ProjectDiscovery

Application SecurityCloud SecuritySecurity Operations also known as ProjectDiscovery, Inc.

Market readinessHow well the company can compete in its security market, scored across eight dimensions against public evidence. Established: Market readiness of 25 to 30, the typical band where most analyzed companies land.
DefensibilityHow well the company holds its position if competitors catch up on features, scored across seven dimensions against public evidence. Exposed: Defensibility of 12 or below. The position is exposed as AI lowers the cost of building commodity software.
Founded 2020
Last updated 2026-09-11

All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.

Executive Summary

ProjectDiscovery sells security testing software to security teams, from individual practitioners to enterprises. Founded in 2020, it created Nuclei, an open-source scanner that finds exploitable flaws in applications, APIs, networks, and cloud. It sells a hosted platform built on Nuclei. Neo, its AI-powered product, runs penetration tests on its own and went on general sale in August 2026, pay-as-you-go from $250. The company raised a $25 million Series A led by CRV in 2023, and its named customers are ConnectWise, Elastic, and Paddle. It won the RSA Conference's Innovation Sandbox startup contest. More than 900 contributors add to its open-source tools, including the 10,000-plus detection templates Nuclei runs. A rival building a competing scanner would have to match that participation.

Sourced Details

Description Open-source-first security testing company whose Nuclei scanner and community-curated detection templates find exploitable vulnerabilities in applications, APIs, code, networks, and cloud, now sold alongside Neo, which automates offensive testing for security teams. [f1]
Founded 2020 [f2]
HQ San Francisco, California, USA [f2]
Latest funding Series A, $25M (August 2023), led by CRV [f3]

Products

Product What it does
Nuclei Fast, customizable open-source vulnerability scanner built on a YAML-based DSL, with a community-maintained detection-template library across apps, APIs, networks, DNS, and cloud configurations.
ProjectDiscovery Cloud Platform Managed SaaS built on the open-source tools for attack surface management, application and API pentesting, code and PR review, and vulnerability triage, priced by credits.
Neo Platform of autonomous agents that run offensive testing across code, applications, APIs, networks, and cloud, confirm which findings are exploitable, and retest fixes, on published pricing.

Matrix Coverage

Cyber Defense Matrix

IdentifyProtectDetectRespondRecover
Devices Workstations, servers, phones, tablets, storage, network devices, IoT infrastructure, and similar hardware.
Applications Software, interactions, and application flows on the devices.
Networks Connections and traffic flowing among devices and apps, plus communication paths.
Data Content at rest, in transit, or in use across devices, apps, and networks.
Users The people using the devices, apps, networks, and data.

Nuclei, the cloud platform, and the Neo agents discover internet-facing assets and detect exploitable vulnerabilities in conventional web apps, APIs, networks, and cloud, so the company is mapped to the Cyber Defense Matrix. [f1]

Market Readiness

How well the company can compete in its security market, scored across eight dimensions against public evidence.

Established 27 /40 Established: Market readiness of 25 to 30, the typical band where most analyzed companies land.
Dimension Score Rationale
Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. 3/5 ProjectDiscovery names the buyer, security teams triaging scanner output, and the pain, version-check noise instead of exploitable findings, but that framing comes from the company's own conference blog post. The cited non-vendor sources confirm the contest win and the scanner's reach without quantifying the false-positive burden. [s17, s13, s8]
Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. 4/5 The engine and its 10,000-plus detection templates are public and MIT-licensed, so a buyer can read the detection logic, and outside researchers work on that code directly: a Wiz research post and the National Vulnerability Database record for CVE-2024-43405 document a signature-verification bypass fixed in Nuclei 3.3.2. Neo's agent results stay vendor-reported. [s2, s3, s9, s11, s12]
Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. 3/5 No independently documented buyer-side demand signal appears in the cited record: the 2025 RSAC Innovation Sandbox win is a judging panel's award rather than evidence of buyers purchasing, and the August 2026 Neo launch is the company's own. Timing is plausible on a credible enabler, agent-driven offensive tooling becoming sellable as a continuous service, which the company dated by shipping Neo v1 in 2026. No analyst category note, procurement record or regulatory driver appears in the cited sources. [s6, s8, s17]
Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. 4/5 The founders shipped a plural set of named in-domain builds, Nuclei alongside the Subfinder, httpx and Naabu tools, and that standing is corroborated outside the company: articles at BleepingComputer and The Hacker News introduce Nuclei as a popular and widely used open-source scanner, and the engine repository carries 30,900 stars. The cited record still shows no prior exit. [s7, s6, s14, s2, s9, s10]
GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. 3/5 Three published customer accounts name Elastic, ConnectWise and Paddle, and two of them quote a named security leader running the commercial platform. All three are the company's own accounts and no independent source confirms customer count, revenue or deployment scale, so the traction is documented by the vendor and not corroborated outside it. [s15, s16, s7, s1]
Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. 3/5 A 25 million dollar Series A led by CRV in 2023 and a 1.7 million dollar seed in early 2021 are the rounds the cited record carries, and shipping since is visible in Neo's 2026 general availability. The cited sources disclose no revenue, margin or growth-efficiency figure, so output per dollar is unconfirmed. [s7, s14, s6]
Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. 4/5 Parties outside the company place it without coaching: an NSFOCUS analysis files it under attack surface management, RSA Conference selected it in a 2025 startup contest for finding and fixing vulnerabilities, and a BleepingComputer article introduces Nuclei as a vulnerability scanner. Those are recognitions rather than an analyst firm naming a category around the company. [s13, s8, s9]
Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. 3/5 Contributor participation across a 10,000-plus template library and pipeline integration create friction an incumbent would have to work through. The engine and the library are both MIT-licensed and public with thousands of forks on record, and the cited sources evidence no vendor-retained data asset beyond the per-customer history the platform keeps, so the friction is short of a structural moat. [s3, s2, s1, s15]
Business Risks Tenable, Qualys or a cloud-security platform could bundle exploitable-vulnerability detection and attack surface management, taking the conventional half of the offer…
  • Tenable, Qualys or a cloud-security platform could bundle exploitable-vulnerability detection and attack surface management, taking the conventional half of the offer.
  • Nuclei and its template library are MIT-licensed with thousands of forks on record, so a rival could ship a competing scanner built on the same public detection content.
  • Neo's results are vendor-reported, and a buyer evaluation that failed to reproduce them would undercut the product the company now leads with.
  • The cited record carries no priced round after the 2023 Series A and does not establish the company's current capital, so a new raise or its continued absence would change what it can sustain in the autonomous-testing contest.
  • The template trust model already failed once, as CVE-2024-43405, and a further bypass would land on the open-source asset the commercial platform is built on.
  • Contribution to the public template library could slow as attention moves to Neo, weakening the participation that raises a rival's effort.
Problem & Market ProjectDiscovery names the buyer and the pain in one line: security teams that chase noise from version-checking scanners instead of the issues an attacker can actually reach…

ProjectDiscovery names the buyer and the pain in one line: security teams that chase noise from version-checking scanners instead of the issues an attacker can actually reach. Its chief operating officer argued that case from the RSAC stage, naming Tenable and Qualys as scanners built more than twenty years ago that overwhelm teams with false positives.

That framing comes from the company. The cited non-vendor sources confirm that RSA Conference selected ProjectDiscovery as its 2025 Innovation Sandbox winner for open-source vulnerability tooling, and an NSFOCUS analysis files the company under attack surface management, but neither quantifies the false-positive burden it sells against.

The market itself is established. The cited record names Tenable and Qualys as the incumbents the company sells against, so the company competes on how findings are produced rather than on opening a category. [s17, s8, s13]

Product Capabilities Nuclei is the foundation and it is readable by anyone…

Nuclei is the foundation and it is readable by anyone. The scanner runs YAML templates with conditional logic that emulate how an attacker probes a target, its repository carries 30,900 stars under the MIT license, and the separate template repository holds more than 10,000 community-curated detections across applications, APIs, networks, DNS and cloud configuration.

Neo is the commercial layer the company now leads with. It reached general availability in August 2026 and runs autonomous offensive testing across code, web applications, APIs, networks and cloud, validates which findings can be reached and abused, and connects to GitHub, Jira, Slack and Linear. The homepage adds that each run carries context forward, so dismissed false positives stay dismissed.

Outside parties work on the open half directly, which is the strongest capability evidence here. Wiz engineers found a signature-verification bypass in Nuclei's template trust model, recorded on the National Vulnerability Database as CVE-2024-43405 at high severity and fixed in version 3.3.2. Neo's own results are vendor-reported, and the cited sources carry no independent evaluation of the agents, so a buyer cannot check the agent claims against an outside test. [s1, s2, s3, s6, s11, s12, s17]

Competitive Positioning The company positions against legacy scanners by name, and its own case study records that comparison going its way: ProjectDiscovery writes that ConnectWise selected it over Tenable Cloud for community-driven agility…

The company positions against legacy scanners by name, and its own case study records that comparison going its way: ProjectDiscovery writes that ConnectWise selected it over Tenable Cloud for community-driven agility. Buyers can place the product in the vulnerability management and attack surface management budget line without coaching.

The community template library is what a competitor would have to match, and it is public. Both the engine and the template collection carry the MIT license and thousands of forks, so a rival could build on the same detection content. What it could not immediately obtain is the 900-plus contributors advancing its open-source coverage.

Neo moves the contest to autonomous testing, a newer market for the company, and the cited sources evidence no vendor-retained asset behind it. The scanning ground the company already holds is where its evidence is strongest. [s15, s3, s2, s6, s1]

Go-to-Market & Traction Adoption starts free and wide…

Adoption starts free and wide. The company counts more than 100,000 security professionals in its community, 900-plus contributors advancing its open-source coverage, and more than two billion monthly scans across its open-source tools, and the Neo launch release repeats the 100,000 figure for the toolchain overall.

The paid motion now carries named references. A published case study quotes Clement Fouque, Principal Information Security Analyst at Elastic, describing ProjectDiscovery Cloud as the piece that let the team scale Nuclei across its environment, and a second quotes Jason Ferguson, Senior Director of Security Operations at ConnectWise, whose team runs the Enterprise tier across 63 AWS accounts. The homepage carries a third customer account, Paddle, without naming the plan it runs.

All three accounts are the company's own. No independent source in the cited record confirms customer count, revenue or deployment scale. The five million dollar investment that came with the 2025 RSAC contest went to each of the ten finalists rather than to the winner alone, so it sizes the contest rather than this company's traction. [s1, s16, s15, s6, s8]

Team & Credibility The founders' credential is the toolchain they shipped…

The founders' credential is the toolchain they shipped. Rishiraj Sharma is named as co-founder and chief executive in the Series A announcement, an interview records seven years as a security engineer before he started the company, and the Series A release describes ProjectDiscovery as the work of four cybersecurity engineers who wanted asset discovery and scanning automated.

That standing is visible outside the company's own pages. Articles at BleepingComputer and The Hacker News introduce Nuclei as a popular and widely used open-source vulnerability scanner, the engine repository carries 30,900 stars, and an outside security firm spent engineering time auditing the template trust model.

What the cited record does not show is a prior exit or a sustained research-publication record. The credibility on file is sustained open-source standing in exactly the domain the company sells into. [s7, s14, s9, s10, s2]

Trust Readiness The company publishes a trust center on SafeBase at security.projectdiscovery.io…

The company publishes a trust center on SafeBase at security.projectdiscovery.io. It lists a SOC 2 Type 2 attestation and the UK extension to the EU-US Data Privacy Framework, and keeps the SOC 2 Type 2 report and a penetration-test report behind an access request. A bug bounty program is listed alongside them.

The enterprise plan lists the controls a regulated buyer asks for, including single sign-on and SAML provisioning, bring-your-own-key, dedicated network isolation with static egress addresses, and organization-level spend caps. Those are features the company sells rather than attestations it holds.

Inspectability is the other half of the trust story and it runs both ways. A practitioner can read exactly how a detection works, and the same openness let Wiz engineers show that the check meant to prove a template was untampered could be bypassed before version 3.3.2 closed it. [s5, s4, s12]

Competitors Tenable, Rapid7…
Company Relationship Note Compare
Tenable competes with N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable.
Rapid7 competes with N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable.

Add analyzed competitors to compare them side by side with ProjectDiscovery.

Strategy Deep Dive

A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.

Defensibility

Exposed 12 /21 Exposed: Defensibility of 12 or below. The position is exposed as AI lowers the cost of building commodity software. pivot urgently

Two things here raise a rival's effort. The attacker-emulation engine behind Nuclei is real offensive-security work, and 900-plus contributors advance its open-source coverage. Both are a head start rather than a lasting lead. The engine and the template library are published under the MIT license with thousands of copies already forked on GitHub, so what a rival cannot immediately get is the participation, not the code. The published assurance is a SOC 2 Type 2 attestation, and the cited record shows no mandate or retained liability that would block a replacement. Paid adoption starts on a published 250-dollar plan with no sales conversation, and the cited sources evidence no data the company keeps to itself.

Dimension Score Rationale
Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. 1/3 The company sells software the customer connects and runs, the scanner, the hosted platform and the Neo agents, and the customer's team owns the outcome. Autonomous testing and exploitability validation are software output rather than a service layer that accepts accountability.
Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. 2/3 Template tuning, pipeline wiring and cloud integrations are meaningful friction, and leaving costs the work of reassembling that scanning setup rather than breaking any production path. The engine and templates are MIT-licensed and portable, and the cited record does not size the migration, so the friction stays at the integration level.
Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. 1/3 The trust center lists a SOC 2 Type 2 attestation and the UK extension to the EU-US Data Privacy Framework, both of which a funded competitor obtains through ordinary enterprise preparation. The cited record carries no mandate, authorization or retained liability that would block a replacement.
Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. 3/3 Detection scenarios written to mimic real-world conditions, autonomous testing that validates which findings can be reached and abused, and a signing scheme for third-party detection content are analysis-heavy offensive engineering rather than assembly of commodity parts. The signing bypass researchers found shows how exacting that work is.
Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. 2/3 A free open-source tier and a published 250-dollar starting price let a team adopt without a procurement review, while the enterprise plan reaches named accounts such as ConnectWise. The cited record therefore shows a buyer band spanning self-serve practitioners and gated enterprises rather than the regulated buyer alone.
Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. 2/3 The product is application and network security tooling that teams adopt and run beside their systems, reporting findings into pipelines and ticketing, rather than infrastructure their traffic is forced through. The engine is embeddable, and the cited record does not show applications depending on it while they run.
Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. 1/3 The detection library is the accumulated asset, and the cited record shows it published: the template repository is public and MIT-licensed with 3,600 forks, and the community curates it. The cited sources name no vendor-retained dataset, content license or granted patent behind the platform.
Strategic Market Segmentation ProjectDiscovery reaches two buyers through one community…

ProjectDiscovery reaches two buyers through one community. The free open-source tools serve security practitioners directly, and the paid platform is positioned to convert teams that already run the scanner.

The published price now defines the entry point rather than a sales conversation. Neo's pay-as-you-go plan starts at 250 dollars for 50 credits per seat with five-dollar top-ups and no minimum commitment, and the launch release frames that as removing the budget approvals and contract negotiation that kept advanced testing inside well-funded teams. The enterprise plan adds unlimited seats, invoiced billing and reseller routes.

The newest segment is the team that wants testing to run continuously. Neo extends the same security or engineering organization to whoever owns pull-request review and release testing, rather than cultivating a separate market.

Product Capabilities & AI Advantages The core capability is attacker-style detection…

The core capability is attacker-style detection. Nuclei runs a YAML template language that lets a team design detection scenarios mimicking real-world conditions, backed by a community-curated library of more than 10,000 detections across applications, APIs, networks, DNS and cloud configuration.

The AI layer is Neo, which runs autonomous offensive testing across code, web applications, APIs, networks and cloud, and validates which findings can be reached and abused before reporting them. The company reached general availability in August 2026 after more than six months of private beta with enterprise customers.

Outside attention has concentrated on the established engine. The open code and the public template library let a buyer inspect the detection logic, and independent researchers examined the engine closely enough to find and report a signing bypass recorded as CVE-2024-43405. The cited sources carry no independent evaluation of the agents.

Sales Engagement & Go-to-Market Go-to-market runs bottom-up from the open-source community…

Go-to-market runs bottom-up from the open-source community. The company counts more than 100,000 security professionals and 900-plus contributors, and more than two billion monthly scans run across its open-source tools, and the company positions the paid platform as the enterprise version of those same tools.

The paid motion now has named voices. Elastic's Principal Information Security Analyst is quoted describing ProjectDiscovery Cloud as the piece that let the team scale Nuclei across its environment, and ConnectWise's Senior Director of Security Operations is quoted on the Enterprise tier, where the account records scan times falling from two days to fifteen minutes for 10,000 assets.

The evidence stays inside the company's own publishing. Both accounts are vendor case studies, and no independent source in the cited record reports customer numbers, revenue or renewal behavior, so the free footprint is far better documented than the revenue it is meant to convert into.

Pricing Model ProjectDiscovery sells Neo by the credit…

ProjectDiscovery sells Neo by the credit. Pay-as-you-go starts at 250 dollars for 50 credits per seat with top-ups at five dollars a credit, and the pricing page publishes what workflows consume: a full application pentest runs 25 to 75 credits at standard reasoning and 50 to 300 at maximum.

Publishing both a starting price and a consumption table fits the open-source-first identity, and the cited record does not document how rival products price. The launch release makes the argument explicit, framing annual engagements and enterprise minimums as the gate the model removes.

The enterprise plan moves to a quote and adds volume credit discounts, unlimited seats, invoiced billing and marketplace or reseller purchase routes. The two-tier structure lets one product serve a self-serve practitioner and a negotiated enterprise deal without repricing the core.

Product Delivery & Operations Delivery spans an open-source command-line scanner, a hosted platform and an agent layer…

Delivery spans an open-source command-line scanner, a hosted platform and an agent layer. A practitioner can install and run Nuclei locally from its repository, while the paid platform delivers attack surface management, pentesting and triage as a service, with a dedicated virtual private cloud and static egress addresses for buyers that need network isolation.

Neo adds an operating layer that runs on its own. It tests continuously across pull requests and releases, connects to GitHub, Jira, Confluence, Slack and Linear, and can reach internal applications over VPN or SSH with 1Password handling credentials.

The mixed model carries an operating tension. The open-source layer needs community maintenance of the template library, while the agent layer needs the reliability and safety controls of software acting against live systems under customer credentials, which are two different disciplines under one roof.

Earning Customers' Trust The clearest trust asset is inspectability…

The clearest trust asset is inspectability. The engine and the detection templates are open source, so a practitioner can read exactly how a finding was produced before acting on it.

Formal assurance is published and gated. The trust center on SafeBase lists a SOC 2 Type 2 attestation and the UK extension to the EU-US Data Privacy Framework, runs a bug bounty program, and keeps the SOC 2 report and a penetration-test report behind an access request. The enterprise plan sells the controls a regulated buyer expects rather than attesting to them.

Openness cuts both ways, which matters more now that agents act against customer systems. The signing check meant to prove a template was untampered was bypassable until Nuclei 3.3.2, and it was outside researchers who found that and reported it.

Platform Strategy & Ecosystem Positioning The ecosystem is the company's strongest structural asset and its most public one…

The ecosystem is the company's strongest structural asset and its most public one. More than 900 contributors feed a library of over 10,000 detection templates, a participation loop the company did not ship as software.

The platform sits where security and engineering teams already work. The pricing page lists GitHub and Slack applications and integrations with AWS, GCP, Azure, Cloudflare and Vercel, and Neo adds Jira, Confluence, Linear, webhooks and Model Context Protocol connections.

The openness runs the other way too. Both the engine and the template repository are MIT-licensed and publicly forkable, with 3,800 and 3,600 forks recorded, so the same openness that built the community lets a rival reuse the format or fork the engine. The ecosystem holds while contributors keep choosing this home.

Team & Execution Capability The founders built their reputation in offensive security through the tools they shipped…

The founders built their reputation in offensive security through the tools they shipped. Rishiraj Sharma is named as co-founder and chief executive in the Series A announcement, an interview records seven years as a security engineer before he started the company, and the Series A release describes four cybersecurity engineers behind the original tools.

The distinctive credential is sustained open-source standing rather than a prior exit. Articles at BleepingComputer introduce Nuclei as a popular open-source vulnerability scanner, and the engine repository carries 30,900 stars under active maintenance.

The cited record shows no prior exit and no sustained research-publication record, and the investor roster behind the Series A adds an indirect endorsement rather than direct evidence of the team's depth.

Sources

Company Detail Sources (3)
Id Source Tier Accessed
f1 ProjectDiscovery: homepage official 2026-08-28
f2 NSFOCUS: RSAC 2025 Innovation Sandbox analysis of ProjectDiscovery research 2026-08-28
f3 PR Newswire: ProjectDiscovery announces a Series A and the Cloud Platform launch press 2026-08-28
Profile Analysis Sources (17)
Id Source Tier Accessed
s1 ProjectDiscovery: homepage
“From the creators of Nuclei. Trusted by more than 100,000 security professionals.”
official 2026-08-28
s2 GitHub: projectdiscovery/nuclei repository
“Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet.”
official 2026-08-28
s3 GitHub: projectdiscovery/nuclei-templates repository
“Community curated list of templates for the nuclei engine to find security vulnerabilities in applications.”
official 2026-08-28
s4 ProjectDiscovery: pricing page
“Advanced security testing, accessible to all.”
official 2026-08-28
s5 ProjectDiscovery: trust center hosted on SafeBase
“The Trust Center provides direct insight into our security practices, policies, and compliance measures. Here, you can explore how we safeguard information and request access to detailed resources such as audit reports and penetration test results.”
official 2026-08-28
s6 PR Newswire: ProjectDiscovery announces Neo v1 general availability
“today announced the general availability of Neo v1, its AI-powered offensive security platform, alongside a new pay-as-you-go pricing model. Neo is now available to every team, from individual practitioners and startups to enterprise security organizations, with no minimum commitment.”
press 2026-08-28
s7 PR Newswire: ProjectDiscovery announces a Series A and the Cloud Platform launch
“today announced that it has raised $25 million in a Series A financing round led by CRV, with participation from Point72 Ventures, SignalFire, Rain Capital, Mango Capital, Accel, Lightspeed, Guillermo Rauch , Caleb Sima and Talha Tariq , among others.”
press 2026-08-28
s8 PR Newswire: RSA Conference names ProjectDiscovery the RSAC 2025 Innovation Sandbox winner
“today announced that ProjectDiscovery has been named the winner of the 20th annual RSAC™ Innovation Sandbox contest”
press 2026-08-28
s9 BleepingComputer: Nuclei flaw lets malicious templates bypass signature verification
“Nuclei is a popular open-source vulnerability scanner created by ProjectDiscovery that scans websites for vulnerabilities and other weaknesses.”
press 2026-08-28
s10 The Hacker News: Researchers uncover Nuclei vulnerability enabling signature bypass
“A high-severity security flaw has been disclosed in ProjectDiscovery's Nuclei , a widely-used open-source vulnerability scanner that, if successfully exploited, could allow attackers to bypass signature checks and potentially execute malicious code.”
press 2026-08-28
s11 NVD: CVE-2024-43405 vulnerability record
“SDK Users are affected if they are developers integrating Nuclei into their platforms, particularly if they permit the execution of custom code templates by end-users.”
regulatory 2026-08-28
s12 Wiz: research post on a Nuclei signature verification bypass
“Wiz's engineering team discovered a high-severity signature verification bypass in Nuclei, one of the most popular open-source security tools, which could potentially lead to arbitrary code execution.”
research 2026-08-28
s13 NSFOCUS: RSAC 2025 Innovation Sandbox analysis of ProjectDiscovery
“Founded in 2020, ProjectDiscovery is a cybersecurity company focusing on attack surface management (ASM) and headquartered in San Francisco, USA.”
research 2026-08-28
s14 Andrew Askins: interview with ProjectDiscovery co-founder Rishi Sharma
“In early 2021, they raised a $1.7 million seed round to build out their community-edition Attack Surface Management tool.”
press 2026-08-28
s15 ProjectDiscovery blog: ConnectWise case study
“Before implementing ProjectDiscovery's Enterprise tier , ConnectWise's security team faced significant scalability challenges with their previous solution.”
official 2026-08-28
s16 ProjectDiscovery blog: Elastic case study
“"We were already invested in Nuclei. ProjectDiscovery Cloud was the missing piece that let us scale it seamlessly across our environment," said Clement Fouque, Principal Information Security Analyst at Elastic.”
official 2026-08-28
s17 ProjectDiscovery blog: Solving Vulnerability Management, the RSA Innovation Sandbox win
“Legacy scanners like Tenable and Qualys, built over 20 years ago, haven't evolved to detect today's security risks. They generate tons of noise due to outdated, primitive version checks that overwhelm security teams with false positives.”
official 2026-08-28
Deep-Dive Sources (12)
Id Source Tier Accessed
s1 ProjectDiscovery: homepage
“From the creators of Nuclei. Trusted by more than 100,000 security professionals.”
official 2026-08-28
s2 GitHub: projectdiscovery/nuclei repository
“Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet.”
official 2026-08-28
s3 GitHub: projectdiscovery/nuclei-templates repository
“Community curated list of templates for the nuclei engine to find security vulnerabilities in applications.”
official 2026-08-28
s4 ProjectDiscovery: pricing page
“Advanced security testing, accessible to all.”
official 2026-08-28
s5 ProjectDiscovery: trust center hosted on SafeBase
“The Trust Center provides direct insight into our security practices, policies, and compliance measures. Here, you can explore how we safeguard information and request access to detailed resources such as audit reports and penetration test results.”
official 2026-08-28
s6 PR Newswire: ProjectDiscovery announces Neo v1 general availability
“today announced the general availability of Neo v1, its AI-powered offensive security platform, alongside a new pay-as-you-go pricing model. Neo is now available to every team, from individual practitioners and startups to enterprise security organizations, with no minimum commitment.”
press 2026-08-28
s7 PR Newswire: ProjectDiscovery announces a Series A and the Cloud Platform launch
“today announced that it has raised $25 million in a Series A financing round led by CRV, with participation from Point72 Ventures, SignalFire, Rain Capital, Mango Capital, Accel, Lightspeed, Guillermo Rauch , Caleb Sima and Talha Tariq , among others.”
press 2026-08-28
s9 BleepingComputer: Nuclei flaw lets malicious templates bypass signature verification
“Nuclei is a popular open-source vulnerability scanner created by ProjectDiscovery that scans websites for vulnerabilities and other weaknesses.”
press 2026-08-28
s11 NVD: CVE-2024-43405 vulnerability record
“SDK Users are affected if they are developers integrating Nuclei into their platforms, particularly if they permit the execution of custom code templates by end-users.”
regulatory 2026-08-28
s14 Andrew Askins: interview with ProjectDiscovery co-founder Rishi Sharma
“In early 2021, they raised a $1.7 million seed round to build out their community-edition Attack Surface Management tool.”
press 2026-08-28
s15 ProjectDiscovery blog: ConnectWise case study
“Before implementing ProjectDiscovery's Enterprise tier , ConnectWise's security team faced significant scalability challenges with their previous solution.”
official 2026-08-28
s16 ProjectDiscovery blog: Elastic case study
“"We were already invested in Nuclei. ProjectDiscovery Cloud was the missing piece that let us scale it seamlessly across our environment," said Clement Fouque, Principal Information Security Analyst at Elastic.”
official 2026-08-28

Disclaimer

This content is provided "as is" with no warranties.

This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.

The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.

Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.

The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.

To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.

Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.

Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.