# future-architect/vuls

Agent-less vulnerability scanner for Linux, FreeBSD, Container, WordPress, Programming language libraries, Network devices

Repository: https://github.com/future-architect/vuls
Canonical: https://ross.abutalabs.com/products/vuls
Homepage: https://vuls.io/
Language: Go
License: GPL-3.0
License Family: copyleft
Topics: vuls, vulnerability-scanners, golang, go, linux, freebsd, vulnerability-detection, security, security-tools, cybersecurity, security-vulnerability, security-scanner, security-hardening, security-automation, security-audit, vulnerability-assessment, vulnerability-management, vulnerability-scanner, vulnerabilities, administrator
Last push: 2026-08-26T10:00:09+00:00

## Health v2 (maintenance only)
Score: 98/100 (v2, computed 2026-09-03T02:39:23.370411+00:00)
- activity 99, release rhythm 95, longevity 100
- inputs: {"age_days": 3812, "days_push": 7, "days_rel": 35, "gap_med": 10, "n_releases_24m": 30}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 12243, forks 1240 (observed 2026-08-28T04:10:52.122774+00:00)

## What it is
Vuls is an agent-less vulnerability scanner written in Go that detects CVEs on Linux, FreeBSD, Windows, macOS, containers, WordPress, programming language libraries, and network devices using databases like NVD, OVAL, and JVN. It supports remote scanning over SSH, local and server modes, fast/deep scan modes, and reports via email, Slack, terminal viewer, or the VulsRepo web UI.

## Use cases
- scan servers for known CVEs without installing agents
- monitor new vulnerabilities affecting installed packages
- detect vulnerable language libraries from lock files
- audit Docker containers for security vulnerabilities
- generate regular vulnerability reports via cron
- check for processes needing restart after updates
- scan WordPress plugins and network devices for vulnerabilities

## When to choose
- you need agent-less CVE scanning across many servers via SSH
- you manage mixed fleets of Linux, FreeBSD, Windows, and macOS hosts
- you want scheduled automated vulnerability reports with Slack/email notifications
- you need to scan non-OS packages, lock files, or containers

## When to avoid
- you need in-depth SAST/DAST application security testing rather than CVE scanning
- you require a lightweight agent on each host instead of a central scanner
- your targets are non-Unix systems outside the supported OS list

## Facets
- artifact type: cli-tool
- maturity: active
- function: vulnerability-scanning, security, monitoring, alerting
- domain: security, infrastructure-as-code, self-hosted
- platform: bsd, windows, go, cli, cross-platform
- tags: vulnerability-management, agentless-scanning, cve, oval, nvd, ssh-remote-scan, container-scanning, wordpress-security, dependency-scanning, slack-notifications, reporting, devops, linux, macos, docker

## Member repositories
- future-architect/vuls (main) score 98

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:10:52.122774+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-29T17:14:14.420293+00:00, confidence not recorded.
  - readme: https://github.com/future-architect/vuls (fetched 2026-08-28T04:10:52.122774+00:00, sha af60dbd89c36)
  - homepage: https://vuls.io/ (fetched 2026-08-29T08:11:50.442614+00:00, sha d72326d97f0a)
  - site_page: https://vuls.io/docs/en/architecture-remote-local.html (fetched 2026-08-29T08:11:50.462762+00:00, sha 470f2958dd92)
  - site_page: https://vuls.io/docs/en/architecture-fast-deep.html (fetched 2026-08-29T08:11:50.464254+00:00, sha c116d8bff738)
  - site_page: https://vuls.io/docs/en/usage-scan-non-os-packages.html (fetched 2026-08-29T08:11:50.465811+00:00, sha 21ec6ac2a641)
  - site_page: https://vuls.io/docs/en/abstract.html (fetched 2026-08-29T08:11:50.452316+00:00, sha 49cca13c56fd)
  - site_page: https://vuls.io/docs/en/community.html (fetched 2026-08-29T08:11:50.454659+00:00, sha ff209c877c5e)
  - site_page: https://vuls.io/docs/en/tutorial.html (fetched 2026-08-29T08:11:50.456811+00:00, sha 8708165bbd6f)
  - site_page: https://vuls.io/docs/en/supported-os.html (fetched 2026-08-29T08:11:50.458958+00:00, sha 5ad4aaee62fb)
- Data as of 2026-08-30T08:39:29.467469+00:00.
