# fit2cloud/riskscanner

RiskScanner 是开源的多云安全合规扫描平台，基于 Cloud Custodian 和 Nuclei 引擎，实现对主流公(私)有云资源的安全合规扫描和漏洞扫描。

Repository: https://github.com/fit2cloud/riskscanner
Canonical: https://ross.abutalabs.com/products/riskscanner
Language: Java
License: GPL-2.0
License Family: copyleft
Topics: cloud-custodian, yaml, vue, cloud, spring-boot, java, aws, azure, aliyun, huawei, tencent, openstack, vsphere, gcp, nuclei, nuclei-templates
Archived: true
Last push: 2023-04-14T10:00:34+00:00

## Health v2 (maintenance only)
Score: 10/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 0, release rhythm 8, longevity 100
- inputs: {"age_days": 2143, "days_push": 1237, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: archived
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1152, forks 185 (observed 2026-08-28T04:03:47.230412+00:00)

## What it is
RiskScanner is an open-source multi-cloud security compliance scanning platform built on Cloud Custodian, Prowler, and Nuclei engines. It performs security compliance checks (CIS, China MLPS 2.0) and vulnerability scanning across major public and private clouds including AWS, Azure, GCP, Alibaba Cloud, Tencent Cloud, Huawei Cloud, OpenStack, and VMware vSphere.

## Use cases
- scan multi-cloud resources for security compliance
- run CIS benchmark checks on cloud accounts
- perform MLPS 2.0 (等保2.0) pre-checks on cloud infrastructure
- scan web services for vulnerabilities like SQL injection and XSS
- audit cloud servers, databases, object storage, and load balancers for misconfigurations
- define custom YAML-based cloud scanning rules
- get best-practice recommendations for cloud compliance baselines

## When to choose
- you need unified security compliance scanning across multiple Chinese and international cloud providers
- you want CIS or MLPS 2.0 compliance checks with a web UI
- you need both cloud resource compliance and web vulnerability scanning in one self-hosted platform

## When to avoid
- you need actively maintained software - the project is discontinued and migrated to CloudExplorer Lite
- you only use a single cloud provider with native security tools available
- you need enterprise-grade support or recent vulnerability rule updates

## Facets
- artifact type: application
- maturity: abandoned
- function: security, vulnerability-scanning, monitoring, cloud
- domain: security, cloud-computing
- platform: self-hosted
- tags: cloud-security, compliance-scanning, multi-cloud, cis-benchmark, nuclei, cloud-custodian, vulnerability-scanning, gpl-2.0, spring-boot, vue, devops, docker, web-server

## Member repositories
- fit2cloud/riskscanner (main) score 10

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:03:47.230412+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T06:33:32.849177+00:00, confidence not recorded.
  - readme: https://github.com/fit2cloud/riskscanner (fetched 2026-08-28T04:03:47.230412+00:00, sha d7514a62fa15)
- Data as of 2026-08-30T08:39:29.467469+00:00.
