projectdiscovery/nuclei
Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations. observed · 2026-08-28
Health v2 · maintenance only
98/100
- Activity 99
- Release rhythm 96
- Longevity 100
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: 20
- age_days: 2343
- days_rel: 25
- days_push: 7
- n_releases_24m: 32
Adoption not part of the score
30855 stars · 3831 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded
Nuclei is a fast, open-source vulnerability scanner built on a simple YAML-based template DSL, maintained by ProjectDiscovery. It uses a large community-contributed template library to detect exploitable vulnerabilities across web applications, APIs, networks, DNS, and cloud infrastructure with minimal false positives.
Use cases
- scan my web apps for known CVEs
- find subdomain takeover vulnerabilities
- run bulk vulnerability scans across many URLs or IP ranges
- write custom security detection checks in YAML
- continuously monitor my attack surface for new vulnerabilities
- automate DAST scanning in CI/CD pipelines
- check cloud and network infrastructure for misconfigurations
When to choose
- you need fast, template-driven vulnerability scanning with a huge community template library
- you want to write custom detection checks without learning a complex scanner plugin system
- you need bulk scanning of URLs, IPs, ASNs, or file-based target lists
- you want low false positives via real-world exploit verification
When to avoid
- you need deep authenticated internal network scanning comparable to a full enterprise vulnerability manager
- you want passive SAST source-code analysis rather than active probing
- you require a GUI-driven scanning workflow out of the box
Facets
cli-tool · maturity active
vulnerability-scanning security cli workflow-automation security penetration-testing developer-tools windows go cli yaml-templates dast cve-scanning attack-surface subdomain-takeover bug-bounty community-templates devops linux macos docker kubernetes
6 sources
- readme: https://github.com/projectdiscovery/nuclei · fetched 2026-08-28 · 330cd63369c9
- homepage: https://docs.projectdiscovery.io/tools/nuclei · fetched 2026-08-29 · 155eeadbeecf
- site_page: https://docs.projectdiscovery.io/ · fetched 2026-08-29 · f8adb7e49951
- site_page: https://docs.projectdiscovery.io/quickstart · fetched 2026-08-29 · 3dad04b1713f
- site_page: https://docs.projectdiscovery.io/opensource/nuclei/install · fetched 2026-08-29 · 248d369e518d
- site_page: https://docs.projectdiscovery.io/opensource/nuclei/faq · fetched 2026-08-29 · 7829b621947c
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| projectdiscovery/nuclei | main | 98 |
For agents
markdown · JSON · MCP: product_card(name="projectdiscovery/nuclei")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem