September 14, 2026 · By YasKad
lissy93/web-check

Web-Check: a single open-source intelligence dashboard for any website

lissy93/web-check · 34,921★ · 2,866 forks

Everything worth knowing about lissy93/web-check: a self-hostable OSINT tool that gathers dozens of network, security, and technology checks about a domain or URL into a single dashboard.

A striking hero image for an article about an open-source OSINT web reconnaissance dashboard, a dark-mode cyberpunk command center dominated by a large floating dashboard interface, with a URL search bar at the top and a dense grid of glowing result cards representing IP lookup, DNS records, TLS certificates, HTTP security headers, technology fingerprinting, threat intelligence, email authentication, and social presence, behind the dashboard a translucent globe, network graph, server rack, and browser window merge into a futuristic holographic scene, neon cyan, electric violet, and soft magenta accents against deep charcoal and black, include subtle radar sweeps, packet traces, lock icons, certificates, DNS nodes, and a shield emblem, but no readable text, dark mode, cyberpunk/tech aesthetic, neon accents, ultra-detailed, 8K resolution

What Web-Check is

Web-Check is an open-source intelligence (OSINT) tool aimed at analyzing any website, IP address, or domain: it uncovers potential attack vectors, describes the server architecture, examines security configuration, and identifies the technologies the site uses. It isn’t a deep vulnerability scanner or a penetration-testing framework: it’s a high-level reconnaissance dashboard that runs more than thirty independent checks in parallel and presents the results as cards on a web dashboard.

The README describes it with the tagline “Comprehensive, on-demand open source intelligence for any website” and positions it as a starting point to “understand, optimize, and secure” a site. Unlike equivalent commercial services, the README and the author’s announcements present it as free, no signup, no ads, and no data collection.

The repository was created on June 25, 2023 by Alicia Sykes (lissy93), a developer based in London, UK. Stable version 1, announced May 20, 2024, was built as a React app with a lambda-functions backend, deployable to Vercel, Netlify, or any Docker-compatible service. By 2026, the project is an Astro app (with React and Svelte) served by a Node.js Express server; the main language is TypeScript and the license is MIT.

Origin

The lissy93/web-check repository was created on June 25, 2023, and the first retrievable public announcement on Hacker News dates to July 23, 2023 (thread 36839603), where the author presented it as an “all-in-one tool for scanning any website (free and open source, no signup, ads, or data collection).”

The motivation is documented in the launch comment of the Show HN on June 22, 2024 (thread 40757951, 411 points), where Alicia Sykes explains the problem she wanted to solve: “There are many tools for discovering metadata and security data about a website, IP, or server. But currently there’s nothing that does it all, in one place, without paywall or user registration.”

That framing — “all in one place, no signup” — is the central tension of the project against services like urlscan.io, BuiltWith, or Google Safe Browsing, each of which covers one aspect, and several of which require an account or API key.

A dark cyberpunk illustration of a developer's laptop and terminal representing the origin of an open-source web reconnaissance project, the screen shows abstract code, repository activity graph, release timeline nodes, and a Hacker News-style discussion thread rendered as glowing lines, without readable text, floating around the laptop are holographic badges for June 2023, stable release 2024, Astro migration 2026, and version cards, neon cyan timeline, violet code snippets, magenta commit nodes, deep black background, dark mode, cyberpunk/tech aesthetic, neon accents, ultra-detailed, 8K resolution

The version timeline retrieved from GitHub releases: v1.0.0 (May 20, 2024, stable release, React + lambda; maintenance of V1.x.x moved to the xray-web/web-check-free organization); v2.1.0 (May 7, 2026, frontend migration to Astro “FEAT - Astroify,” new WAFs in firewall detection); v2.2.0 (July 28, 2026, web-check-live moved to the client, new advisory panel, subdomain search, informational OCSP stapling, fixed IPv6 DNS record visual truncation). The version currently declared in package.json is 2.2.5.

Philosophy and principles

Everything in one place, no signup or paywall. The author states this explicitly in the 2024 Show HN; the design assumes the user doesn’t want to create an account just to know what technologies a site uses or whether it has HSTS enabled.

Self-hostable by default. Every documented deployment path (Netlify, Vercel, Docker, Render, source) is free or low-cost; the author states the public instance costs her “about $25/month” in lambda functions and asks for GitHub Sponsors backing to cover it.

A conceptual dark-mode visual for open-source, self-hosted, no-signup intelligence, a central glowing padlock with an open shackle is surrounded by Docker container cubes, server racks, and cloud deployment nodes represented as abstract platform icons with no readable text, a user silhouette clicks a single button and receives a complete website analysis, independent modular check cards detach and reattach freely, showing resilience and optional dependencies, glass panels, floating containers, and network cables glow in cyan, violet, and magenta, dark mode, cyberpunk/tech aesthetic, neon accents, ultra-detailed, 8K resolution

Each check is independent and dispensable. Checks live as standalone modules in api/ (one file per check); if a dependency is missing (Chromium, traceroute, dig), that check is skipped instead of breaking everything. The README documents this literally: “These jobs will simply be skipped if those packages are not present.” Transparency about what it doesn’t know. The README dedicates a section to each check with description, use cases, and links to external documentation (RFC, OWASP, Cloudflare Learning, Mozilla). User-verifiable data. Many sources are queryable public lists (URLHaus, PhishTank, Tranco, security.txt, robots.txt); the project doesn’t hide where each data point comes from.

How it works

Architecturally, Web-Check has two halves: the web dashboard — an Astro app (React 19 and Svelte 5, TypeScript) with a URL search box and a card grid; each card corresponds to a check and shows its result or status (success, fail, skipped) — and the checks API — an Express (Node.js) server that, in self-hosted mode, exposes each api/*.js module as a /api/<check-name> endpoint (e.g., get-ip, ssl, dns, headers, trace-route, ports, tech-stack, threats, social-presence…). Optional *_API_KEY keys extend or enable certain checks.

An architectural diagram rendered as a neon cyberpunk data flow, on the left an Astro dashboard interface with a URL search field and a card grid, on the right an Express Node.js API server with modular endpoint chips represented by abstract icons for IP, SSL, DNS, headers, traceroute, ports, tech stack, threats, and social presence, data pulses travel between frontend and backend through glowing conduits, include optional API key tokens as small luminous keys and environment variables as floating chips, but no readable text, circuitry, server nodes, and packet streams glow in cyan and violet, dark mode, cyberpunk/tech aesthetic, neon accents, ultra-detailed, 8K resolution

The implemented checks (one per file in api/) span five families: network and location (IP, DNS records, DNSSEC, DNS server, subdomains, open ports, traceroute, server location, associated hosts, redirect chain, Tranco ranking); certificates and TLS (SSL chain, TLS cipher suites, TLS security configuration, handshake simulation, OCSP stapling); web security (HTTP headers, HSTS, CSP, security.txt, robots.txt, WAF detection, tech fingerprint via Wappalyzer); email (SPF, DKIM, DMARC, BIMI, MX configuration); and reputation and context (malware/phishing lists, privacy/parental DNS blocking, carbon footprint, Wayback Machine history, sitemap, social tags, cookies, Whois/RDAP, site screenshot).

A wide dark dashboard scene divided into five glowing families of web checks, Family 1: network and location, with globe, IP nodes, DNS records, traceroute path, and port scanner, Family 2: certificates and TLS, with certificate chains, encryption keys, and handshake simulation, Family 3: web security, with HTTP headers, HSTS, CSP, WAF shield, and technology fingerprint, Family 4: email, with SPF, DKIM, DMARC, and BIMI icons, Family 5: reputation, with threat lists, malware/fishing alerts, carbon footprint, and Wayback Machine timeline, each family is a neon card cluster with abstract icons, no readable text, dark mode, cyberpunk/tech aesthetic, neon accents, ultra-detailed, 8K resolution

The basic flow: enter a URL in the search box (or call /api/<check>?url=…), wait for the panel to populate the cards, and read the advisory panel (introduced in v2.2.0) that summarizes actionable findings.

A close-up of an advisory panel on a dark OSINT dashboard, summarizing actionable website findings, glowing risk badges, severity meters, checkmark cards, and warning chips represent HSTS, security headers, TLS configuration, email authentication, WAF detection, and threat list status, a central holographic advisory summary highlights recommendations without readable text, the interface feels calm but urgent, with cyan safe states, amber warnings, and red critical alerts, glassmorphism panels, subtle scanlines, and neon dashboard glow, dark mode, cyberpunk/tech aesthetic, neon accents, ultra-detailed, 8K resolution

The ecosystem

Official organization and versions

xray-web/web-check-free — 150 stars. Xray/Web-Check’s GitHub organization; maintains the 1.x version branch (“Self-Hosted Edition”). It’s not a community fork: it’s the official repository where V1 is preserved. xray-web/web-check-api — 77 stars, an API-focused variant. Official Codeberg mirror: codeberg.org/alicia/web-check. Official container images: Docker Hub lissy93/web-check and GHCR ghcr.io/lissy93/web-check; release 2.2.0 adds standard OCI labels to the Dockerfile.

The author’s sibling repositories

The author maintains a set of networking/security/self-hosting projects often used alongside Web-Check: lissy93/dashy (26,463 stars, a self-hosted start page with widgets and status checks), lissy93/personal-security-checklist (22,318 stars, a checklist of 300+ personal security/privacy tips), lissy93/awesome-privacy (9,876 stars, a curated list of privacy software and services), lissy93/portainer-templates (2,910 stars), lissy93/networking-toolbox (2,669 stars, 100+ offline-first network tools), lissy93/AdGuardian-Term (1,658 stars, a traffic monitor for AdGuard Home), lissy93/domain-locker (1,515 stars, a domain portfolio manager), lissy93/wapalyzer (426 stars, a fork of Wappalyzer), lissy93/who-dat (309 stars, a domain lookup API), and lissy93/awesome-osint (69 stars, a curated list that includes Web-Check).

A portrait-style cyberpunk ecosystem of related open-source tools by the same developer, a central developer silhouette is surrounded by floating project cards: a self-hosted start page with widgets, a personal security checklist, a privacy software list, Portainer templates, a networking toolbox, AdGuard traffic monitor, domain portfolio manager, Wappalyzer technology fingerprint engine, WHOIS/RDAP lookup API, and OSINT resource list, each card is a neon panel with abstract icons, no readable text, the scene should feel like a curated developer toolkit orbiting a central creator, dark mode, cyberpunk/tech aesthetic, neon accents, ultra-detailed, 8K resolution

Forks, reimplementations, and community extensions

mwakidenis/WebCheck-OSINT — 170 stars, 34 forks, created December 14, 2025, MIT. Not a git fork of lissy93/web-check (the API flags it as fork: false); it’s an independent reimplementation/derivative that inherited the name and idea. hexsecteam/web-check — 43 stars, a direct fork with the same tagline. sethuaung/Web-Check — 8 stars, an earlier, unrelated project (August 2022). gksander/raycast-osint-webcheck — a Raycast extension. GiuffreLab/kubernetes-web-check — Kubernetes deployment. hamdihacihaliloglu/web-check-rs — a Rust rewrite. 00xCanelo/CVE-2025-32778 — a PoC for CVE-2025-32778, a command injection vulnerability in an OSINT Web-Check tool (3 stars). It’s a relevant reference for any self-hoster: the vulnerability is documented against this family of tools, and it’s worth keeping the container updated.

A security advisory scene for self-hosters: a glowing CVE warning chip represented by a hazard triangle and abstract identifier, connected to an OSINT web-check container, a shield with a crack is being repaired by an update stream, showing command injection attempts as red glitch particles blocked by a hardened Docker container, terminal windows display abstract logs and patch notes without readable text, the composition should communicate vulnerability awareness, container updates, and safe self-hosting, dark mode, cyberpunk/tech aesthetic, neon accents, ultra-detailed, 8K resolution

Curated lists

lissy93/awesome-osint (the author’s own, 69 stars) lists Web-Check: “All-in-one tool for viewing website and server meta data.” awesome-selfhosted/awesome-selfhosted (319,171 stars) does not include Web-Check in the file checked on September 14, 2026; it does include other projects by the author (Dashy, Domain Locker).

A cyberpunk constellation showing an open-source ecosystem, the central node is a web reconnaissance dashboard; connected branches lead to an official organization repository, API variant, mirror repository, Docker and GHCR container images, Kubernetes deployment cluster, Raycast extension, Rust rewrite, AI analysis engine, and community reimplementations, nodes glow with star ratings as luminous sparks, but no readable numbers or text, include shields, containers, Kubernetes helm, terminal windows, and mirror arrows, the scene should feel like a living map of forks, mirrors, deployments, and community extensions, dark mode, cyberpunk/tech aesthetic, neon accents, ultra-detailed, 8K resolution

Official / semi-official status

No official vendor or marketplace status: Web-Check doesn’t appear in any official plugin marketplace or as a vendor-backed product in the sources consulted. It’s a 100% open-source (MIT) project maintained by its author, with community deployment on Netlify/Vercel/Render/Docker. De facto in its niche: the public instance web-check.xyz is cited as a reference in r/selfhosted and r/homelab threads when someone asks for “a self-hostable app similar to web-check.xyz.” Presence in reference lists: included in lissy93/awesome-osint, not included in awesome-selfhosted as of September 14, 2026. Official multi-registry distribution: Docker Hub + GHCR + a Codeberg mirror maintained by the repo’s own CI; version 1.x is officially preserved at xray-web/web-check-free.

Quick-start guide

Installation and first run

Prerequisites for building from source: Node.js v22.12 or later, yarn, and git. Some checks also require chromium, traceroute, and dns (dig) in the environment; if missing, those jobs get skipped rather than failing.

Option 1 — Docker (fastest):

docker run -p 3000:3000 lissy93/web-check
# open http://localhost:3000

Option 2 — From source:

git clone https://github.com/Lissy93/web-check.git
cd web-check
yarn install
yarn build
yarn start

Option 3 — One-click PaaS: Netlify (“Deploy to Netlify”), Vercel (“Deploy with Vercel”), Render (“Deploy to Render,” using the official Docker Hub image).

Development: yarn dev starts backend and frontend in parallel. Quality scripts: yarn lint, yarn typecheck, yarn hold-my-beer (format + lint + typecheck).

Common workflows

  • Analyze a full site in the panel: open the instance, enter the URL, and wait for the cards to populate; the advisory panel summarizes actionable findings.
  • Query a specific check via API: call /api/get-ip?url=<domain> and /api/ssl?url=<domain> against the self-hosted server.
  • Narrow the scope of a self-hosted instance: set API_ENABLED_CHECKS=get-ip,ssl,dns,headers to run only those checks, or API_DISABLED_CHECKS=trace-route,ports to exclude the slower ones.
  • Verify your own site’s security configuration: search the domain, review the security-headers, HSTS, DNSSEC, SPF/DKIM/DMARC/BIMI, and security.txt cards.

Essential configuration

The README states that by default no configuration is needed. Optional variables: .env (container for all variables), API_DISABLED_CHECKS (comma-separated list of checks to disable), API_BLOCKED_HOSTS (hosts that should never be scanned), CHROME_PATH (path to the Chromium executable), GOOGLE_CLOUD_API_KEY (PageSpeed Insights key), REACT_APP_SHODAN_API_KEY/REACT_APP_WHO_API_KEY (host and Whois enrichment).

README warning: variables prefixed with REACT_APP_ are used client-side and “should be granted minimal privileges, as they may be exposed by intercepting network requests between the browser and the server.”

Common pitfalls and fixes

  • Checks skipped with no apparent explanation — if chromium, traceroute, or dig is missing, those jobs get skipped. Set CHROME_PATH and check dependencies are installed.
  • Quality metrics fail with 403 despite having a key — user j1elo: the Google Cloud key was passed correctly, but the PageSpeed API wasn’t enabled on the project.
  • False positives in “Malware & Phishing” — user daflip: entering Https://cnn.com (uppercase scheme) caused the tool to detect malware where there was none.
  • The free public instance has less capacity than self-hosted — user simple10: the Docker version “worked better for testing,” because the free site doesn’t have all checks (like Chromium) enabled.
  • Contested DNS/DNSSEC/DKIM results — several users reported DNSSEC marked absent when it existed, or MX shown as IPs instead of hosts. v2.2.0 fixed the IPv6 DNS record visual truncation.

Integrations and migration

The Express server exposes each check as a REST endpoint under /api/ with configurable CORS and optional rate limiting, so Web-Check can be chained into CI pipelines. The author publishes Portainer templates, and GiuffreLab/kubernetes-web-check exists for Kubernetes. gksander/raycast-osint-webcheck launches a web-check from Raycast. Migrating from V1 to V2: the v1.0.0 note warns that “future versions don’t guarantee backward compatibility”; V1.x.x is maintained at xray-web/web-check-free and V2 is the active branch (Astro + Express).

Current metrics

Measured: September 14, 2026, public GitHub API and Docker Hub.

MetricValue
Stars34,802
Forks2,850
Subscribers (real watchers)181
Commits on master700
Open issues per open_issues_count30
Main languageTypeScript
LicenseMIT
CreatedJune 25, 2023
Latest dated releasev2.2.0, July 28, 2026
package.json version2.2.5
Docker Hub image pulls3,067,780

Top contributors: lissy93 (575), liss-bot (63), ojusave (7), tnga (4), n0a (3), muni106 (3), ChrisCarini (3). Caveats: open_issues_count also includes open pull requests; watchers_count mirrors the stars, so subscribers_count (181) is reported separately; the 700-commit count came from the pagination header of the commits endpoint for the default branch.

Community reception

The evidence retrieved shows enthusiasm for the “all-in-one, no signup” idea, but also concrete criticism about the accuracy of several checks.

Hacker News — Show HN of June 22, 2024, 40757951: 411 points, 57 comments.

Ahmd72: “One of the best open source tools, at least for me, because I need to check URL reputation and this is really helpful with how everything is organized into cards… Looking forward to the API version and being able to use it as a VT [VirusTotal] replacement.” leobg: “I like how you can scroll to get a good overview without any single section being too long.” thwarted (criticism): “It’s checking two sites/domains I’m responsible for and this info is really confusing or just plain wrong. The ‘DNS Records’ card for MX isn’t the actual MX record IP addresses.” compootr (criticism): “‘everything about any website’ — you’re missing subdomains and certificates, a very crucial part of investigations.” SahAssar (technical criticism): DNSSEC shown as absent when Verisign’s analyzer shows it green; the DNS records panel shows the SPF record as NS. j1elo (resolved gotcha): the quality check failed with 403 despite passing the Google key; the PageSpeed API wasn’t enabled. daflip (reported bug): with an uppercase scheme, the tool detected malware that didn’t exist. fguerraz (harsh criticism): “So broken it’s probably just a tool for collecting URLs.”

Hacker News — second submission, July 27, 2024, 41088429: 80 points.

paulryanrogers: “Seems very surface-level. Maybe that’s why the subtitle is open source intelligence? Could be useful as a first step, I guess.” _Rabs_: “For the recon phase, absolutely useful. But yeah, mostly surface-level details.”

Reddit:

r/selfhosted 1jq94ju (April 4, 2025): “Is there a self-hostable open-source app similar to web-check.xyz?” — u/-defron- replies: “You could consider self-hosting web-check.xyz.” r/homelab 1je1pii (November 29, 2024): u/Don_Sandman after trying it: “Just installed this and HOLY SMOKES, IT’S GOOD… it does all that stuff other services make you pay for or sign up for an undocumented free trial.”

Comparison with similar projects

ToolVerifiable overlapVerifiable difference
urlscan.ioURL scanning and analysis with public results; Web-Check queries URLHaus and other threat lists that urlscan also covers.urlscan is a managed API service; Web-Check is self-hostable and adds DNS, TLS, headers, email, carbon footprint, Tranco ranking, etc.
BuiltWithIdentifies a site’s tech stack (the README links BuiltWith as an enrichment option).BuiltWith is commercial and paid for heavy use; Web-Check is free and uses Wappalyzer fingerprinting by default.
Wappalyzer (and the lissy93/wapalyzer fork)Web technology detection; Web-Check depends on the wappalyzer npm package.Wappalyzer is a technology-focused extension; Web-Check integrates it as just one of dozens of checks.
SSL LabsTLS configuration analysis; Web-Check links SSL Labs in its documentation.SSL Labs focuses only on TLS with letter grading; Web-Check integrates it alongside certificates, DNS, headers.
Google Safe Browsing / VirusTotalMalicious/phishing URL detection; Web-Check queries Safe Browsing among its threat lists.These are malware-focused URL reputation services; Web-Check uses them as one input and adds network OSINT.
mwakidenis/WebCheck-OSINT (170 ★)Same “all-in-one OSINT” idea; an independent derivative of the concept.Not a git fork; a reimplementation created in December 2025 that inherited the name and goal.

Web-Check stands out when you want a single, free, self-hostable entry point for site reconnaissance, without creating accounts across a dozen services. Specialized tools (SSL Labs, securityheaders.com, urlscan.io, Wappalyzer) remain deeper in their respective niches.

How to contribute

The README documents a simple contribution process: fork the repository, make changes, add/commit/push, open a pull request; for beginners, it links a freeCodeCamp guide; Contributor Covenant v2.1 code of conduct; report bugs by opening an issue with reproduction steps; and support via GitHub Sponsors. No formal integration-test harness is documented; the quality scripts are yarn lint, yarn typecheck, and yarn hold-my-beer.

Use cases

  • Initial reconnaissance in cybersecurity and bug bounty: positioned as a “first step” for seeing what technologies a target uses, what ports it exposes, whether it has DNSSEC/SPF/DKIM/DMARC, and its Wayback Machine history.
  • Self-hosters exposing services: checking the security of services exposed on one’s own network.
  • Website owners and dev teams: auditing their own site’s security configuration before launch or after a change.
  • OSINT researchers and journalists: building a map of a domain’s digital footprint via associated hosts, redirects, TXT records, and social presence.
  • Digital trust / anti-phishing analysts: evaluating a link’s reputation before opening it, using it “as a VT replacement” per a community comment.
  • Infrastructure operations teams: a quick view of infrastructure health and geography without leaving the panel.
  • Security/privacy educators and students: each check links to RFC, OWASP, Cloudflare Learning, and Wikipedia.

Resources


Note: this article combines the lissy93/web-check README, GitHub releases, the public GitHub API and Docker Hub, retrieved Hacker News and Reddit threads, and repository searches performed on September 14, 2026. Star, fork, and pull figures change over time.

Comments