosted deployment, and data ownership, plus:

  • Advanced QA workflows and approval processes
  • Client-facing branded portals for real-time results
  • Integration with Jira, ServiceNow, Azure DevOps
  • Onboarding and ongoing support, + template conversions
  • Team management and granular access controls
Compare All Features
Loading...

Or go straight to download

Frequently Asked Questions About Dradis CE

If your answer is not here, the Community Forums are your best bet

Dradis Community Edition is released under the GPLv2 license. This means it's "Free software" that respects users' freedom and community.

Roughly, you have the freedom to run, copy, distribute, study, change and improve the software. "Free" here refers to liberty, not price—think "free speech," not "free beer."

Dradis CE is both "Free software" (freedom-respecting) and gratis (no cost).

You can find the source code on GitHub: /dradis/dradis-ce

You'll need a Ruby environment to run Dradis CE.

No dedicated IT staff required - standard system administration skills are sufficient. Full installation documentation is available in our CE documentation.

Don't worry - help is available! Please head to the Community Forums and describe what went wrong.

There are plenty of experienced users ready to help. You can also join our Slack channel for real-time assistance.

When asking for help, include:

  • What you were trying to do
  • What happened instead (error messages, screenshots)
  • Your Dradis CE version and operating system

Consider upgrading to Dradis Pro when you need:

  • Interactive results portal: Branded, real-time results delivery
  • Advanced QA workflows: Multi-stage approval processes and revision tracking
  • Ticketing integrations: Sync findings with Jira, ServiceNow, or Azure DevOps
  • Additional support: Report template conversions, onboarding and ongoing support
  • Team scaling: Granular permissions and user management for larger teams

Pro retains all CE benefits (open-source foundation, self-hosted deployment, data ownership) and adds professional features. Compare editions

Yes. Dradis Pro is built on the same open-source foundation as CE and remains fully self-hosted:

  • Self-hosted deployment: Install on your infrastructure, complete data ownership
  • Open-source core: GPL-licensed foundation with full transparency
  • No vendor lock-in: Your data, your control
  • Custom integrations: Full API access and extensibility

The difference between CE and Pro is features and support, not architecture. Pro adds advanced workflows, client portals, and priority support while maintaining the same self-hosted, open-source principles.

Self hosted gives you complete control:

  • Data ownership: All client or assessment data stays on your infrastructure - no third-party access
  • No vendor lock-in: Open-source GPL license means you're never dependent on us
  • Compliance flexibility: Deploy in air-gapped environments or restricted networks
  • Custom integrations: Build your own plugins without vendor approval

Perfect for security-conscious organizations, consultancies with strict data residency requirements, and teams who value transparency and control.

Dradis CE is community-supported with active channels:

  • Community Forums: Active user community with responses from experienced users
  • Slack Channel: Real-time chat with other Dradis users
  • GitHub Issues: Bug reports, feature requests, and development discussions
  • Documentation: Comprehensive guides, tutorials, and API references

Need dedicated support? Dradis Pro includes onboarding and ongoing support directly from our team.

Absolutely. Many Pro customers start with CE to validate that Dradis fits their workflows and integrates with their existing tools.

Benefits of evaluating with CE:

  • Test with your actual security tools and scanning outputs
  • Validate report customization with your templates
  • Train your team on core workflows risk-free
  • No time limits or feature restrictions in CE - full core functionality

CE includes basic reports, you can work on one project at a time and generate reports in standard formats.

CE limitations:

  • Single project workflow (one engagement at a time)
  • Non-branded report templates

For full customization, upgrade to Pro:

  • Multiple concurrent projects (manage all engagements simultaneously)
  • Complete report template control
  • Multiple template sets for different assessment types
  • Advanced output formats (DOCX, PDF, HTML, custom formats)
  • Reusable finding libraries you can customize per engagement

Many teams start with CE for evaluation, then upgrade to Pro when they need multi-project management and custom branded reports. Compare editions

Looking For More Features?

Find out which edition best fits your team’s needs

How Much Will You Save?

ROI calculator: Tell us about your business.

We've got people in the team, each of us is involved in about projects per month on average, and our average rate is around $ USD.

If we could save hours per report. How much money will using Dradis Pro save us?


If you saved 2 hours per report, or $200 at your current rate, times 3 projects a month: you'll save $600 per person each month, that's $3,000 for the 5 of you every month.

Just to be clear, the investment required for Dradis Pro is $79 per person (or $474 for the team). If the tool saves you $600, the first $474 go towards paying for itself and the remaining $521 are pure savings, every month. That's $6,252 per year that you're leaving on the table.


There are lots of things you can do with $6,252:

  • Invest more time testing to get more results and add more value to your clients.
  • Use that time to wrap up the project and update your testing methodologies.
  • Use that time to find new clients.
  • Pass the savings to your clients and become more competitive.
  • Don't tell anyone and just pocket the savings.

Seven Strategies To Differentiate Your Cybersecurity Consultancy

You don’t need to reinvent the wheel to stand out from other cybersecurity consultancies. Often, it's about doing the simple things better, and clearly communicating what sets you apart.

  • Tell your story better
  • Improve your testimonials and case studies
  • Build strategic partnerships

Your email is kept private. We don't do the spam thing.