finds.dev← search

// the find

lissy93/web-check

★ 35,051 · TypeScript · MIT · updated Oct 2026

🕵️‍♂️ All-in-one OSINT tool for analysing any website

A self-hostable dashboard that runs 40+ independent checks (DNS, SSL/TLS, headers, threat lists, tech stack, carbon footprint, etc.) against any domain and renders them as a report. Aimed at sysadmins, security-curious devs, and anyone who wants a one-click OSINT sweep of a site without stitching together a dozen separate tools.

Each check is its own isolated api/*.js function paired with its own analysis/rules/*.ts interpreter, so the 'fetch data' and 'score the result' concerns are cleanly separated and you can disable or extend individual checks without touching the rest. Operators get real knobs for running this safely: API_DISABLED_CHECKS, API_ENABLED_CHECKS, and API_BLOCKED_HOSTS let you fence off which checks run and which targets are off-limits, which matters a lot for a tool that does port scans and traceroutes. It degrades gracefully — no API keys are required for the core experience, and Shodan/Google/Cloudmersive/Tranco keys just unlock extra checks rather than being hard requirements. Six first-class deploy paths (Docker, Netlify, Vercel, Render, Hostinger, from-source) with env-var config covers most people's hosting preference without custom tooling.

There's no visible test suite in the tree despite this being a tool that actively probes arbitrary user-supplied hosts (port scans, traceroute, whois, Shodan lookups) — that's exactly the kind of surface where silent regressions turn into SSRF or abuse vectors against your own infra. Several checks silently no-op if chromium/traceroute/dns binaries aren't present on the host, which means a self-hosted instance can quietly serve incomplete reports with no error surfaced to the user. The maintainer notes the hosted instance costs ~$25/month in lambda usage from traffic alone, which hints that running 40+ separate functions per scan isn't cheap or fast at scale — anyone self-hosting for a team should expect to tune cold starts and cost, not just docker-run it and forget it. Safety here is opt-in (you have to configure API_BLOCKED_HOSTS yourself); a default deployment pointed at the open internet is one misconfiguration away from being used to probe internal network ranges.

View on GitHub → Homepage ↗

// want more like this?

We dig through GitHub every week and send a few repos picked for what you actually care about — each with an honest take like this one.

Get finds in your inbox → Search again →