Skip to content
NucleiSecurity Center

Vulnerability scanning, without the enterprise price.

Open source and free to run. Small security teams often do not have the budget for expensive vulnerability scanners and platforms. Nuclei Security Center lets you deploy a vulnerability scanner on battle-proven Nuclei. It gives you everything you need to triage findings and escalate them to the people who can fix them.

Findings · dark mode
Nuclei Security Center findings page with a populated results table in dark mode.
Populated Findings from a honey.scanme.sh full-catalog scan.

Nuclei already scans. This is the rest of the program.

The scanner is disposable and credential-less. The backend is what a team actually operates: a finding lifecycle, fail-closed scope, OIDC, and an audit trail.

Tenable-style finding lifecycle

Dedup, evidence-driven detection state (new, active, resurfaced, mitigated), and analyst dispositions: accept-risk, false-positive, recast.

Scope guardrail

Every scan stays inside approved targets. The guardrail matches before dispatch and fails closed. No approved targets, no scan.

OIDC / BFF auth

Access and refresh tokens stay on the server. The browser holds an httpOnly session cookie. RBAC is enforced on every mutating endpoint.

Policies, schedules, discovery

Define targets and template sets, run on demand or on a cron schedule, and use naabu for port discovery before Nuclei.

Exports that fit the rest of the stack

Findings as JSON, CSV, SARIF, or raw JSONL. Complete scans import/export as versioned scan bundles (JSON or zip).

Scanner nodes hold no database credentials

Backend is the system of record. Scanner nodes run nuclei, serve results over HTTP, and are reachable only backend → node.

Architecture

Traffic is strictly backend to scanner. Raw scanner output archives to S3-compatible object storage. Every mutating call is a structured audit event.

Browser

React SPA, session cookie, roles

Served by the backend at the site root. The SPA talks to the session-authenticated API.

Backend

System of record

Postgres, OIDC/BFF, dispatch, ingestion, audit log, scope guardrail.

Scanner node

Credential-less nuclei runner

Pinned nuclei + naabu on UBI 10 Micro. No database credentials.

Designed with security in mind.

Finding data is some of the most sensitive information a security team holds. Nuclei Security Center is built so that data stays in the system of record, not on a scanner, and so a small team can run it without giving up the controls they would expect from an expensive platform. The project is scanned and reviewed regularly. Report issues privately through GitHub.

Credential-less scanners and mTLS

Scanner nodes hold no database credentials and never call the backend. Traffic is backend to node only. On an untrusted segment you can require TLS and mutual TLS so a stolen node cannot impersonate the backend.

Tokens stay off the browser

OIDC runs as a BFF. Access and refresh tokens never reach JavaScript. The browser holds an httpOnly session cookie, RBAC is enforced on every mutating call, and cookie-authenticated changes must match the application origin.

Fail-closed scope and an audit trail

Scans are rejected unless the target is already approved. Every mutation is a structured audit event to stdout, off the application database, for the log aggregator you already run.

Regular scanning and review

The project is scanned and reviewed regularly, and security fixes land on the latest main and the newest tagged release. Use GitHub private vulnerability reporting rather than a public issue.

Report a vulnerability

Get it

Run it locally with Docker Compose, or pull the published backend and scanner images from GitHub Container Registry. Images are built for both amd64 and arm64, and every release tag publishes a matching pair.

Only scan systems you own or are explicitly authorised to test. Scanning other systems without permission can be a criminal offence, including in Germany under §§ 202a–202c StGB.