4 min read

Ultralytics YOLO: Object Detection in a Few Lines (GitHub, Scanned)

Detect, segment, track and estimate pose in images, video and webcams with pretrained YOLO models.

Ultralytics YOLO logo
✅
Scan: safe. Nothing malicious in the scanned code. Two things to know: it sends anonymous usage events to Google Analytics by default (yolo settings sync=False stops them), and in December 2024 hijacked releases on PyPI shipped a cryptocurrency miner, so pin the version you install. Scanned Oct 3, 2026; the full report is below.

Ultralytics is the Python package behind the YOLO models most people mean when they say object detection. One pip install gives you a yolo command and a Python API that load a pretrained model and find people, cars, animals and 80 everyday object classes in an image, a video file, a stream or a webcam, drawing boxes as they go. The same interface does instance and semantic segmentation, pose estimation, tracking objects across frames, image classification, oriented boxes for aerial images and, most recently, depth estimation.

It earns its place because it makes computer vision approachable: the bounding-box overlays in countless demo clips online come from a few lines of this code. Training a detector on your own labelled images is one call, and models export to ONNX, TensorRT, CoreML, OpenVINO and other formats for phones, edge boards and servers. It supports models from YOLOv3 to the current YOLO26, with YOLO27 announced as in development.

The package is made by Ultralytics and has about 62,000 stars. It is dual-licensed: AGPL-3.0 for open-source use, or a paid Ultralytics Enterprise License for commercial products that do not want to open their code.

  • Repository: github.com/ultralytics/ultralytics
  • Licence: AGPL-3.0 (GNU Affero General Public License v3.0)
  • Language: Python. Stars: 62.2K. Forks: 11.8K. Last push: Oct 3, 2026.
  • Scan: safe, Oct 3, 2026, commit 0541953

Who it is for

Developers adding detection to an app, students learning computer vision, makers building camera projects, and anyone who wants to count, track or measure things in video without training a model from scratch.

Getting started

1. Install the package (Python 3.8 or later with PyTorch)

pip install ultralytics

2. Detect objects in a sample image with the small YOLO26 model (weights download on first use)

yolo predict model=yolo26n.pt source='https://ultralytics.com/images/bus.jpg'

3. Run it live on your webcam

yolo predict model=yolo26n.pt source=0 show=True

4. Or from Python, then export the model to ONNX

from ultralytics import YOLO
model = YOLO("yolo26n.pt")
results = model("path/to/image.jpg")
results[0].show()
model.export(format="onnx")

Pretrained weights download from Ultralytics' GitHub releases the first time you name a model. Anonymous usage events are sent to Google Analytics by default; yolo settings sync=False turns them off. Pin the version you install, for the reason given in the safety notes below.

Safety scan

We cloned ultralytics/ultralytics at commit 0541953 on Oct 3, 2026 and ran the checks described on the GitHub Tools page: credential patterns, decode-and-execute code, install-time scripts, committed binaries, risky CI workflows, every host the code talks to, known vulnerabilities in pinned dependencies, and project hygiene. A person read every hit. This is what we found.

  • One secret hit: docs/en/platform/api/index.md line 2342, a placeholder "-----BEGIN PRIVATE KEY-----\n..." in an example request for connecting Google Cloud Storage; no real key. The one pattern hit, ultralytics/data/scripts/get_imagenet.sh, pipes a third-party script from soumith/imagenetloader.torch into bash to sort ImageNet validation images, and runs only if you prepare that dataset. About 203,000 lines in 1,038 files, 92,000 of them Python.
  • We read ultralytics/utils/events.py. With the sync setting on, which is the default, it posts anonymous events to Google Analytics' Measurement Protocol: task and mode, model architecture, the dataset file's name, image size and training statistics, from the main process of pip or git installs when online. yolo settings sync=False turns it off.
  • Supply-chain history: in December 2024, ultralytics 8.3.41 and 8.3.42 were published to PyPI containing an XMRig cryptocurrency miner after an attacker abused a GitHub Actions workflow injection in the project's CI; 8.3.45 and 8.3.46 followed using a leaked PyPI token. All four were removed. Nothing similar is in the code scanned here, but it is the reason to pin versions and install from PyPI deliberately.
  • 12 workflows. The only pull_request_target workflow, cla.yml, passes secrets to ultralytics/actions/cla@main without checking out pull request code. None of the 56 third-party actions, the project's own ultralytics/actions included, is pinned to a commit, so a change to those action repositories runs here immediately.
  • No lockfile: pyproject.toml declares version ranges, so there were no pinned dependencies to check against OSV. Dependabot, licence and contributing guide present; no security policy or CodeQL.

What the scanner counted

CheckResult
Secrets1 candidate found and read; see the notes above.
Suspicious code1 pattern hit found and read; every one is listed under the raw findings.
Install-time codeNone: nothing runs at install beyond the package manager itself.
Committed binariesNone.
CI workflows12 workflows. 1 uses pull_request_target, none check out the pull request head. 56 of 56 third-party actions pinned to a tag rather than a commit.
Network hosts40 distinct hosts referenced from source; most often ultralytics.com, github.com, docs.ultralytics.com, arxiv.org. No URLs to bare IP addresses.
Known vulnerabilitiesNo lockfile to check: dependencies are declared as ranges, so what gets installed is whatever is current on the day.
Project hygieneHas automated dependency updates, licence file, contributing guide. Missing security policy, CodeQL.
OpenSSF ScorecardNot scored: the project is not in Scorecard's weekly index.

The raw findings

Every hit the scanner wrote out, with a link to the exact line at the scanned commit. Secrets candidates are redacted.

Secret candidates (1, redacted)
WhereRuleMatch
docs/en/platform/api/index.md:2342private-key-----B…--- (27 chars)
Pattern hits (1)
WhereRuleMatch
ultralytics/data/scripts/get_imagenet.sh:45download-piped-to-shellwget -qO- https://raw.githubusercontent.com/soumith/imagenetloader.torch/master/valprep.sh | bash # move into subdirs
Workflows worth a look

By the numbers

Stars62.2K
Forks11.8K
Contributors466
Commits5,317
Open issues38
Open pull requests37
Releases499
Latest releasev8.4.171
LicenceAGPL-3.0
Main languagePython
Project age4 years
Last pushOct 3, 2026
Tracked files1,038
Lines of code203.3K
Checkout size10 MB

Lines by language: Python 92.3K, Markdown 89.9K, YAML 15.1K, Rust 2,020, Jupyter 1,164, C/C++ header 1,122.

Questions

Is Ultralytics YOLO free?

Under AGPL-3.0, yes, for students, researchers and open-source projects. AGPL means that if you build it into a product or a network service, you must release your own source code under the same licence. Companies that do not want to do that buy an Ultralytics Enterprise License. The pretrained models fall under the same terms.

Do I need a GPU to run YOLO?

No. The small models such as yolo26n run in real time on many laptop CPUs, especially after exporting to ONNX or OpenVINO. A GPU makes the larger models and training much faster, and an NVIDIA card with TensorRT is the fastest option for video.

Can I train YOLO on my own objects?

Yes. Label your images in YOLO format, describe the dataset in a small YAML file, and call model.train(data="your.yaml", epochs=100) or the yolo train command. Starting from a pretrained model, a few hundred labelled images per class is often enough for useful results.


This post is part of GitHub Tools, where every repository is cloned and scanned before it is written up. The scan is a snapshot of one commit on one day; the repository has moved on since, so check it before you install.