Ross ROSS = Recommend OSS · open-source software intelligence for agents

future-architect/vuls

Agent-less vulnerability scanner for Linux, FreeBSD, Container, WordPress, Programming language libraries, Network devices observed · 2026-08-28

github.com/future-architect/vuls · homepage · Go · GPL-3.0 (copyleft) observed · 2026-08-28

Health v2 · maintenance only

98/100

  • Activity 99
  • Release rhythm 95
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 10
  • age_days: 3812
  • days_rel: 35
  • days_push: 7
  • n_releases_24m: 30

Full methodology

Adoption not part of the score

12243 stars · 1240 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

Vuls is an agent-less vulnerability scanner written in Go that detects CVEs on Linux, FreeBSD, Windows, macOS, containers, WordPress, programming language libraries, and network devices using databases like NVD, OVAL, and JVN. It supports remote scanning over SSH, local and server modes, fast/deep scan modes, and reports via email, Slack, terminal viewer, or the VulsRepo web UI.

Use cases

  • scan servers for known CVEs without installing agents
  • monitor new vulnerabilities affecting installed packages
  • detect vulnerable language libraries from lock files
  • audit Docker containers for security vulnerabilities
  • generate regular vulnerability reports via cron
  • check for processes needing restart after updates
  • scan WordPress plugins and network devices for vulnerabilities

When to choose

  • you need agent-less CVE scanning across many servers via SSH
  • you manage mixed fleets of Linux, FreeBSD, Windows, and macOS hosts
  • you want scheduled automated vulnerability reports with Slack/email notifications
  • you need to scan non-OS packages, lock files, or containers

When to avoid

  • you need in-depth SAST/DAST application security testing rather than CVE scanning
  • you require a lightweight agent on each host instead of a central scanner
  • your targets are non-Unix systems outside the supported OS list

Facets

cli-tool · maturity active

vulnerability-scanning security monitoring alerting security infrastructure-as-code self-hosted bsd windows go cli cross-platform vulnerability-management agentless-scanning cve oval nvd ssh-remote-scan container-scanning wordpress-security dependency-scanning slack-notifications reporting devops linux macos docker

9 sources

Member repositories

RepositoryRoleHealth v2
future-architect/vulsmain98

For agents

markdown · JSON · MCP: product_card(name="future-architect/vuls")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem