I Use This!
High Activity
Analyzed 1 day ago. based on code collected 1 day ago.

Project Summary

The Apache Tomcat software is an open source implementation of the Java Servlet, JavaServer Pages, Java Expression Language and Java WebSocket technologies.

Tags

apache http http_server java jsp servlet web web_services

In a Nutshell, Apache Tomcat...

Apache License 2.0
Permitted

Commercial Use

Modify

Distribute

Place Warranty

Sub-License

Private Use

Use Patent Claims

Forbidden

Hold Liable

Use Trademarks

Required

Include Copyright

State Changes

Include License

Include Notice

These details are provided for information only. No information here is legal advice and should not be used as such.

Project Security

Vulnerabilities per Version ( last 10 releases )

Project Vulnerability Report

Security Confidence Index

Poor security track-record
Favorable security track-record

Vulnerability Exposure Index

Many reported vulnerabilities
Few reported vulnerabilities

Did You Know...

  • ...
    use of OSS increased in 65% of companies in 2016
  • ...
    check out hot projects on the Open Hub
  • ...
    55% of companies leverage OSS for production infrastructure
  • ...
    search using multiple tags to find exactly what you need
About Project Security

Languages

Java
81%
XML
9%
XML Schema
8%
10 Other
2%

30 Day Summary

Apr 26 2025 — May 26 2025

12 Month Summary

May 26 2024 — May 26 2025
  • 1105 Commits
    Up + 56 (5%) from previous 12 months
  • 26 Contributors
    Down -7 (21%) from previous 12 months

Ratings

315 users rate this project:
4.23175
   
4.2/5.0
Click to add your rating
  
Review this Project!
 

Static Analysis ( Generated by Coverity Scan for Apache Tomcat )

Repository URL: https://github.com/apache/tomcat

Version: 12-36c226f

2024-09-26
Last Analyzed
254,848
Lines of Code Analyze
0.22
Defect Density

Defects by status for current build

1,270
Total defects
57
Outstanding
808
Fixed

CWE Top 25 defects

ID CWE-Name Number of Defects
22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 8
79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') 31
327 Use of a Broken or Risky Cryptographic Algorithm 2
798 Use of Hard-coded Credentials 11