# bountyyfi/lonkero

Lonkero - Wraps around your attack surface.  Professional-grade scanner for real penetration testing. Fast. Modular. Rust.

Repository: https://github.com/bountyyfi/lonkero
Canonical: https://ross.abutalabs.com/products/lonkero
Homepage: https://lonkero.bountyy.fi/en
Language: Rust
License: NOASSERTION
License Family: other
Topics: cve-scanning, pentesting-tools, rust, vulnerability-scanners, websecurity, appsec, cybersecurity, offensive-security, pentesting, security-automation, security-tools, vulnerability-assessment, web-application-security, web-pentest, web-security, webscanner, hackers, security, waf, xss
Last push: 2026-08-16T06:35:30+00:00

## Health v2 (maintenance only)
Score: 73/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 98, release rhythm 72, longevity 19
- inputs: {"age_days": 271, "days_push": 17, "days_rel": 184, "gap_med": 1.0, "n_releases_24m": 23}
- flags: no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1047, forks 87 (observed 2026-08-28T04:03:22.107910+00:00)

## What it is
Lonkero is a professional-grade web application security scanner written in Rust, built for real penetration testing with 125+ scan modules, context-aware intelligent mode, and ML-based false positive reduction. It detects technologies like Next.js, Django, and Laravel to test only relevant attack vectors, and includes a browser extension and proof-based XSS detection without browser dependencies.

## Use cases
- scan my web app for xss vulnerabilities
- find cves in outdated javascript libraries on my site
- pentest a web application before a client engagement
- check if my api endpoints leak data they shouldn't
- test login bypass and session management weaknesses
- generate owasp top 10 and pci dss compliance reports
- detect waf and tech stack before testing a target

## When to choose
- you need fast, low-false-positive web vulnerability scanning in a rust cli
- you're a security consultant doing real penetration tests with commercial reporting
- you want context-aware scanning that adapts to detected frameworks
- you need compliance-oriented reports (OWASP, PCI DSS, GDPR)

## When to avoid
- you need a fully open-source tool - the license is proprietary
- you want static source code analysis rather than black-box web scanning
- you need network/infrastructure scanning beyond web applications
- you require free unlimited commercial use without a paid plan

## Facets
- artifact type: cli-tool
- maturity: active
- function: vulnerability-scanning, penetration-testing, security, web-scraping
- domain: security, penetration-testing, web-development, developer-tools
- platform: windows, cli, rust
- tags: web-security-scanner, pentesting, xss-detection, cve-scanning, waf-detection, appsec, false-positive-reduction, proprietary-license, linux, macos

## Member repositories
- bountyyfi/lonkero (main) score 73

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:03:22.107910+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T07:01:05.702085+00:00, confidence not recorded.
  - readme: https://github.com/bountyyfi/lonkero (fetched 2026-08-28T04:03:22.107910+00:00, sha e97ad56e5f45)
  - homepage: https://lonkero.bountyy.fi/en (fetched 2026-08-29T13:02:22.349408+00:00, sha efc80da95b15)
  - registry_crates: https://crates.io/api/v1/crates/lonkero (fetched 2026-08-29T13:02:22.358865+00:00, sha 2cc9f5feb91e)
- Data as of 2026-08-30T08:39:29.467469+00:00.
