prowler-cloud/prowler

Prowler is the world’s most widely used open-source cloud security platform that automates security and compliance across any cloud environment.

View on GitHub ↗Jump to charts ↓Open shareable report

Summary Information

Updated 47 seconds ago
Added to GitGenius on September 4th, 2026
Created on August 24th, 2016
Open Issues & Pull Requests: 385 (+0)
GitHub issues: Enabled
Number of forks: 2,379
Total Stargazers: 14,767 (+0)
Total Subscribers: 126 (+0)

Repository Insights (GitGenius)

Median issue/PR response: 15.8 hours
Mean response time: 8.4 days
90th percentile: 7.3 days
Tracked items: 570

How this project is maintained

Around half of the issues opened in the past year never receive a reply. 89% of open issues come from outside the core team, so the backlog reflects real-world use rather than internal planning. Work labelled "severity/low" is answered fastest, typically in about 7 hours, while "new-check" waits about 3 days. Almost all tracked open issues have seen activity in the last three months. Only 4% of issues opened in the past year have been closed.

Charts & Analytics

Fetching additional details & charts...

Issue Activity (beta)

Open issues: 138
New in 7 days: 13
Closed in 7 days: 1
Avg open age: 139 days
Stale 30+ days: 41
Stale 90+ days: 21

Recent activity

Opened in 7 days: 9
Closed in 7 days: 0
Comments in 7 days: 0
Events in 7 days: 0

Top labels

  • bug (282)
  • feature-request (265)
  • provider/aws (145)
  • severity/medium (94)
  • new-check (93)
  • good first issue (75)
  • status/needs-triage (58)
  • status/waiting-for-revision (58)

Detailed Description

Prowler is an open-source cloud security platform that automates security and compliance auditing across AWS, Azure, GCP, and other cloud environments.

Prowler addresses the challenge of maintaining consistent security posture and compliance across multi-cloud infrastructure by running automated security checks against cloud resources. The tool evaluates configurations, permissions, and security settings against established benchmarks and compliance frameworks, identifying misconfigurations and policy violations that could expose organizations to risk. It operates by connecting to cloud provider APIs to inspect resources and compare them against predefined security checks and compliance standards.

Organizations should adopt Prowler if they operate across multiple cloud providers and need centralized visibility into security and compliance status without building custom auditing infrastructure. The tool suits teams managing AWS, Azure, or GCP environments who want to enforce CIS benchmarks, GDPR compliance, or other regulatory requirements at scale. It is particularly valuable for DevSecOps workflows where continuous security monitoring needs to integrate into existing deployment pipelines. The project provides thousands of ready-to-use checks covering common security concerns like IAM configuration, encryption, logging, and access controls, reducing the effort required to establish baseline security assessments.

The project maintains active development with regular updates to checks and compliance frameworks. The codebase shows ongoing refinement of existing functionality rather than major architectural shifts. The tool receives consistent attention to expanding cloud provider coverage and adding new compliance standards. Integration capabilities are actively developed to support diverse deployment scenarios and downstream security tools.