Ross ROSS = Recommend OSS · open-source software intelligence for agents

bountyyfi/lonkero

Lonkero - Wraps around your attack surface. Professional-grade scanner for real penetration testing. Fast. Modular. Rust. observed · 2026-08-28

github.com/bountyyfi/lonkero · homepage · Rust · NOASSERTION (other) observed · 2026-08-28

Health v2 · maintenance only

73/100

  • Activity 98
  • Release rhythm 72
  • Longevity 19

Flags: no_license

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 1.0
  • age_days: 271
  • days_rel: 184
  • days_push: 17
  • n_releases_24m: 23

Full methodology

Adoption not part of the score

1047 stars · 87 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

Lonkero is a professional-grade web application security scanner written in Rust, built for real penetration testing with 125+ scan modules, context-aware intelligent mode, and ML-based false positive reduction. It detects technologies like Next.js, Django, and Laravel to test only relevant attack vectors, and includes a browser extension and proof-based XSS detection without browser dependencies.

Use cases

  • scan my web app for xss vulnerabilities
  • find cves in outdated javascript libraries on my site
  • pentest a web application before a client engagement
  • check if my api endpoints leak data they shouldn't
  • test login bypass and session management weaknesses
  • generate owasp top 10 and pci dss compliance reports
  • detect waf and tech stack before testing a target

When to choose

  • you need fast, low-false-positive web vulnerability scanning in a rust cli
  • you're a security consultant doing real penetration tests with commercial reporting
  • you want context-aware scanning that adapts to detected frameworks
  • you need compliance-oriented reports (OWASP, PCI DSS, GDPR)

When to avoid

  • you need a fully open-source tool - the license is proprietary
  • you want static source code analysis rather than black-box web scanning
  • you need network/infrastructure scanning beyond web applications
  • you require free unlimited commercial use without a paid plan

Facets

cli-tool · maturity active

vulnerability-scanning penetration-testing security web-scraping security penetration-testing web-development developer-tools windows cli rust web-security-scanner pentesting xss-detection cve-scanning waf-detection appsec false-positive-reduction proprietary-license linux macos

3 sources

Member repositories

RepositoryRoleHealth v2
bountyyfi/lonkeromain73

For agents

markdown · JSON · MCP: product_card(name="bountyyfi/lonkero")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem