Skip to content
nerlo.ai

The scanner suite

Nerlo runs a suite of independent scanners over every artifact and publishes each verdict separately. They are shown here at one flat rank: no scanner is privileged, none can veto another, and there is no visual hierarchy between them. The composite trust score is a subordinate summary layered on top for readers who want one number — it never hides, overrides, or reranks a per-scanner verdict.

Each scanner below is one of two kinds: off-the-shelf tools we pin and run as-is, or Nerlo-original detectors we built ourselves. The kind is a provenance label, not a rank — an off-the-shelf CVE finding and a Nerlo-original behavioral finding count exactly the same.

Want the exact scoring math and how the composite is assembled? See the scoring methodology. Every scanner also publishes its source, version, and install command with each scan so you can verify its provenance yourself.