🧰Nuclei
projectdiscovery/nuclei · homepage ↗
Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.
⭐ Very popular: 31k stars, gaining about 147 a week
View on GitHub ↗repo profile
momentum
durability
bus factor = how many people it takes to cover more than half the commits (6 months). 1 is a solo project; higher means the work is spread across a team. top-author share is the single busiest author's slice of those commits.
since we covered it
why it's a big deal
- It turns vulnerability scanning into a programmable system, where detection logic can be defined, versioned, and shared across teams.
- The open template ecosystem allows vulnerability discovery to scale through community contributions and increasingly AI-generated logic.
- By integrating into CI/CD pipelines, it shifts security from periodic checks to continuous, always-on inspection.
under the hood
- Uses a YAML-based DSL to define requests, matching logic, and validation steps for precise vulnerability detection.
- Maintains a large, community-driven template library covering CVEs, misconfigurations, and common attack vectors.
- Optimized for high-speed parallel execution across multiple protocols including HTTP, DNS, TCP, and cloud services.
our take from PR#32, 2026-04-22
star history
- PR#32 28k 2026-04-22
- now 31k + 3k since first covered
curve is sampled from GitHub's star history, plus our own daily readings since we covered it; the dashed stretch is before we first covered it, the solid line since. figures at coverage are the numbers we printed then (approx.), current count is live.
understory
Quietly building: more output than attention, for now.
- output, commits & releases
- clout, star velocity
output = commits & releases; clout = star velocity, both 0 to 100 monthly indices; the gap where output runs above clout is the understory. The understory →
covered in
-
Programmable vulnerability scanning for continuous security workflows
similar projects
compare these →- 🦉 strix
Python
Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.
53k ACTIVE - ⚿ Infisical
TypeScript
Infisical is the open-source platform for secrets, certificates, and privileged access management.
29k ACTIVE - 🕷️ PentAGI
Fully autonomous AI Agents system capable of performing complex penetration testing tasks
22k ACTIVE
comments
Sign in with GitHub to add your blip on Nuclei.