If you discover a security vulnerability in this project, please do not open a public GitHub issue. Instead, report it privately:
- Email: rajesh.sharma@owg.com (or use GitHub's private vulnerability reporting feature on this repository)
Please include:
- A description of the vulnerability and its potential impact
- Steps to reproduce
- Any relevant logs or proof-of-concept code
We aim to acknowledge reports within 3 business days.
| Version | Supported |
|---|---|
| 0.1.x | ✅ |
This project never logs, persists, or transmits your Shodan API key outside
of the official Shodan API endpoints. Keys are masked in all CLI output and
stored locally only if you explicitly run shodan-recon configure.
This tool is a thin client around the Shodan API. It does not perform any scanning, exploitation, or unauthorized access on its own — all data comes from Shodan's existing index, and any on-demand scan requests are executed by Shodan's own infrastructure against targets you submit. You are responsible for ensuring you have authorization to query, monitor, or request scans of any target you use with this tool, and for complying with Shodan's Terms of Service and all applicable laws.