IT AI Index
Index Vendors › Nuclei · September 2026 Edition
3 categories · Named, not ranked

Nuclei

13Judge labels
0First choices
4Negative labels
7 of 12Models named it
3Categories
September 2026 Edition. Every number here is derived from the raw labels under vendor table vv2026-09.2, every buyer segment counted.
Standing
8 labels, too few to rank
A product needs 10 labels in a category before a share or quadrant is stated. Nuclei was named 8 times in Vuln management and 2 other categories, where Rapid7 InsightVM led with 45%. The labels and the evidence are below, counted exactly.
By buyer segmentRead the same way at every buyer size.
In vuln management · each standing computed within its segment · bars are 0 to 100 · the accent bar is the product's own best reading

Standing by category

Every category where a model named Nuclei for a mid-market B2B company. Share is first choices across the direct, paraphrase, budget and scale prompts; rank is within every product named in that category.
CategoryFunctionShareRankNegative rateLabelsQuadrant
Vulnerability management platformsSecurity operations0%30 of 8020%5under 10 labels · led by Rapid7 InsightVM at 45%
Attack surface managementSecurity operations0%36 of 1040%2under 10 labels · led by Intruder at 59%
Penetration testing as a serviceSecurity operations0%64 of 760%1under 10 labels · led by Cobalt at 44%

Movement

This is the first edition on this tier, so no move can be computed for Nuclei yet. From the next edition this section shows, per buyer segment, whether its share moved by more than the measured noise floor.

By model

How each model treated Nuclei across every prompt where it was named for a mid-market B2B company. Twelve models, six prompts per category.
ModelFirst choiceAlternativeMentionNegativeLabels
Claude Haiku 4.500101
GPT-5.4 mini00000
Gemini 3.5 Flash00000
Perplexity Sonar00011
Grok 4.1 Fast01001
Mistral Small00000
DeepSeek V4 Flash00101
Llama 4 Maverick00000
Qwen 3.7 Flash00000
Kimi K200101
GLM 4.7 FlashX01102
MiniMax M2.500101

By framing

Which of the six questions produced the naming. By model says how often; this says asked what. The first-choice count on the right carries the marks of the models that produced it.
FramingLabels by classFirst choices
Direct0 labelsNone
Paraphrase0 labelsNone
Comparative0 labelsNone
Budget-constrained9 labelsNone
Scale-constrained0 labelsNone
Negative4 labelsNone
First choiceAlternativeMentionNegative13 labels in all, every segment counted; 0 of the 0 first choices count toward share, since the comparative and negative framings do not. The bar is one segment per label class, to scale within the framing.

What the models said for it

Verbatim evidence the judge attached to positive labels.

“Nuclei – fast template-based scanner for known vulnerabilities” GLM 4.7 FlashX · ASM · budget prompt · alternative
“Free (open-source) | Fast CVE/misconfig scans ... No full UI.” Grok 4.1 Fast · Vuln management · budget prompt · alternative

And against it

Verbatim evidence attached to negative labels. A warning on a product with few labels is a warning; on a product with many, it is one voice among them.

“Trivy and Nuclei are noted as strong specialized tools but with limited enterprise features or centralized management” Perplexity Sonar · Vuln management · negative prompt · soft negative

Named alongside

The products named in the same answers as Nuclei, over the 13 answers that named it. Took the first choice instead counts the answers where the other product was the first choice and Nuclei was named but was not.
ProductSame answerTook the first choice insteadHead to head
OpenVAS12 of 132Not in the top three
Intruder7 of 132Not in the top three
ManageEngine Vulnerability Manager Plus4 of 133Not in the top three
Qualys4 of 131Not in the top three
Tenable4 of 131Not in the top three
NinjaOne3 of 131Not in the top three
DefectDojo3 of 130Not in the top three
OWASP Amass3 of 130Not in the top three
OWASP ZAP3 of 130Not in the top three
A head-to-head page exists where both products are in a category's top three. The other rows are the same fact without a page behind them, so they link to the product instead.

What carried it into the answer

The sites and pages cited by the answers that named Nuclei. A fact about retrieval, not a lever on the model.

Citations exist only for the models that return a source list, four of the twelve in this edition, so these counts come from 13 of the 13 answers that named Nuclei and are not a share of its labels.

Domains cited

upguard.com9
pdq.com7
attaxion.com6
vicarius.io6
axis-intelligence.com5
g2.com4
reddit.com4
sentinelone.com4
tuxcare.com4
beaglesecurity.com3

Fifty-two of the fifty-two domain citations in answers naming Nuclei came from somebody else's page.

Pages cited

Pages are listed as the models cited them.

Is this your product?

Claim this page

Claiming is free and changes nothing in the data. A claimed page shows a verified contact who is told when each edition publishes and when Nuclei's standing changes by more than the noise floor; the right to propose corrections to the vendor table, meaning names the judge wrote that should or should not read as Nuclei, applied by version and listed in the change log; and a one-line description supplied by the vendor and marked as such.

It does not get any change to labels, shares or verdicts, any preview, or any say over which quotes appear. A verification link goes to your work email; an address at nuclei.ai is approved on the spot, any other address is reviewed by hand.

Your name and company appear on the claimed page, or the company alone if you ask below. A title and a LinkedIn address appear there too if you give them, and are left off if you do not. Your email address is never published.