Ross ROSS = Recommend OSS · open-source software intelligence for agents

PhonePe/mantis

Mantis is a security framework that automates the workflow of discovery, reconnaissance, and vulnerability scanning. observed · 2026-08-28

github.com/PhonePe/mantis · homepage · Python · Apache-2.0 (permissive) observed · 2026-08-28

Health v2 · maintenance only

67/100

  • Activity 91
  • Release rhythm 28
  • Longevity 79
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: 61.5
  • age_days: 1117
  • days_rel: 530
  • days_push: 57
  • n_releases_24m: 3

Full methodology

Adoption not part of the score

1039 stars · 134 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

Mantis is a command-line security framework that automates asset discovery, reconnaissance, and vulnerability scanning for given top-level domains. It chains open-source and custom tools to find subdomains, certificates, open ports, technologies, secrets, misconfigurations, and phishing domains, storing results in MongoDB with dashboard and alerting support.

Use cases

  • automate subdomain discovery and recon for my domains
  • scan for exposed secrets and misconfigurations across assets
  • attack surface monitoring for my company's domains
  • run distributed vulnerability scans across multiple machines
  • find phishing domains impersonating my brand
  • bug bounty recon automation

When to choose

  • you want an end-to-end automated discovery, recon, and scanning pipeline for domains
  • you need distributed scanning, alerting, and a MongoDB-backed dashboard out of the box
  • you are a product security team or bug bounty hunter wanting customizable recon workflows

When to avoid

  • you need a lightweight single-purpose scanner rather than a CPU-intensive multi-tool framework
  • you cannot run a dedicated VM or manage MongoDB and AppSmith dependencies
  • you lack authorization to scan the target domains

Facets

framework · maturity active

security osint vulnerability-scanning cli monitoring alerting security penetration-testing developer-tools cli python attack-surface-management recon bug-bounty subdomain-discovery secrets-scanning phishing-detection distributed-scanning automation linux macos docker

2 sources

Member repositories

RepositoryRoleHealth v2
PhonePe/mantismain67

For agents

markdown · JSON · MCP: product_card(name="PhonePe/mantis")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem