# threathunterX/nebula

[已归档] Nebula 1.x —— 2019 年停止维护,依赖技术栈均已 EOL,请勿用于生产。新版本见 threathunterX/nebula2

Repository: https://github.com/threathunterX/nebula
Canonical: https://ross.abutalabs.com/products/threathunterx-nebula
Homepage: https://threathunter.cn/nebula.html
Language: Lua
License: Apache-2.0
License Family: permissive
Topics: anti-fraud, archived, business-security, deprecated, fraud-detection, lua, openresty, real-time, risk-control, rule-engine
Archived: true
Last push: 2026-07-25T14:41:45+00:00

## Health v2 (maintenance only)
Score: 10/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 94, release rhythm 8, longevity 100
- inputs: {"age_days": 3291, "days_push": 39, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: archived
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1099, forks 383 (observed 2026-08-28T04:03:35.100376+00:00)

## What it is
Nebula 1.x is an open-source business risk-control (anti-fraud) platform that captures traffic out-of-band via OpenResty and analyzes it in real time with a visual rule engine. The repository is archived and unmaintained since 2019; its dependency stack is EOL with known vulnerabilities, and users are directed to the Flink-based Nebula 2.0.

## Use cases
- detect fraudulent login and registration traffic
- real-time risk scoring for online payments and orders
- block marketing promotion abuse without code instrumentation
- deploy a self-hosted anti-fraud rule engine
- analyze visitor and account risk from bypass traffic capture

## When to choose
- studying the architecture and risk-control domain models as historical reference
- evaluating design ideas before adopting Nebula 2.0

## When to avoid
- any production deployment - the project is archived and dependencies have known exploitable vulnerabilities
- new projects - use threathunterX/nebula2 instead
- environments requiring maintained security software or security audits

## Facets
- artifact type: service
- maturity: abandoned
- function: security, monitoring, analytics, streaming, workflow-automation
- domain: security, fintech, e-commerce, analytics
- platform: self-hosted, cloud
- tags: fraud-detection, risk-control, rule-engine, openresty, anti-fraud, archived, traffic-analysis, business-security, real-time, linux, docker

## Member repositories
- threathunterX/nebula (main) score 10

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:03:35.100376+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T06:46:11.650858+00:00, confidence not recorded.
  - readme: https://github.com/threathunterX/nebula (fetched 2026-08-28T04:03:35.100376+00:00, sha 65a7922c1be2)
- Data as of 2026-08-30T08:39:29.467469+00:00.
