# PhonePe/mantis

Mantis is a security framework that automates the workflow of discovery, reconnaissance, and vulnerability scanning.

Repository: https://github.com/PhonePe/mantis
Canonical: https://ross.abutalabs.com/products/phonepe-mantis
Homepage: https://phonepe.github.io/mantis/introduction/introduction.html
Language: Python
License: Apache-2.0
License Family: permissive
Topics: application-security, attack-surface-management, osint, pentesting, recon, bugbounty, product-security, security-tools, hacktoberfest, caasm
Last push: 2026-07-07T05:30:20+00:00

## Health v2 (maintenance only)
Score: 67/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 91, release rhythm 28, longevity 79
- inputs: {"age_days": 1117, "days_push": 57, "days_rel": 530, "gap_med": 61.5, "n_releases_24m": 3}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1039, forks 134 (observed 2026-08-28T04:03:19.855455+00:00)

## What it is
Mantis is a command-line security framework that automates asset discovery, reconnaissance, and vulnerability scanning for given top-level domains. It chains open-source and custom tools to find subdomains, certificates, open ports, technologies, secrets, misconfigurations, and phishing domains, storing results in MongoDB with dashboard and alerting support.

## Use cases
- automate subdomain discovery and recon for my domains
- scan for exposed secrets and misconfigurations across assets
- attack surface monitoring for my company's domains
- run distributed vulnerability scans across multiple machines
- find phishing domains impersonating my brand
- bug bounty recon automation

## When to choose
- you want an end-to-end automated discovery, recon, and scanning pipeline for domains
- you need distributed scanning, alerting, and a MongoDB-backed dashboard out of the box
- you are a product security team or bug bounty hunter wanting customizable recon workflows

## When to avoid
- you need a lightweight single-purpose scanner rather than a CPU-intensive multi-tool framework
- you cannot run a dedicated VM or manage MongoDB and AppSmith dependencies
- you lack authorization to scan the target domains

## Facets
- artifact type: framework
- maturity: active
- function: security, osint, vulnerability-scanning, cli, monitoring, alerting
- domain: security, penetration-testing, developer-tools
- platform: cli, python
- tags: attack-surface-management, recon, bug-bounty, subdomain-discovery, secrets-scanning, phishing-detection, distributed-scanning, automation, linux, macos, docker

## Member repositories
- PhonePe/mantis (main) score 67

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:03:19.855455+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T07:03:34.514332+00:00, confidence not recorded.
  - readme: https://github.com/PhonePe/mantis (fetched 2026-08-28T04:03:19.855455+00:00, sha 1fd020fe21dc)
  - homepage: https://phonepe.github.io/mantis/introduction/introduction.html (fetched 2026-08-29T13:04:46.852909+00:00, sha 77548258b239)
- Data as of 2026-08-30T08:39:29.467469+00:00.
