# HASecuritySolutions/VulnWhisperer

Create actionable data from your Vulnerability Scans

Repository: https://github.com/HASecuritySolutions/VulnWhisperer
Canonical: https://ross.abutalabs.com/products/vulnwhisperer
Homepage: https://twitter.com/VulnWhisperer
Language: Python
License: Apache-2.0
License Family: permissive
Topics: nessus, elasticstack, elasticsearch, logstash, vulnerability, python, qualys
Archived: true
Last push: 2026-05-06T01:42:45+00:00

## Health v2 (maintenance only)
Score: 10/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 80, release rhythm 8, longevity 100
- inputs: {"age_days": 3366, "days_push": 120, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: archived
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1396, forks 276 (observed 2026-08-28T04:04:36.606530+00:00)

## What it is
VulnWhisperer is a vulnerability management tool and report aggregator that pulls scan reports from scanners like Nessus, Qualys, OpenVAS, and Tenable.io. It normalizes the data, syncs findings to Jira, and ships them through Logstash into Elasticsearch for visualization in Kibana dashboards.

## Use cases
- aggregate vulnerability scan reports from nessus and qualys
- feed vulnerability scan data into elasticsearch via logstash
- sync vulnerability findings to jira tickets
- visualize vulnerability data in kibana dashboards
- create actionable data from openvas scans
- centralize tenable.io scan reports

## When to choose
- you use Nessus, Qualys, OpenVAS, or Tenable.io and want centralized reporting in the Elastic Stack
- you need automated Jira syncing of vulnerability findings
- you want a self-hosted, open-source vulnerability report aggregator

## When to avoid
- you use scanners not yet supported like Nexpose, Burp Suite, or OWASP ZAP
- you need OpenSearch support, which is only under consideration
- you need actively maintained software with current documentation and code review

## Facets
- artifact type: application
- maturity: maintenance
- function: security, monitoring, etl, logging
- domain: security, monitoring
- platform: python, self-hosted
- tags: vulnerability-management, nessus, qualys, openvas, elk-stack, jira-integration, report-aggregation, devops, linux, docker

## Member repositories
- HASecuritySolutions/VulnWhisperer (main) score 10

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:04:36.606530+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T04:39:17.918725+00:00, confidence not recorded.
  - readme: https://github.com/HASecuritySolutions/VulnWhisperer (fetched 2026-08-28T04:04:36.606530+00:00, sha e3bcf168a24d)
- Data as of 2026-08-30T08:39:29.467469+00:00.
