# cisagov/log4j-scanner

log4j-scanner is a project derived from other members of the open-source community by CISA to help organizations identify potentially vulnerable web services affected by the log4j vulnerabilities.

Repository: https://github.com/cisagov/log4j-scanner
Canonical: https://ross.abutalabs.com/products/log4j-scanner
Language: Java
License Family: other
Topics: security-tools, security, log4j, cve-2021-45046, cve-2021-44228
Archived: true
Last push: 2022-12-06T14:38:33+00:00

## Health v2 (maintenance only)
Score: 10/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 0, release rhythm 35, longevity 100
- inputs: {"age_days": 1716, "days_push": 1366, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases, archived, no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1278, forks 208 (observed 2026-08-28T04:04:13.492382+00:00)

## What it is
A CISA-derived scanner for detecting web services vulnerable to the Log4Shell remote code execution vulnerabilities (CVE-2021-44228 and CVE-2021-45046). It probes endpoints with Log4j payloads and detects callbacks via self-hosted DNS logging or services like Interact.sh and Canarytokens.

## Use cases
- scan web services for log4shell vulnerability
- check if my servers are affected by CVE-2021-44228
- detect log4j RCE in web applications
- find vulnerable log4j endpoints across a network
- test web apps for CVE-2021-45046 exploitation

## When to choose
- auditing systems during the Log4Shell incident response window
- needing a community-vetted scanner endorsed by CISA
- wanting DNS-based out-of-band detection of exploitation callbacks

## When to avoid
- needing ongoing maintenance or updates - the repo is archived as of December 2022
- requiring a guaranteed true-positive scanner - false negatives may occur
- scanning systems you do not own or lack authorization to test

## Facets
- artifact type: cli-tool
- maturity: abandoned
- function: security, vulnerability-scanning, penetration-testing, http-client
- domain: security, penetration-testing, developer-tools
- platform: cli, cross-platform, python, jvm
- tags: log4shell, cve-2021-44228, cve-2021-45046, cisa, vulnerability-scanner, dns-callback, archived

## Member repositories
- cisagov/log4j-scanner (main) score 10

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:04:13.492382+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T05:02:44.823512+00:00, confidence not recorded.
  - readme: https://github.com/cisagov/log4j-scanner (fetched 2026-08-28T04:04:13.492382+00:00, sha 29117941e675)
- Data as of 2026-08-30T08:39:29.467469+00:00.
