Skip to content

Security: bountyyfi/lonkero

SECURITY.md

Security Policy

Supported Versions

Version Supported
2.0.x
< 2.0

We recommend always running the latest version of Lonkero.

Reporting a Vulnerability

We take security seriously. If you discover a vulnerability in Lonkero, we appreciate responsible disclosure.

How to Report

Email: info@bountyy.fi

Please include:

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Any suggested fixes (optional)

What to Expect

  • Initial Response: Within 48 hours
  • Status Update: Within 7 days
  • Resolution Timeline: Depends on severity, typically 30-90 days

Scope

In Scope:

  • Lonkero core scanner
  • Built-in attack modules
  • Configuration handling
  • Output/reporting functionality

Out of Scope:

  • Issues in third-party dependencies (report upstream)
  • Social engineering attacks
  • Denial of service against the tool itself

Security Considerations

Lonkero is a security testing tool. By design, it performs potentially intrusive operations against web applications.

Important:

  • Only scan targets you own or have explicit authorization to test
  • Understand your local laws regarding security testing
  • We are not responsible for misuse of this tool

Acknowledgments

We appreciate the security research community. Researchers who report valid vulnerabilities will be acknowledged here (with permission).


This policy follows responsible disclosure best practices.

There aren't any published security advisories