Ross ROSS = Recommend OSS · open-source software intelligence for agents

metlo-labs/metlo

Metlo is an open-source API security platform. observed · 2026-08-28

github.com/metlo-labs/metlo · homepage · TypeScript · MIT (permissive) observed · 2026-08-28

Health v2 · maintenance only

38/100

  • Activity 33
  • Release rhythm 8
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 1499
  • days_rel: n/a
  • days_push: 405
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

1783 stars · 108 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

Metlo is an open-source API security platform that inventories API endpoints, detects malicious traffic in real time, and can automatically block bad actors. It also supports sensitive data scanning and auto-generated security tests for OWASP Top 10 vulnerabilities with CI/CD integration.

Use cases

  • discover and inventory all API endpoints from network traffic
  • detect API attacks and bad actors in real time
  • automatically block malicious API requests
  • scan APIs for PII and sensitive data exposure
  • test APIs for OWASP Top 10 vulnerabilities like BOLA and SQL injection
  • integrate API security testing into CI/CD pipelines
  • self-host an API security tool on AWS, GCP, Azure, or Docker

When to choose

  • you need visibility into all API endpoints and sensitive data across your services
  • you want passive real-time attack detection and blocking for APIs
  • you want automated OWASP API Top 10 security testing in development and staging
  • you prefer a self-hosted, MIT-licensed API security platform

When to avoid

  • you need a WAF for non-API web traffic rather than API-specific security
  • you require a fully managed SaaS with vendor support rather than self-hosting
  • your stack has no supported language agent or traffic capture point
  • you only need simple rate limiting or authentication rather than attack detection

Facets

service · maturity active

security monitoring api-gateway vulnerability-scanning testing ci-cd security apis backend web-development self-hosted cloud api-security api-inventory attack-detection owasp pentest traffic-capture bola sensitive-data-scanning devops docker nodejs web-server

3 sources

Member repositories

RepositoryRoleHealth v2
metlo-labs/metlomain38

For agents

markdown · JSON · MCP: product_card(name="metlo-labs/metlo")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem