bountyyfi/lonkero
Lonkero - Wraps around your attack surface. Professional-grade scanner for real penetration testing. Fast. Modular. Rust. observed · 2026-08-28
Health v2 · maintenance only
73/100
- Activity 98
- Release rhythm 72
- Longevity 19
Flags: no_license
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: 1.0
- age_days: 271
- days_rel: 184
- days_push: 17
- n_releases_24m: 23
Adoption not part of the score
1047 stars · 87 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
Lonkero is a professional-grade web application security scanner written in Rust, built for real penetration testing with 125+ scan modules, context-aware intelligent mode, and ML-based false positive reduction. It detects technologies like Next.js, Django, and Laravel to test only relevant attack vectors, and includes a browser extension and proof-based XSS detection without browser dependencies.
Use cases
- scan my web app for xss vulnerabilities
- find cves in outdated javascript libraries on my site
- pentest a web application before a client engagement
- check if my api endpoints leak data they shouldn't
- test login bypass and session management weaknesses
- generate owasp top 10 and pci dss compliance reports
- detect waf and tech stack before testing a target
When to choose
- you need fast, low-false-positive web vulnerability scanning in a rust cli
- you're a security consultant doing real penetration tests with commercial reporting
- you want context-aware scanning that adapts to detected frameworks
- you need compliance-oriented reports (OWASP, PCI DSS, GDPR)
When to avoid
- you need a fully open-source tool - the license is proprietary
- you want static source code analysis rather than black-box web scanning
- you need network/infrastructure scanning beyond web applications
- you require free unlimited commercial use without a paid plan
Facets
cli-tool · maturity active
vulnerability-scanning penetration-testing security web-scraping security penetration-testing web-development developer-tools windows cli rust web-security-scanner pentesting xss-detection cve-scanning waf-detection appsec false-positive-reduction proprietary-license linux macos
3 sources
- readme: https://github.com/bountyyfi/lonkero · fetched 2026-08-28 · e97ad56e5f45
- homepage: https://lonkero.bountyy.fi/en · fetched 2026-08-29 · efc80da95b15
- registry_crates: https://crates.io/api/v1/crates/lonkero · fetched 2026-08-29 · 2cc9f5feb91e
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| bountyyfi/lonkero | main | 73 |
For agents
markdown · JSON · MCP: product_card(name="bountyyfi/lonkero")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem