Skip to content

ProjectDiscovery

Security company behind the widely used open-source Nuclei vulnerability scanner, now offering a commercial cloud platform for AI-assisted pentesting and attack surface management.

Visit Website ↗ + Add to Compare
62/100Incremental Innovator

Overview

ProjectDiscovery was founded in 2020 and is headquartered in San Francisco. The company began as the team behind a suite of widely adopted open-source security tools — including the Nuclei vulnerability scanner, Subfinder, HTTPX and Naabu — that became staples of the bug bounty and offensive security research community, with Nuclei alone maintaining a library of 10,000+ community-contributed detection templates.

Building on that open-source foundation, the company now offers a commercial Cloud Platform for vulnerability scanning and attack surface management, plus a newer AI-powered pentesting and security agent product. ProjectDiscovery reports more than 100,000 security professionals using its tools and cites customers including Elastic, ConnectWise and Paddle, and the company was recognized at both the RSA Conference Innovation Sandbox and Black Hat in 2025.

Innovation Matrix Assessment

Innovation Velocity 7/10

A prolific open-source release cadence (Nuclei, Subfinder, HTTPX, Naabu) plus rapid expansion into an AI pentesting agent shows fast, community-validated product iteration.

Operational Value 6/10

Widely adopted open-source scanning tooling embedded in many security teams' existing workflows reduces friction in adopting the commercial platform built on top of it.

Market Momentum 6/10

Recognition at RSA Innovation Sandbox and Black Hat 2025, plus a reported 100,000+ tool users, indicate strong community and industry momentum, even without disclosed funding figures.

Category Disruption 5/10

Open-sourcing core scanning infrastructure and layering a commercial AI agent on top is a notable go-to-market model, though the scanning techniques themselves build on established approaches.

Real-World Efficacy 6/10

Nuclei's broad, community-vetted adoption in bug bounty and pentest workflows is a meaningful real-world efficacy signal, though this is community usage rather than a controlled benchmark.

Enduring Relevance 7/10

Open-source-backed vulnerability scanning and AI-assisted attack surface testing sit squarely in the direction the broader security tooling market is moving.

Why CISOs Should Care

ProjectDiscovery gives CISOs access to attack surface and vulnerability scanning built on the same open-source engine already trusted and battle-tested by a huge global community of independent security researchers and bug bounty hunters.

What Makes It Different

Its open-source-first model, with a massive community-contributed detection template library, differentiates ProjectDiscovery from closed, proprietary-only scanning vendors and gives its commercial platform an unusually large and transparent detection-content base.

The Matrix Verdict

62/100 — INCREMENTAL INNOVATOR

A technically well-regarded company with genuine grassroots credibility from its open-source tools, now converting that community trust into a commercial AI-assisted attack surface and pentesting platform; strong technical reputation, still building out enterprise commercial scale.

Editorial Note: Claims vs. Verified Findings

User counts, customer names and award recognition are drawn from ProjectDiscovery's own site; specific funding details could not be independently verified in this research pass and are marked undisclosed.

Sources