Nuclei

Windows · Mac · Linux · Self-hosted

Freedom report

Three barsScore 6.6

  • Free tierA free tier is on its own pricing page
  • Open codeNo open-source code on record
  • Runs widely3 of 6 device platforms
  • DocumentedPlans, terms and facts published

Nuclei is a free, open-source vulnerability scanner for applications, infrastructure, cloud platforms and networks. It uses YAML templates to define checks, with more than 6,500 community-contributed templates available. Users can also create custom templates, apply authentication such as HTTP basic authentication or JWT, and run bulk or parallel scans with multiple target formats and inclusion or exclusion filters. Its modules cover HTTP, DNS, TCP, headless, JavaScript, code and file checks. Nuclei can be integrated into CI/CD workflows, including through GitHub Actions, and can export SARIF results to GitHub Code Scanning. It can connect to ProjectDiscovery Cloud Platform to view scans. The tool is distributed under the MIT License and is primarily intended as a standalone command-line tool. Installation options include Go, Homebrew, Docker, GitHub, downloadable binaries and Helm. Nuclei is actively developed but has no LTS or stable version, so releases may introduce breaking changes. Some templates can fuzz or take actions that risk denial of service; these templates are tagged and excluded from default scans.

Who it is for

Nuclei names security engineers and analysts, red teams, DevOps teams, bug bounty hunters and penetration testers as users. Its templates and CI/CD integrations also suit teams automating security checks.

What is good

  • More than 6,500 community-contributed templates.
  • Users can create custom YAML templates.
  • Supports HTTP basic and JWT authentication.
  • Integrates with GitHub Actions and SARIF export.
  • MIT-licensed and free.

What to know first

  • No LTS or stable version is available.
  • Releases may introduce breaking changes.
  • Some templates can risk denial of service.
  • Primarily intended as a standalone CLI tool.

Freedom251 review

Nuclei: the full review

Nuclei offers a template-based approach to scanning across several target types, with custom checks and CI/CD integration. Its active development and potentially disruptive templates call for review of release changes and scan selections.

Overview

Nuclei is a command-line vulnerability scanner that applies YAML-defined checks to applications, infrastructure, cloud platforms and networks. It is a strong fit for security practitioners and technical teams that want configurable scans across varied targets, especially in automated workflows. Its free, open-source CLI is a meaningful advantage; its active development and the care required around scan selection make it less suitable for teams seeking a stable, managed service.

Key features

Nuclei’s template library provides more than 6,500 community-contributed checks for real-world vulnerabilities and attack vectors, and users can also write their own. Public templates are reviewed, signed and checked for non-destructive, read-only requests before distribution. That review offers a useful safeguard, but it is not a substitute for checking what a scan will do: some templates can fuzz or take actions that may cause denial of service. Those templates are tagged and excluded from default scans.

Bulk and parallel scans, multiple target formats, and inclusion and exclusion filters help teams tune coverage to their targets. Its modules span HTTP, DNS, TCP, headless, JavaScript, code and file checks; authentication options include HTTP basic authentication and JWT. This breadth suits practitioners who need more than a web-only scanner, though it also places responsibility on users to choose suitable templates and scope.

Nuclei can run in CI/CD pipelines, including with GitHub Actions, and export SARIF results to GitHub Code Scanning. That makes it practical for automated security testing and regression checks. It can also connect to ProjectDiscovery Cloud Platform to view scans, but the product is primarily a standalone CLI, and the maker warns that deploying it as a service may pose security risks.

Pricing

Nuclei CLI costs 0.00 USD per free. The plan is open-source and MIT licensed, with on-premise deployment and support for authenticated, scheduled and API scans, as well as compliance reports. For teams able to operate a command-line tool, that covers a broad range of scanning needs without a subscription charge. It does not remove the operational burden of managing scans, templates and changes.

Platforms

Nuclei supports Linux, macOS and Windows, and can be deployed on-premise or self-hosted. Installation options include Go, Homebrew, Docker, GitHub, downloadable binaries and Helm. This range gives technical teams several ways to fit it into their environments, while the CLI orientation is a poor match for users who need a conventional hosted interface.

Who it's for

Security engineers, analysts, red teams, DevOps teams, bug bounty hunters and penetration testers are the clearest fits. Teams with the skills to create or curate templates can tailor checks and automate them in pipelines. Nuclei is less appropriate for organizations that require a long-term stable release or want to operate scanning as a service: it has no LTS or stable version, breaking changes can occur, and releases generally arrive every two weeks.

Pros and cons

  • Broad, customizable coverage: More than 6,500 community templates, custom checks and modules for several protocols and target types suit varied security workflows.
  • Pipeline-ready output: GitHub Actions support and SARIF export make it easier to incorporate results into CI/CD and GitHub Code Scanning.
  • No license cost: The MIT-licensed CLI is free, with authenticated, scheduled and API scans and compliance reports included in the plan.
  • Operational care is essential: Some templates may disrupt targets, and users must select safe templates and define appropriate scope.
  • Change risk: Active development brings frequent releases and possible breaking changes, which can complicate teams that need predictable versions.
  • CLI-first deployment: The standalone design favors technical users; running it as a service may introduce security risks.

Alternatives

OWASP ZAP is another free, open-source option for teams that want a project anyone can contribute to. Wapiti is also free and open source, and may suit readers comparing another no-cost scanner. Beagle Security is worth considering for readers seeking a freemium option with a free trial and a Free plan that includes one lite test per month, monthly surface scan reports, and SSL and domain expiry monitoring.

Qualys External Attack Surface Management offers a 30-day no-cost trial of CSAM with EASM for readers who want to assess that option before buying. ZeroThreat may suit someone who wants to try a freemium service with five scan credits on sign-up, valid for 15 days, followed by one scan credit per month and one target per account. ImmuniWeb offers a monthly mobile-app scan subscription at 395.00 EUR per month per app, with unlimited scans of builds or versions of the same app.

Pentest-Tools.com API Scanner is an alternative for readers considering a freemium API scanner with a paid NetSec plan from $95/month and five assets. Burp Suite DAST is another option, with tailored pricing based on portfolio and a free trial.

Browse Web Application Security Scanners, Network Vulnerability Scanners or Vulnerability Scanning Software to compare more options.

Verdict

Choose Nuclei if your security or DevOps team wants a free, MIT-licensed scanner with broad template-based checks and CI/CD integration, and can manage scan scope and ongoing changes. Its flexibility and lack of license cost are the main reasons to choose it. Look elsewhere if you need a stable release track or a service-oriented deployment that avoids the security and maintenance responsibilities of a CLI tool.

Nuclei plans and pricing

All plans
Nuclei CLI Free Open-source CLI · MIT licensed · primarily intended as a standalone tool github.com · 4 Oct 2026

Compared on vulnerability scanning software

Free plan
Yes

Best Nuclei alternatives

See all 12