Ross ROSS = Recommend OSS · open-source software intelligence for agents

tongcheng-security-team/NextScan

飞刃是一套完整的企业级黑盒漏洞扫描系统,集成漏洞扫描、漏洞管理、扫描资产、爬虫等服务。 拥有强大的漏洞检测引擎和丰富的插件库,覆盖多种漏洞类型和应用程序框架。 observed · 2026-08-28

github.com/tongcheng-security-team/NextScan · homepage · JavaScript observed · 2026-08-28

Health v2 · maintenance only

21/100

  • Activity 0
  • Release rhythm 8
  • Longevity 90

Flags: no_license

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 1265
  • days_rel: n/a
  • days_push: 1160
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

1164 stars · 105 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

NextScan (飞刃) is an enterprise-grade distributed black-box vulnerability scanning platform built in Go, composed of Server, Agent, and Web components. It integrates vulnerability scanning, vulnerability and POC management, asset management, and a headless-browser crawler, with deep Nuclei integration supporting 5000+ POC templates.

Use cases

  • scan web applications for common vulnerabilities
  • manage vulnerabilities and POCs in one platform
  • run distributed large-scale security scans
  • crawl websites with a headless browser for attack surface discovery
  • passively scan traffic through an HTTP proxy
  • ingest scan targets from Kafka traffic or logs
  • assess enterprise assets for host and service vulnerabilities

When to choose

  • you need an out-of-the-box enterprise vulnerability scanning platform with a web UI
  • you want Nuclei-compatible POC scanning with distributed horizontal scaling
  • you need combined asset discovery, crawling, scanning, and vulnerability management
  • you want multiple scan sources including proxy, browser plugin, and Kafka feeds

When to avoid

  • you need full source code - the code is not fully open-sourced yet, only binaries are released
  • you need ARM/Apple Silicon support - only amd64 is well tested
  • you need a lightweight CLI-only scanner rather than a full platform with MongoDB, Redis, and etcd dependencies
  • you require an OSI-approved license - the repository has none

Facets

application · maturity maintenance

vulnerability-scanning security web-scraping self-hosted developer-tools security penetration-testing web-development self-hosted self-hosted go black-box-scanner nuclei-integration distributed-scanning poc-management headless-browser-crawler passive-scanning vulnerability-management enterprise-security linux docker web-server

10 sources

Member repositories

RepositoryRoleHealth v2
tongcheng-security-team/NextScanmain21

For agents

markdown · JSON · MCP: product_card(name="tongcheng-security-team/NextScan")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem