Skip to content

Release history

Lonkero releases

Lonkero - Wraps around your attack surface. Professional-grade scanner for real penetration testing. Fast. Modular. Rust.

All releases

23 shown

v3.7.3 Bug fix

Fixed cross-platform binary path resolution using the which crate for improved compatibility across operating systems.

v3.7.2 Bug fix

Fixed UTF-8 boundary panic crashes when processing multi-byte characters, improving stability with international text.

v3.7.1 Bug fix

Fixed broken XSS and framework scanners, CMS scan handler, UTF-8 string slicing panics, browser extension CSP violations, and license validation issues.

v3.7.0 New feature
Notable features
  • WAF Bypass button with 220+ techniques
  • AI-powered security testing agent
v3.6.6 Security relevant
Security fixes
  • HMAC authentication vulnerability
  • SSRF (Server-Side Request Forgery) vulnerability
  • Temp-directory security issues
Notable features
  • Token detection enhancements
  • JS route and API extraction with probing
  • Next.js vulnerability detection
v3.6.5 New feature
Breaking changes
  • Browser extension now requires Personal+ license tier
Security fixes
  • CSP (Content Security Policy) bypass fixes
Notable features
  • License gating for browser extension
v3.6.4 Bug fix

Fixed unclosed character class in sandbox detection regex pattern that affected pattern matching reliability.

v3.6.3 Security relevant
Breaking changes
  • Replaced federated learning with one-way model distribution API
Security fixes
  • Security vulnerabilities fixed
Notable features
  • One-way model distribution API
v3.6.0 Bug fix

Fixed scanner freeze issue, disabled aggressive anti-tamper checks blocking Professional license tier users, and updated dependencies.

v3.5.7 Bug fix

Fixed scanner freeze on b61 nx architecture affecting scanning performance.

v3.5.2 Bug fix

Fixed scanner freeze issue on b61 nx architecture affecting scanning performance.

v3.5.1 Bug fix

Prevented scanner freeze by removing parallel iteration in browser extension scanner implementation.

v3.5.0 Maintenance

Multiple dependency updates including serde_json, rust_xlsxwriter, deadpool-redis, blake3, and flate2. Removed unused dependencies and fixed compiler compatibility issues.

v3.2.0 New feature
Notable features
  • SQLi confirmation techniques in OOBZero
  • 404 response filtering
v3.1.0 Bug fix

Removed incorrect skip logic for Node.js command injection detection that was preventing legitimate vulnerability detection.

v3.0.1 Maintenance

Improved CI/CD infrastructure with cross-platform build fixes for ARM and macOS, updated GitHub Actions, enabled crates.io publishing, and improved Chrome compatibility in CI environments.

v3.0.0 Breaking risk
Breaking changes
  • Strict signing with no offline fallback
Notable features
  • Quantum-safe report signing
  • CVE-2025-55183/55184 detection
  • Google Dorking module

Beta — feedback welcome: [email protected]