Roadmap
N0CK is evolving. Here's what's shipped, what's in progress, and what's on the horizon.
Status Legend
Now (v0.x)
Core scanning engine
v0.1.0Scope enforcement, rate limiting, basic vulnerability detection
GraphQL introspection
v0.2.0Schema discovery and mutation analysis
Authentication flows
v0.3.0Multi-step auth, session management, token refresh handling
Advanced validators
v0.3.0SSRF OAST detection, blind SQLi timing, DOM-based XSS
Next (v0.4-0.5)
WebSocket scanning
Real-time protocol testing with message fuzzing
API contract diffing
Compare OpenAPI specs, detect undocumented endpoints
Custom payload library
User-defined test cases with templating
Collaborative scanning
Multi-operator support with shared findings
Future (v1.0+)
Smart fuzzing with LLMs
Context-aware payload generation based on endpoint behavior
Continuous monitoring mode
Scheduled scans with diff alerts and regression detection
Cloud integrations
Native AWS/GCP/Azure security posture checks
Plugin system
Custom modules for proprietary tech stacks
Team features
Role-based access, audit logs, centralized reporting
Timelines are estimates and subject to change. Features may be added, removed, or reprioritized based on feedback and real-world usage.