# jaeles-project/jaeles

The Swiss Army knife for automated Web Application Testing

Repository: https://github.com/jaeles-project/jaeles
Canonical: https://ross.abutalabs.com/products/jaeles
Homepage: https://jaeles-project.github.io/
Language: Go
License: MIT
License Family: permissive
Topics: golang, hacking, bugbounty, jaeles, web-scanner, scanner, infosec, security-tools, vulnerabilities
Last push: 2026-06-20T12:53:44+00:00

## Health v2 (maintenance only)
Score: 62/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 88, release rhythm 8, longevity 100
- inputs: {"age_days": 2483, "days_push": 74, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 2370, forks 334 (observed 2026-08-28T04:06:41.705025+00:00)

## What it is
Jaeles is a Go-based framework for building and running automated web application vulnerability scanners using customizable YAML signatures. It supports bulk scanning of URL lists, concurrency, proxies, and Slack notifications, and is distributed as a CLI tool and Docker image.

## Use cases
- scan a list of urls for known web vulnerabilities
- automate bug bounty reconnaissance and vulnerability scanning
- write custom detection signatures for web app flaws
- detect vulnerable jira wordpress or java components at scale
- run a web scanner through a proxy like burp
- get slack notifications when a vulnerability is found

## When to choose
- you want a flexible signature-driven web vulnerability scanner in Go
- you need to scan large lists of urls concurrently during bug bounty work
- you want to write your own detection signatures instead of using fixed rules

## When to avoid
- the repository is archived and no longer maintained - prefer its successor or active alternatives like nuclei
- you need a full dynamic application security testing (DAST) suite with crawling and reporting
- you need commercial support or guaranteed updates for new CVEs

## Facets
- artifact type: cli-tool
- maturity: abandoned
- function: security, vulnerability-scanning, web-scraping, cli
- domain: security, penetration-testing, web-development, developer-tools
- platform: windows, cli, go
- tags: web-application-scanner, bug-bounty, signature-based-scanning, automated-testing, archived, linux, macos, docker

## Member repositories
- jaeles-project/jaeles (main) score 62

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:06:41.705025+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T02:35:25.124679+00:00, confidence not recorded.
  - readme: https://github.com/jaeles-project/jaeles (fetched 2026-08-28T04:06:41.705025+00:00, sha 80da8afaf67a)
  - homepage: https://jaeles-project.github.io/ (fetched 2026-08-29T10:16:13.302862+00:00, sha 89bc87cfab4c)
- Data as of 2026-08-30T08:39:29.467469+00:00.
