Web-Check: a single open-source intelligence dashboard for any website
lissy93/web-check · 34,921★ · 2,866 forks
Everything worth knowing about lissy93/web-check: a self-hostable OSINT tool that gathers dozens of network, security, and technology checks about a domain or URL into a single dashboard.

What Web-Check is
Web-Check is an open-source intelligence (OSINT) tool aimed at analyzing any website, IP address, or domain: it uncovers potential attack vectors, describes the server architecture, examines security configuration, and identifies the technologies the site uses. It isn’t a deep vulnerability scanner or a penetration-testing framework: it’s a high-level reconnaissance dashboard that runs more than thirty independent checks in parallel and presents the results as cards on a web dashboard.
The README describes it with the tagline “Comprehensive, on-demand open source intelligence for any website” and positions it as a starting point to “understand, optimize, and secure” a site. Unlike equivalent commercial services, the README and the author’s announcements present it as free, no signup, no ads, and no data collection.
The repository was created on June 25, 2023 by Alicia Sykes (lissy93), a developer based in London, UK. Stable version 1, announced May 20, 2024, was built as a React app with a lambda-functions backend, deployable to Vercel, Netlify, or any Docker-compatible service. By 2026, the project is an Astro app (with React and Svelte) served by a Node.js Express server; the main language is TypeScript and the license is MIT.
Origin
The lissy93/web-check repository was created on June 25, 2023, and the first retrievable public announcement on Hacker News dates to July 23, 2023 (thread 36839603), where the author presented it as an “all-in-one tool for scanning any website (free and open source, no signup, ads, or data collection).”
The motivation is documented in the launch comment of the Show HN on June 22, 2024 (thread 40757951, 411 points), where Alicia Sykes explains the problem she wanted to solve: “There are many tools for discovering metadata and security data about a website, IP, or server. But currently there’s nothing that does it all, in one place, without paywall or user registration.”
That framing — “all in one place, no signup” — is the central tension of the project against services like urlscan.io, BuiltWith, or Google Safe Browsing, each of which covers one aspect, and several of which require an account or API key.

The version timeline retrieved from GitHub releases: v1.0.0 (May 20, 2024, stable release, React + lambda; maintenance of V1.x.x moved to the xray-web/web-check-free organization); v2.1.0 (May 7, 2026, frontend migration to Astro “FEAT - Astroify,” new WAFs in firewall detection); v2.2.0 (July 28, 2026, web-check-live moved to the client, new advisory panel, subdomain search, informational OCSP stapling, fixed IPv6 DNS record visual truncation). The version currently declared in package.json is 2.2.5.
Philosophy and principles
Everything in one place, no signup or paywall. The author states this explicitly in the 2024 Show HN; the design assumes the user doesn’t want to create an account just to know what technologies a site uses or whether it has HSTS enabled.
Self-hostable by default. Every documented deployment path (Netlify, Vercel, Docker, Render, source) is free or low-cost; the author states the public instance costs her “about $25/month” in lambda functions and asks for GitHub Sponsors backing to cover it.

Each check is independent and dispensable. Checks live as standalone modules in api/ (one file per check); if a dependency is missing (Chromium, traceroute, dig), that check is skipped instead of breaking everything. The README documents this literally: “These jobs will simply be skipped if those packages are not present.” Transparency about what it doesn’t know. The README dedicates a section to each check with description, use cases, and links to external documentation (RFC, OWASP, Cloudflare Learning, Mozilla). User-verifiable data. Many sources are queryable public lists (URLHaus, PhishTank, Tranco, security.txt, robots.txt); the project doesn’t hide where each data point comes from.
How it works
Architecturally, Web-Check has two halves: the web dashboard — an Astro app (React 19 and Svelte 5, TypeScript) with a URL search box and a card grid; each card corresponds to a check and shows its result or status (success, fail, skipped) — and the checks API — an Express (Node.js) server that, in self-hosted mode, exposes each api/*.js module as a /api/<check-name> endpoint (e.g., get-ip, ssl, dns, headers, trace-route, ports, tech-stack, threats, social-presence…). Optional *_API_KEY keys extend or enable certain checks.

The implemented checks (one per file in api/) span five families: network and location (IP, DNS records, DNSSEC, DNS server, subdomains, open ports, traceroute, server location, associated hosts, redirect chain, Tranco ranking); certificates and TLS (SSL chain, TLS cipher suites, TLS security configuration, handshake simulation, OCSP stapling); web security (HTTP headers, HSTS, CSP, security.txt, robots.txt, WAF detection, tech fingerprint via Wappalyzer); email (SPF, DKIM, DMARC, BIMI, MX configuration); and reputation and context (malware/phishing lists, privacy/parental DNS blocking, carbon footprint, Wayback Machine history, sitemap, social tags, cookies, Whois/RDAP, site screenshot).

The basic flow: enter a URL in the search box (or call /api/<check>?url=…), wait for the panel to populate the cards, and read the advisory panel (introduced in v2.2.0) that summarizes actionable findings.

The ecosystem
Official organization and versions
xray-web/web-check-free — 150 stars. Xray/Web-Check’s GitHub organization; maintains the 1.x version branch (“Self-Hosted Edition”). It’s not a community fork: it’s the official repository where V1 is preserved. xray-web/web-check-api — 77 stars, an API-focused variant. Official Codeberg mirror: codeberg.org/alicia/web-check. Official container images: Docker Hub lissy93/web-check and GHCR ghcr.io/lissy93/web-check; release 2.2.0 adds standard OCI labels to the Dockerfile.
The author’s sibling repositories
The author maintains a set of networking/security/self-hosting projects often used alongside Web-Check: lissy93/dashy (26,463 stars, a self-hosted start page with widgets and status checks), lissy93/personal-security-checklist (22,318 stars, a checklist of 300+ personal security/privacy tips), lissy93/awesome-privacy (9,876 stars, a curated list of privacy software and services), lissy93/portainer-templates (2,910 stars), lissy93/networking-toolbox (2,669 stars, 100+ offline-first network tools), lissy93/AdGuardian-Term (1,658 stars, a traffic monitor for AdGuard Home), lissy93/domain-locker (1,515 stars, a domain portfolio manager), lissy93/wapalyzer (426 stars, a fork of Wappalyzer), lissy93/who-dat (309 stars, a domain lookup API), and lissy93/awesome-osint (69 stars, a curated list that includes Web-Check).

Forks, reimplementations, and community extensions
mwakidenis/WebCheck-OSINT — 170 stars, 34 forks, created December 14, 2025, MIT. Not a git fork of lissy93/web-check (the API flags it as fork: false); it’s an independent reimplementation/derivative that inherited the name and idea. hexsecteam/web-check — 43 stars, a direct fork with the same tagline. sethuaung/Web-Check — 8 stars, an earlier, unrelated project (August 2022). gksander/raycast-osint-webcheck — a Raycast extension. GiuffreLab/kubernetes-web-check — Kubernetes deployment. hamdihacihaliloglu/web-check-rs — a Rust rewrite. 00xCanelo/CVE-2025-32778 — a PoC for CVE-2025-32778, a command injection vulnerability in an OSINT Web-Check tool (3 stars). It’s a relevant reference for any self-hoster: the vulnerability is documented against this family of tools, and it’s worth keeping the container updated.

Curated lists
lissy93/awesome-osint (the author’s own, 69 stars) lists Web-Check: “All-in-one tool for viewing website and server meta data.” awesome-selfhosted/awesome-selfhosted (319,171 stars) does not include Web-Check in the file checked on September 14, 2026; it does include other projects by the author (Dashy, Domain Locker).

Official / semi-official status
No official vendor or marketplace status: Web-Check doesn’t appear in any official plugin marketplace or as a vendor-backed product in the sources consulted. It’s a 100% open-source (MIT) project maintained by its author, with community deployment on Netlify/Vercel/Render/Docker. De facto in its niche: the public instance web-check.xyz is cited as a reference in r/selfhosted and r/homelab threads when someone asks for “a self-hostable app similar to web-check.xyz.” Presence in reference lists: included in lissy93/awesome-osint, not included in awesome-selfhosted as of September 14, 2026. Official multi-registry distribution: Docker Hub + GHCR + a Codeberg mirror maintained by the repo’s own CI; version 1.x is officially preserved at xray-web/web-check-free.
Quick-start guide
Installation and first run
Prerequisites for building from source: Node.js v22.12 or later, yarn, and git. Some checks also require chromium, traceroute, and dns (dig) in the environment; if missing, those jobs get skipped rather than failing.
Option 1 — Docker (fastest):
docker run -p 3000:3000 lissy93/web-check
# open http://localhost:3000
Option 2 — From source:
git clone https://github.com/Lissy93/web-check.git
cd web-check
yarn install
yarn build
yarn start
Option 3 — One-click PaaS: Netlify (“Deploy to Netlify”), Vercel (“Deploy with Vercel”), Render (“Deploy to Render,” using the official Docker Hub image).
Development: yarn dev starts backend and frontend in parallel. Quality scripts: yarn lint, yarn typecheck, yarn hold-my-beer (format + lint + typecheck).
Common workflows
- Analyze a full site in the panel: open the instance, enter the URL, and wait for the cards to populate; the advisory panel summarizes actionable findings.
- Query a specific check via API: call
/api/get-ip?url=<domain>and/api/ssl?url=<domain>against the self-hosted server. - Narrow the scope of a self-hosted instance: set
API_ENABLED_CHECKS=get-ip,ssl,dns,headersto run only those checks, orAPI_DISABLED_CHECKS=trace-route,portsto exclude the slower ones. - Verify your own site’s security configuration: search the domain, review the security-headers, HSTS, DNSSEC, SPF/DKIM/DMARC/BIMI, and
security.txtcards.
Essential configuration
The README states that by default no configuration is needed. Optional variables: .env (container for all variables), API_DISABLED_CHECKS (comma-separated list of checks to disable), API_BLOCKED_HOSTS (hosts that should never be scanned), CHROME_PATH (path to the Chromium executable), GOOGLE_CLOUD_API_KEY (PageSpeed Insights key), REACT_APP_SHODAN_API_KEY/REACT_APP_WHO_API_KEY (host and Whois enrichment).
README warning: variables prefixed with REACT_APP_ are used client-side and “should be granted minimal privileges, as they may be exposed by intercepting network requests between the browser and the server.”
Common pitfalls and fixes
- Checks skipped with no apparent explanation — if
chromium,traceroute, ordigis missing, those jobs get skipped. SetCHROME_PATHand check dependencies are installed. - Quality metrics fail with 403 despite having a key — user
j1elo: the Google Cloud key was passed correctly, but the PageSpeed API wasn’t enabled on the project. - False positives in “Malware & Phishing” — user
daflip: enteringHttps://cnn.com(uppercase scheme) caused the tool to detect malware where there was none. - The free public instance has less capacity than self-hosted — user
simple10: the Docker version “worked better for testing,” because the free site doesn’t have all checks (like Chromium) enabled. - Contested DNS/DNSSEC/DKIM results — several users reported DNSSEC marked absent when it existed, or MX shown as IPs instead of hosts. v2.2.0 fixed the IPv6 DNS record visual truncation.
Integrations and migration
The Express server exposes each check as a REST endpoint under /api/ with configurable CORS and optional rate limiting, so Web-Check can be chained into CI pipelines. The author publishes Portainer templates, and GiuffreLab/kubernetes-web-check exists for Kubernetes. gksander/raycast-osint-webcheck launches a web-check from Raycast. Migrating from V1 to V2: the v1.0.0 note warns that “future versions don’t guarantee backward compatibility”; V1.x.x is maintained at xray-web/web-check-free and V2 is the active branch (Astro + Express).
Current metrics
Measured: September 14, 2026, public GitHub API and Docker Hub.
| Metric | Value |
|---|---|
| Stars | 34,802 |
| Forks | 2,850 |
| Subscribers (real watchers) | 181 |
Commits on master | 700 |
Open issues per open_issues_count | 30 |
| Main language | TypeScript |
| License | MIT |
| Created | June 25, 2023 |
| Latest dated release | v2.2.0, July 28, 2026 |
package.json version | 2.2.5 |
| Docker Hub image pulls | 3,067,780 |
Top contributors: lissy93 (575), liss-bot (63), ojusave (7), tnga (4), n0a (3), muni106 (3), ChrisCarini (3). Caveats: open_issues_count also includes open pull requests; watchers_count mirrors the stars, so subscribers_count (181) is reported separately; the 700-commit count came from the pagination header of the commits endpoint for the default branch.
Community reception
The evidence retrieved shows enthusiasm for the “all-in-one, no signup” idea, but also concrete criticism about the accuracy of several checks.
Hacker News — Show HN of June 22, 2024, 40757951: 411 points, 57 comments.
Ahmd72: “One of the best open source tools, at least for me, because I need to check URL reputation and this is really helpful with how everything is organized into cards… Looking forward to the API version and being able to use it as a VT [VirusTotal] replacement.” leobg: “I like how you can scroll to get a good overview without any single section being too long.” thwarted (criticism): “It’s checking two sites/domains I’m responsible for and this info is really confusing or just plain wrong. The ‘DNS Records’ card for MX isn’t the actual MX record IP addresses.” compootr (criticism): “‘everything about any website’ — you’re missing subdomains and certificates, a very crucial part of investigations.” SahAssar (technical criticism): DNSSEC shown as absent when Verisign’s analyzer shows it green; the DNS records panel shows the SPF record as NS. j1elo (resolved gotcha): the quality check failed with 403 despite passing the Google key; the PageSpeed API wasn’t enabled. daflip (reported bug): with an uppercase scheme, the tool detected malware that didn’t exist. fguerraz (harsh criticism): “So broken it’s probably just a tool for collecting URLs.”
Hacker News — second submission, July 27, 2024, 41088429: 80 points.
paulryanrogers: “Seems very surface-level. Maybe that’s why the subtitle is open source intelligence? Could be useful as a first step, I guess.” _Rabs_: “For the recon phase, absolutely useful. But yeah, mostly surface-level details.”
Reddit:
r/selfhosted 1jq94ju (April 4, 2025): “Is there a self-hostable open-source app similar to web-check.xyz?” — u/-defron- replies: “You could consider self-hosting web-check.xyz.” r/homelab 1je1pii (November 29, 2024): u/Don_Sandman after trying it: “Just installed this and HOLY SMOKES, IT’S GOOD… it does all that stuff other services make you pay for or sign up for an undocumented free trial.”
Comparison with similar projects
| Tool | Verifiable overlap | Verifiable difference |
|---|---|---|
| urlscan.io | URL scanning and analysis with public results; Web-Check queries URLHaus and other threat lists that urlscan also covers. | urlscan is a managed API service; Web-Check is self-hostable and adds DNS, TLS, headers, email, carbon footprint, Tranco ranking, etc. |
| BuiltWith | Identifies a site’s tech stack (the README links BuiltWith as an enrichment option). | BuiltWith is commercial and paid for heavy use; Web-Check is free and uses Wappalyzer fingerprinting by default. |
Wappalyzer (and the lissy93/wapalyzer fork) | Web technology detection; Web-Check depends on the wappalyzer npm package. | Wappalyzer is a technology-focused extension; Web-Check integrates it as just one of dozens of checks. |
| SSL Labs | TLS configuration analysis; Web-Check links SSL Labs in its documentation. | SSL Labs focuses only on TLS with letter grading; Web-Check integrates it alongside certificates, DNS, headers. |
| Google Safe Browsing / VirusTotal | Malicious/phishing URL detection; Web-Check queries Safe Browsing among its threat lists. | These are malware-focused URL reputation services; Web-Check uses them as one input and adds network OSINT. |
mwakidenis/WebCheck-OSINT (170 ★) | Same “all-in-one OSINT” idea; an independent derivative of the concept. | Not a git fork; a reimplementation created in December 2025 that inherited the name and goal. |
Web-Check stands out when you want a single, free, self-hostable entry point for site reconnaissance, without creating accounts across a dozen services. Specialized tools (SSL Labs, securityheaders.com, urlscan.io, Wappalyzer) remain deeper in their respective niches.
How to contribute
The README documents a simple contribution process: fork the repository, make changes, add/commit/push, open a pull request; for beginners, it links a freeCodeCamp guide; Contributor Covenant v2.1 code of conduct; report bugs by opening an issue with reproduction steps; and support via GitHub Sponsors. No formal integration-test harness is documented; the quality scripts are yarn lint, yarn typecheck, and yarn hold-my-beer.
Use cases
- Initial reconnaissance in cybersecurity and bug bounty: positioned as a “first step” for seeing what technologies a target uses, what ports it exposes, whether it has DNSSEC/SPF/DKIM/DMARC, and its Wayback Machine history.
- Self-hosters exposing services: checking the security of services exposed on one’s own network.
- Website owners and dev teams: auditing their own site’s security configuration before launch or after a change.
- OSINT researchers and journalists: building a map of a domain’s digital footprint via associated hosts, redirects, TXT records, and social presence.
- Digital trust / anti-phishing analysts: evaluating a link’s reputation before opening it, using it “as a VT replacement” per a community comment.
- Infrastructure operations teams: a quick view of infrastructure health and geography without leaving the panel.
- Security/privacy educators and students: each check links to RFC, OWASP, Cloudflare Learning, and Wikipedia.
Resources
- Repository: https://github.com/lissy93/web-check
- Documentation / official site: https://web-check.xyz — About page: https://web-check.xyz/about
- Live demo: https://web-check.as93.net
- Self-hosting guide: https://web-check.xyz/self-hosted-setup
- Related official repositories: https://github.com/xray-web/web-check-free (V1) · https://github.com/xray-web/web-check-api
- Codeberg mirror: https://codeberg.org/alicia/web-check
- Container images: Docker Hub https://hub.docker.com/r/lissy93/web-check · GHCR
- Sponsorship: https://github.com/sponsors/Lissy93
- Relevant HN threads: https://news.ycombinator.com/item?id=40757951 · https://news.ycombinator.com/item?id=41088429
- Reddit threads: https://www.reddit.com/r/selfhosted/comments/1jq94ju/ · https://www.reddit.com/r/homelab/comments/1je1pii/
- Author: Alicia Sykes — https://aliciasykes.com · X https://x.com/Lissy_Sykes
Note: this article combines the lissy93/web-check README, GitHub releases, the public GitHub API and Docker Hub, retrieved Hacker News and Reddit threads, and repository searches performed on September 14, 2026. Star, fork, and pull figures change over time.
Comments