Skip to content
Agents tracked: 378 Downloads (7d): 244M down 5.7% GitHub stars: 8.4M VS Code installs: 151M Releases (7d): 407 Agent status: 1 with issues Updated Oct 10, 2026

Codex Security vs Strix

Codex Security (OpenAI) and Strix (Strix) side by side on public data, as of Oct 10, 2026.

Strix has 6.1x the GitHub stars of Codex Security (67.6K against 11K). Codex Security shipped 30 stable releases in the past 90 days. Strix shipped 14 stable releases in the past 90 days.

Side-by-side numbers

Metric Codex SecurityStrix
Gid Score7325
Overall rank#10#226
Downloads, last 7 days—9,808
Downloads, 7-day change—up 11.5%
Downloads, 30-day change—down 49.7%
VS Code installs——
Marketplace rating——
GitHub stars11K67.6K
Homebrew installs, 30 days——
Hacker News mentions, 30 days2041
Latest stable release0.2.0 · 4d ago1.7.0 · 5d ago
Stable releases, 90 days3014
Terminal-Bench (best run)——
PriceFree (OSS)Free + $29/mo
LicenseApache-2.0Apache-2.0
First releasedJuly 2026August 2025
Interfaces——
Models

Trends

GitHub starsrunning total
Codex SecurityStrix
Hacker News mentionsrolling 7-day total
Codex SecurityStrix

Codex Security

OpenAI's Codex Security CLI and TypeScript SDK for finding, validating, and fixing security vulnerabilities. npm: https://www.npmjs.com/package/@openai/codex-security

Pricing: Open source under the Apache-2.0 licence; check the website for any paid hosted plans.

Latest release 0.2.0:

  • Threat models are now saved with Standard, Deep, and Diff scan results and generated security policies. Export a saved model without another model call using codex-security export --artifact…
  • Scans now check for exposed credentials in source code, including unused code and tests, and distinguish suspected exposures from placeholders. This check runs offline, without trying discovered…
  • Use --model and --effort when generating patches, validating findings, verifying fixes, or matching and comparing saved scans. Deep Scan workers and patches generated during a scan also respect…
  • Patch, validation, and fix-verification commands now respect custom model providers and their authentication settings. Amazon Bedrock users get clearer authentication errors and cost estimates for…

Full Codex Security profile

Strix

An open-source multi-agent penetration testing tool that runs dynamic tests against applications, validates findings with working proofs of concept and proposes fixes; it runs locally with Docker or as a hosted service.

Pricing: Open-source version free to run locally. Strix Cloud Pro is $29 per seat a month with pentests billed separately; Enterprise custom.

Latest release 1.7.0:

  • fix(models): frontier model check matches the model name only, never the provider route
  • feat(reporting): link HTTP exchange evidence
  • feat(prompts): require httpexchangeids for proxy-validated findings
  • docs: add Vercel AI Gateway provider guide

Full Strix profile