0xKayala/NucleiFuzzer
NucleiFuzzer is a robust automation tool that efficiently detects web application vulnerabilities, including XSS, SQLi, SSRF, and Open Redirects, leveraging advanced scanning and URL enumeration techniques observed · 2026-08-28
Health v2 · maintenance only
66/100
- Activity 77
- Release rhythm 40
- Longevity 85
Flags: no_license
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.
- gap_med: 4
- age_days: 1199
- days_rel: 603
- days_push: 138
- n_releases_24m: 2
Adoption not part of the score
1862 stars · 259 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
NucleiFuzzer is a Python-based automation tool that combines URL discovery tools (ParamSpider, Waybackurls, Gauplus, Hakrawler, Katana) with Nuclei fuzzing templates to detect web application vulnerabilities like XSS, SQLi, SSRF, and Open Redirects. It handles deduplication with uro, HTTP filtering with httpx, rate limiting, and JSON/HTML reporting for security testing workflows.
Use cases
- find xss vulnerabilities in a web application
- scan a domain for sqli and ssrf bugs
- enumerate hidden endpoints and parameters for bug bounty
- automate nuclei fuzzing scans across multiple domains
- discover urls from wayback machine and crawl them for vulnerabilities
- batch scan a list of domains for open redirects
When to choose
- you are a bug bounty hunter or pentester wanting an automated recon-plus-scan pipeline
- you already use nuclei and want broader URL/parameter coverage
- you need batch domain scanning with deduplication and severity-grouped reports
When to avoid
- you need a GUI or managed vulnerability management platform
- you cannot install the required external tools (nuclei, paramspider, httpx, uro, etc.)
- you need authenticated or complex multi-step application testing rather than fuzzing templates
Facets
cli-tool · maturity active
security penetration-testing web-scraping cli fuzzing security penetration-testing web-development developer-tools windows cli python vulnerability-scanning bug-bounty nuclei url-discovery recon xss sqli ssrf open-redirect automation linux macos
2 sources
- readme: https://github.com/0xKayala/NucleiFuzzer · fetched 2026-08-28 · 362c4715136f
- homepage: https://nucleifuzzer.0xkayala.com · fetched 2026-08-29 · 82466a66afdb
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| 0xKayala/NucleiFuzzer | main | 66 |
For agents
markdown · JSON · MCP: product_card(name="0xKayala/NucleiFuzzer")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem