wycheproof

The premium Open Source alternative to Veracode

🎯 Best for:Developers verifying the correctness of crypto implementations.
Visit WebsiteCompare with Veracode
3.0k
Stars
Apache-2.0License

What is wycheproof?

Replaces manual security audits for cryptographic library implementations. Provides automated unit tests to detect vulnerabilities against known mathematical attacks.

Tech Stack
GoTesting & QA

Why wycheproof?

  • Google-backed research
  • Detects subtle edge-case bugs
  • Supports Java, C++, and Go

Limitations

  • Limited to crypto logic
  • No remediation suggestions
  • Requires deep crypto knowledge
3/5/2026
Last Update
319
Forks
15
Issues
Apache-2.0
License
Financial Leak Detected

Stop the "SaaS Tax"

Your team could be burning cash. Switching to wycheproof instantly boosts your runway.

Competitor Cost
-$1,440
/ year (est. based on Veracode)
Self-Hosted
$0
/ year
Team Size10 Users
150+
SAVE 100%

Community Discussion

Comments