finds.dev← search

// the find

tomnomnom/waybackurls

★ 4,563 · Go · updated May 2024

Fetch all the URLs that the Wayback Machine knows about for a domain

waybackurls is a single-purpose Go CLI that pulls every URL the Wayback Machine has archived for a domain (and its subdomains), reading domains from stdin and writing URLs to stdout. It's aimed at security researchers and bug bounty hunters doing recon, not general web developers.

- Does exactly one thing and composes cleanly with other recon tools via stdin/stdout — fits the standard Unix pipeline pattern used throughout the ProjectDiscovery/tomnomnom recon toolchain

- Zero-config, single Go binary via `go install`, no API keys or setup required

- Small enough codebase (essentially one main.go) that you can read the whole thing in a few minutes and know exactly what network calls it's making

- No rate limiting or retry/backoff logic against the Wayback CDX API — large domain lists will get you throttled or blocked with no graceful handling

- No tests in the repo at all, and the README gives zero detail on output format, error behavior, or how subdomain matching (`*.domain`) actually works

- Last commit is well over a year old and there's a long tail of open issues/PRs on the upstream repo that never got triaged — treat this as effectively unmaintained

- No filtering options (dedup, extension filtering, date ranges) — you get raw archived URLs and have to pipe into other tools just to make the output usable

View on GitHub →

// want more like this?

We dig through GitHub every week and send a few repos picked for what you actually care about — each with an honest take like this one.

Get finds in your inbox → Search again →