RISKORA
دليل الاستخدامSign in
Deterministic · no LLM in runtime

Know your
security posture.

Riskora verifies you own the target, orchestrates mature scanning engines, normalizes every result into vendor-neutral findings, and scores risk with a rule set you can read.

6
engines orchestrated
412
normalized rules
0
LLM calls at runtime
riskora — scan pipeline
riskora scan --target app.example.com --level ACTIVE
authorization: VERIFIED (.well-known/riskora-challenge)
stage PREPARING ✓ scope resolved · 1 host · SSRF guard armed
stage RUNNING ✓ http-observe · discovery · nuclei · tls
stage NORMALIZING ✓ raw results → vendor-neutral findings
stage ANALYZING ✓ severity counted · rules applied
score computed · posture band reported (reproducible)
Security score
0–100 band
Authorization before anything

DNS TXT or a .well-known file. Without it, no active testing happens — ever.

Vendor-neutral findings

Raw results from several engines normalize into de-duplicated findings.

A score you can read

Every deducted point maps to a published rule. No black box.

Monitoring & regressions

Recurring scans alert you the moment a fixed issue comes back.