Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.
Nuclei added LLM support for non-HTTP protocols and enhanced LLM matcher inputs, broadening the tool's ability to leverage language models across protocol types. The week also included dependency updates—notably upgrading to go-github v92—and documentation refreshes to reflect the new capabilities.
Get this in your inbox every Monday →A deterministic 0–100 hygiene score — README, license, CI, tests, docs, and freshness.
Who ships this repo — author concentration and the bus factor across the last 300 mainline commits.
How welcoming this repo is to contributors — issue throughput, close time, responsiveness, and good-first-issue count.
What this project is built on — dependency count by ecosystem, the license mix, and anything worth a legal look before you adopt it.
Whether this project's CI can be trusted — pass rate, run times, flaky runs, and which workflow is the weak link.
Grounded in nuclei's README, structure, and recent commits — answers won't invent code they haven't seen.
A Monday email with what shipped, in plain English — no account needed.
Showing raw commit titles for the newest commits. Sign in to generate AI summaries.
Merge pull request #7834 from projectdiscovery/perf/functional-runtime
Merge pull request #7840 from projectdiscovery/fix/7836-fuzz-progress-total
Merge pull request #7841 from projectdiscovery/fix/7837-js-port-requests
Merge pull request #7842 from projectdiscovery/fix/7838-flow-request-count
Merge pull request #7843 from projectdiscovery/fix/7839-js-precondition-count
A floor, not a guess: counts only commits whose author, co-author trailer, or message explicitly credits an AI tool (Claude, Copilot, Cursor, aider, Codex…). Based on 30 mainline commits. Unattributed AI code isn't counted here — the full audit estimates that separately.