
🕵️♂️ All-in-one OSINT tool for analysing any website
Comprehensive, on-demand open source intelligence for any website
🌐 web-check.xyz
Kindly supported by:
|
NinjaPear API to get a full B2B profiles from any URL |
Hostinger Deploy Web-Check with one click on Hostinger |
![]() Warp Built for coding with multiple AI agents |
Get an insight into the inner-workings of a given website: uncover potential attack vectors, analyse server architecture, view security configurations, and learn what technologies a site is using.
The aim is to help you easily understand, optimize and secure your website.
A hosted version can be accessed at: web-check.as93.net
The source for this repo is mirrored to CodeBerg, available at: codeberg.org/alicia/web-check
Build & Deploys:
Repo Management & Miscellaneous:
See web-check.xyz/about for the full list of checks, and what each one does
Click the button below, to deploy to Netlify 👇
Click the button below, to deploy to Vercel 👇
Deploy Web-Check with a single click on Hostinger – pre-configured and ready to run 👇
Click the button below, to deploy to Render 👇
Run docker run -p 3000:3000 lissy93/web-check, then open localhost:3000
You can get the Docker image from:
lissy93/web-checkghcr.io/lissy93/web-checkdocker build -t web-check .Install the prerequisites listed in the Developing section, then run:
git clone https://github.com/Lissy93/web-check.git # Download the code from GitHub
cd web-check # Navigate into the project dir
yarn install # Install the NPM dependencies
yarn build # Build the app for production
yarn start # Start the app (API and GUI)
By default, no configuration is needed.
But there are some optional environmental variables that you can set to give you access to some additional checks, or to increase rate-limits for some checks that use external APIs.
API Keys & Credentials:
GOOGLE_CLOUD_API_KEY - A Google API key with the PageSpeed Insights API enabled (get here). This can be used to return quality metrics for a siteREACT_APP_SHODAN_API_KEY - A Shodan API key (get here). This will show associated host names for a given domainREACT_APP_WHO_API_KEY - A WhoAPI key (get here). This will show more comprehensive WhoIs records than the default jobSECURITY_TRAILS_API_KEY - A Security Trails API key (get here). This will show org info associated with the IPCLOUDMERSIVE_API_KEY - API key for Cloudmersive (get here). This will show known threats associated with the IPTRANCO_USERNAME - A Tranco email (get here). This will show the rank of a site, based on trafficTRANCO_API_KEY - A Tranco API key (get here). This will show the rank of a site, based on trafficURL_SCAN_API_KEY - A URLScan API key (). This will fetch miscalanious info about a siteConfiguration Settings:
All values are optional.
You can add these as environmental variables. Either put them directly into an .env file in the projects root, or via the Netlify / Vercel UI, or by passing to the Docker container with the --env flag, or using your own environmental variable management system
Note that keys that are prefixed with REACT_APP_ are used client-side, and as such they must be scoped correctly with minimum privileges, since may be made visible when intercepting browser <-> server network requests
git clone [email protected]:Lissy93/web-check.gitcd web-checkyarnyarn devYou'll need Node.js (v22.22 or later) installed, plus yarn as well as git.
Some checks also require chromium, traceroute and dns to be installed within your environment. These jobs will just be skipped if those packages aren't present.
Contributions of any kind are very welcome, and would be much appreciated. For Code of Conduct, see Contributor Convent.
To get started, fork the repo, make your changes, add, commit and push the code, then come back here to open a pull request. If you're new to GitHub or open source, this guide or the git docs may help you get started, but feel free to reach out if you need any support.
If you've found something that doesn't work as it should, or would like to suggest a new feature, then go ahead and raise a ticket on GitHub. For bugs, please outline the steps needed to reproduce, and include relevant info like system info and resulting logs.
The app will remain 100% free and open source. But due to the amount of traffic that the hosted instance gets, the lambda function usage is costing about $25/month. Any help with covering the costs via GitHub Sponsorship would be much appreciated. It's thanks to the support of the community that this project is able to be freely available for everyone :)
Credit to the following users for contributing to Web-Check
Huge thanks to these wonderful people, who sponsor me on GitHub, their support helps cover the costs required to keep Web-Check and my other projects free for everyone. Consider joining them, by sponsoring me on GitHub if you're able.
Lissy93/Web-Check is licensed under MIT © Alicia Sykes 2023 - 2026.
For information, see TLDR Legal > MIT
The MIT License (MIT)
Copyright (c) Alicia Sykes <[email protected]>
Permission is hereby granted, free of charge, to any person obtaining a copy
of this software and associated documentation files (the "Software"), to deal
in the Software without restriction, including without limitation the rights
to use, copy, modify, merge, publish, distribute, sub-license, and/or sell
copies of the Software, and to permit persons to whom the Software is furnished
to do so, subject to the following conditions:
The above copyright notice and this permission notice shall be included install
copies or substantial portions of the Software.
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED,
INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANT ABILITY, FITNESS FOR A
PARTICULAR PURPOSE AND NON INFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT
HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION
OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE
SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
© Alicia Sykes 2026
Licensed under MIT
![]()
Thanks for visiting :)
| Key | Value |
|---|
GOOGLE_CLOUD_API_KEY | A Google API key with the PageSpeed Insights API enabled (get here). This can be used to return quality metrics for a site |
REACT_APP_SHODAN_API_KEY | A Shodan API key (get here). This will show associated host names for a given domain |
REACT_APP_WHO_API_KEY | A WhoAPI key (get here). This will show more comprehensive WhoIs records than the default job |
BUILT_WITH_API_KEY - A BuiltWith API key (get here). This will show the main features of a siteTORRENT_IP_API_KEY - A torrent API key (get here). This will show torrents downloaded by an IP| Key | Value |
|---|
PORT | Port to serve the API, when running server.js (e.g. 3000) |
API_ENABLE_RATE_LIMIT | Enable rate-limiting for the /api endpoints (e.g. true) |
PUBLIC_API_TIMEOUT_LIMIT | The timeout limit for API requests, in milliseconds (e.g. 25000) |
API_CORS_ORIGIN | Enable CORS, by setting your allowed hostname(s) here (e.g. example.com) |
API_DISABLED_CHECKS | Comma-separated list of checks to disable (e.g. trace-route,ports) |
API_ENABLED_CHECKS | If set, only these checks will run (e.g. get-ip,ssl,dns,headers) |
API_BLOCKED_HOSTS | Hosts that must never be scanned (e.g. lan.example.com,192.168.0.0/16) |
CHROME_PATH | The path the Chromium executable (e.g. /usr/bin/chromium) |
DISABLE_GUI | Disable the GUI, and only serve the API (e.g. false) |
REACT_APP_API_ENDPOINT | The endpoint for the API, either local or remote (e.g. /api) |