Skip to content
repository radar
Security

🧰Nuclei

ACTIVE STEADY

projectdiscovery/nuclei · homepage ↗

Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.

⭐ Very popular: 31k stars, gaining about 147 a week

View on GitHub ↗

repo profile

vintage 2020 6 years old
delivery product
language Go
license MIT

momentum

total stars 31k
stars added last week +147
binary downloads 40k total · GitHub releases
used by 2 repos & packages
commits / week 13 accelerating · +61% vs prior mo
issues closed 96% ~3d to close, median
contributors 271 (+1 in 15d)
release cadence monthly
last activity today

durability

backing VC-backed ProjectDiscovery (CRV)
openness permissive
security score 6.4/10 OpenSSF Scorecard · 2026-08-10
bus factor 2 concentrated
top-author share 33% 6 mo

bus factor = how many people it takes to cover more than half the commits (6 months). 1 is a solo project; higher means the work is spread across a team. top-author share is the single busiest author's slice of those commits.

since we covered it

monthly average + 680/mo (+2%/mo) · + 3k total since PR#32

why it's a big deal

  • It turns vulnerability scanning into a programmable system, where detection logic can be defined, versioned, and shared across teams.
  • The open template ecosystem allows vulnerability discovery to scale through community contributions and increasingly AI-generated logic.
  • By integrating into CI/CD pipelines, it shifts security from periodic checks to continuous, always-on inspection.

under the hood

  • Uses a YAML-based DSL to define requests, matching logic, and validation steps for precise vulnerability detection.
  • Maintains a large, community-driven template library covering CVEs, misconfigurations, and common attack vectors.
  • Optimized for high-speed parallel execution across multiple protocols including HTTP, DNS, TCP, and cloud services.

our take from PR#32, 2026-04-22

star history

PR#32 · 28k31k now Apr 2020Aug 2026
  1. PR#32 28k 2026-04-22
  2. now 31k + 3k since first covered

curve is sampled from GitHub's star history, plus our own daily readings since we covered it; the dashed stretch is before we first covered it, the solid line since. figures at coverage are the numbers we printed then (approx.), current count is live.

understory

Quietly building: more output than attention, for now.

+6 understory score output 72 · clout 66
Aug 2025 Jul 2026
  • output, commits & releases
  • clout, star velocity

output = commits & releases; clout = star velocity, both 0 to 100 monthly indices; the gap where output runs above clout is the understory. The understory →

covered in

  • PR#32 2026-04-22 above the radar

    Programmable vulnerability scanning for continuous security workflows

similar projects

compare these →
  • 🦉 strix

    Python

    Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

    53k ACTIVE
  • Infisical

    TypeScript

    Infisical is the open-source platform for secrets, certificates, and privileged access management.

    29k ACTIVE
  • 🕷️ PentAGI

    Fully autonomous AI Agents system capable of performing complex penetration testing tasks

    22k ACTIVE

comments

Sign in with GitHub to add your blip on Nuclei.

loading comments…