A professional-grade web security scanner for penetration testing with intelligent, context-aware scanning and proof-based vulnerability detection.
Lonkero is a professional-grade web security scanner designed for penetration testing. It uses intelligent, context-aware scanning to detect vulnerabilities like XSS, SQL injection, and authorization flaws with high accuracy and minimal false positives. The scanner incorporates proof-based detection techniques and an AI-driven interactive mode to simulate skilled manual testing.
Security professionals, penetration testers, and development teams conducting security audits who need a fast, accurate scanner that reduces noise and focuses on exploitable vulnerabilities.
Developers choose Lonkero for its intelligent scanning that skips framework noise, its proof-based vulnerability detection requiring fewer requests, and its AI-guided interactive mode that allows surgical testing based on real-time findings.
Lonkero - Wraps around your attack surface. Professional-grade scanner for real penetration testing. Fast. Modular. Rust.
Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.
Uses mathematical proof of exploitability without browser dependencies, detecting XSS in 16 contexts with only 2-3 requests per parameter, making it 300x faster and eliminating browser stability issues.
Skips framework internals and untestable elements, prioritizing high-value injection points to reduce scan time by 80% and minimize false positives to around 5%, as noted in the README's comparison tables.
OOBZero engine detects blind SQL injection without external infrastructure using statistical inference and deterministic confirmation techniques like calibrated SLEEP correlation and data extraction for proof.
Allows natural language-driven security testing where an AI agent guides targeted scans based on reconnaissance findings, enabling surgical testing with modules like --only scans, as demonstrated in the example session.
The project uses a proprietary license, and premium features require a valid license key, which limits accessibility for open-source or budget-constrained projects compared to fully free alternatives.
Requires Rust 1.85+, OpenSSL development libraries, and installation from crates.io or source, which can be a barrier for quick deployment, especially on systems without these pre-installed.
AI-powered interactive testing depends on external LLM providers like Claude API (with API keys) or local Ollama setup, adding complexity, potential costs, and privacy concerns for sensitive targets.