Ross ROSS = Recommend OSS · open-source software intelligence for agents

fit2cloud/riskscanner

RiskScanner 是开源的多云安全合规扫描平台,基于 Cloud Custodian 和 Nuclei 引擎,实现对主流公(私)有云资源的安全合规扫描和漏洞扫描。 observed · 2026-08-28

github.com/fit2cloud/riskscanner · Java · GPL-2.0 (copyleft) · archived observed · 2026-08-28

Health v2 · maintenance only

10/100

  • Activity 0
  • Release rhythm 8
  • Longevity 100

Flags: archived

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 2143
  • days_rel: n/a
  • days_push: 1237
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

1152 stars · 185 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

RiskScanner is an open-source multi-cloud security compliance scanning platform built on Cloud Custodian, Prowler, and Nuclei engines. It performs security compliance checks (CIS, China MLPS 2.0) and vulnerability scanning across major public and private clouds including AWS, Azure, GCP, Alibaba Cloud, Tencent Cloud, Huawei Cloud, OpenStack, and VMware vSphere.

Use cases

  • scan multi-cloud resources for security compliance
  • run CIS benchmark checks on cloud accounts
  • perform MLPS 2.0 (等保2.0) pre-checks on cloud infrastructure
  • scan web services for vulnerabilities like SQL injection and XSS
  • audit cloud servers, databases, object storage, and load balancers for misconfigurations
  • define custom YAML-based cloud scanning rules
  • get best-practice recommendations for cloud compliance baselines

When to choose

  • you need unified security compliance scanning across multiple Chinese and international cloud providers
  • you want CIS or MLPS 2.0 compliance checks with a web UI
  • you need both cloud resource compliance and web vulnerability scanning in one self-hosted platform

When to avoid

  • you need actively maintained software - the project is discontinued and migrated to CloudExplorer Lite
  • you only use a single cloud provider with native security tools available
  • you need enterprise-grade support or recent vulnerability rule updates

Facets

application · maturity abandoned

security vulnerability-scanning monitoring cloud security cloud-computing self-hosted cloud-security compliance-scanning multi-cloud cis-benchmark nuclei cloud-custodian vulnerability-scanning gpl-2.0 spring-boot vue devops docker web-server

1 source

Member repositories

RepositoryRoleHealth v2
fit2cloud/riskscannermain10

For agents

markdown · JSON · MCP: product_card(name="fit2cloud/riskscanner")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem