Skip to content
By goldendivider licenseopen-sourceannouncement

Exploitmatic is now Apache 2.0 ๐ŸŽ‰

Exploitmatic is now Apache License 2.0. ๐ŸŽ‰

The runtime moved off its dual AGPL/commercial terms and now shares the permissive license the solution corpus has used from the start. One license for the whole project.

One license instead of a decision

The old arrangement gave the runtime two paths: AGPL-3.0 for free use, and separate commercial terms for anyone who wanted permissive use, such as embedding it in a closed-source product or running it as a hosted service. The corpus was already Apache-2.0.

Two paths meant a decision at the door for every potential user, and the commercial path started with a conversation. That is friction, and friction is the last thing a runtime meant to be embedded and built on needs.

Apache-2.0 removes the choice. There is one license and one set of terms, with no gate before you can use it.

What the license gives you

  • Use, modify, and distribute the runtime, including inside closed-source products.
  • No obligation to release your source code, including when you run it as a hosted service.
  • A patent grant from every contributor.
  • No contributor license agreement to sign before contributing.

What went away with the old terms

Removing the dual license also removed the extras that came with it:

  • The attribution term that asked hosted services to show a โ€œPowered by Exploitmaticโ€ notice.
  • The contribution clause in the old license text.
  • The signed contributor license agreement flow, individual and corporate.

Apache-2.0 has no CLA. Contributions arrive under the license, and that is the whole process.

Why permissive fits this project

Exploitmatic is built to be part of other things. There is a public crate API for Rust projects, a CLI, and a desktop workbench, and the MCP server lets editors drive the runtime. The natural use is inside another product or pipeline, and permissive terms are what keep that legal review short.

The corpus is the same story. Attack recipes are data, not code. Apache-2.0 keeps them easy to share, which is the point of a public corpus.

What has not changed

The license change is about terms, not behavior. Exploitmatic is still a local runner for proof-of-concept attacks. It does not phone home, and the scope is unchanged: use it only against systems you own or are explicitly authorized to test. A verified result still means the asserts passed on your run, nothing more.

The Apache-2.0 files live in the runtime repository and in the corpus repository. If you build on Exploitmatic, the terms are now the simplest ones available. That is the announcement. ๐ŸŽ‰

Give exploit research a common language.

Bring a PoC, a writeup, or an AI-generated draft into an Exploitmatic solution: inspect it, validate it, and replay it against a target you own. The runtime and the corpus are open source.