Vendors › Vulnerability Management › Greenbone OpenVAS
Greenbone OpenVAS
Greenbone AG
Combined score
▪ Editorial verdict
Greenbone OpenVAS has maintained genuine relevance in the vulnerability management category since its 2008 fork from the original Nessus codebase, and the free Community Edition offers real enterprise-grade scanning depth with over 170,000 test routines at zero licensing cost. For budget-constrained organisations, government agencies, and technical teams with the engineering capacity to self-host and maintain the infrastructure, this represents genuine vulnerability scanning capability that many organisations would otherwise go without entirely. The active German development community and available paid Enterprise editions mean organisations are not limited to purely unsupported open source if they eventually need commercial backing.
The honest trade-off mirrors every free and open source infrastructure tool in this comparison. Prioritisation is basic CVSS scoring without the exploit intelligence and attack path context that Tenable or Rapid7 provide, there is no native patch management or remediation workflow, and CI/CD integration is limited. Organisations choosing Greenbone are trading commercial platform convenience for zero licensing cost and full infrastructure control.
The verdict: Greenbone OpenVAS is right for budget-constrained organisations and technical teams wanting genuinely free, comprehensive vulnerability scanning with the capacity to build the surrounding workflow themselves. Organisations wanting integrated prioritisation and turnkey remediation should evaluate Tenable or Qualys instead.
Last reviewed: September 2026
G2
PeerSpot
Vulnerability Management assessment
Strongest: Asset & exposure coverage
Watch out for: Remediation workflows
Strengths & limitations
Strengths
Watch out for
Best for
Budget-constrained organisations and technical teams wanting genuinely free, comprehensive vulnerability scanning coverage with the engineering capacity to build the surrounding remediation workflow themselves.
Not suitable for: Organisations wanting integrated prioritisation intelligence, native patch management, or a turnkey vulnerability management program without significant additional tooling and engineering investment.
Compliance coverage
Switching intelligence
Switching from
Common migration paths based on review data
- No vulnerability scanning
- Expired commercial licenses