
Nuclei
ProjectDiscovery’s template-driven vulnerability scanner for fast, community-powered checks across web apps, APIs, networks and cloud assets.
0 upvotes · 0 downvotes
- Pricing
- Free
- Platforms
- LinuxWindowsmacOS
- Licence
- Open source
- Reviewed
- Last reviewed 1 October 2026
What it is
Nuclei is a fast, template-driven vulnerability scanner from ProjectDiscovery. Operators describe checks as YAML templates that probe applications, APIs, infrastructure and cloud assets for known issues and misconfigurations. A large community template library and official documentation make it a common choice in modern pentest, bug bounty and DevSecOps workflows.
What it helps with
- Running community and custom YAML templates against URLs, hosts, IP ranges and other target forms.
- Covering web, network, DNS, SSL and related checks with matchers designed for low noise.
- Bulk scanning many targets with parallel execution and flexible output formats such as JSON.
- Integrating into CI/CD and regression cycles to re-test known issues.
- Extending coverage with the nuclei-templates repository and custom organisational templates.
- Combining with other ProjectDiscovery tooling for reconnaissance and HTTP probing pipelines.
Who it's for
Penetration testers, red teams, bug bounty hunters, security engineers and DevOps teams who need automated, template-based vulnerability checks on assets they are authorised to scan.
Worth knowing
Use Nuclei only on systems you are explicitly authorised to assess. Template-based scanning can still be noisy or disruptive if misconfigured. Nuclei is free under the MIT Licence; ProjectDiscovery also offers commercial cloud and enterprise options separate from the open-source engine. Official product and docs pages live under projectdiscovery.io. Attribution: framing from ProjectDiscovery Nuclei docs and the projectdiscovery/nuclei README; licence from the repository licence file.