Ross ROSS = Recommend OSS · open-source software intelligence for agents

projectdiscovery/nuclei

Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations. observed · 2026-08-28

github.com/projectdiscovery/nuclei · homepage · Go · MIT (permissive) observed · 2026-08-28

Health v2 · maintenance only

98/100

  • Activity 99
  • Release rhythm 96
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 20
  • age_days: 2343
  • days_rel: 25
  • days_push: 7
  • n_releases_24m: 32

Full methodology

Adoption not part of the score

30855 stars · 3831 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

Nuclei is a fast, open-source vulnerability scanner built on a simple YAML-based template DSL, maintained by ProjectDiscovery. It uses a large community-contributed template library to detect exploitable vulnerabilities across web applications, APIs, networks, DNS, and cloud infrastructure with minimal false positives.

Use cases

  • scan my web apps for known CVEs
  • find subdomain takeover vulnerabilities
  • run bulk vulnerability scans across many URLs or IP ranges
  • write custom security detection checks in YAML
  • continuously monitor my attack surface for new vulnerabilities
  • automate DAST scanning in CI/CD pipelines
  • check cloud and network infrastructure for misconfigurations

When to choose

  • you need fast, template-driven vulnerability scanning with a huge community template library
  • you want to write custom detection checks without learning a complex scanner plugin system
  • you need bulk scanning of URLs, IPs, ASNs, or file-based target lists
  • you want low false positives via real-world exploit verification

When to avoid

  • you need deep authenticated internal network scanning comparable to a full enterprise vulnerability manager
  • you want passive SAST source-code analysis rather than active probing
  • you require a GUI-driven scanning workflow out of the box

Facets

cli-tool · maturity active

vulnerability-scanning security cli workflow-automation security penetration-testing developer-tools windows go cli yaml-templates dast cve-scanning attack-surface subdomain-takeover bug-bounty community-templates devops linux macos docker kubernetes

6 sources

Member repositories

RepositoryRoleHealth v2
projectdiscovery/nucleimain98

For agents

markdown · JSON · MCP: product_card(name="projectdiscovery/nuclei")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem