
Browser privacy-leak detector — eight detection modules, risk scoring, and per-account history, all in your browser.
Browser privacy-leak detector — eight detection modules, risk scoring, and per-account history, all in your browser.
Built with Verdent — an agentic coding assistant. Every detection module, the analytics dashboard, the API-key auth flow, the bilingual UI and the Kubernetes-ready Docker image were designed and implemented in pair-programming sessions driven by Verdent.
Open a URL, click Run all, and within a few seconds Leakish tells you what
your browser is leaking about you and your network — over WebRTC, fingerprinting
APIs, DNS, and a server-side probe. Eight independent modules each produce a
typed result + risk signals, an aggregated score (0–100) and a level
(safe / warning / critical).
Signed-in users can save scans to MySQL, browse history, and open an analytics
dashboard that shows distribution charts, fingerprint-hash repetition, IP / ASN
timeline, outlier scans, and a pairwise compare. Everything else (the detector
itself) works without an account — anyone can land on /app and run a scan.
| ID | Module | What it inspects |
|---|---|---|
network-probe | Network egress probe | Server-observed public IP, ASN, country/region/city, VPN/proxy/Tor/hosting flags, TLS/HTTP |
webrtc | WebRTC | Public IPv4 + IPv6 via STUN, RFC1918 leaks, mDNS-obfuscated .local candidates |
browser-fingerprint | Browser fingerprint | UA, screen, timezone, plugins, CPU cores, device memory, language list, DNT, cookies |
canvas-fingerprint | Canvas / WebGL | 2D + WebGL renderer/vendor strings, text-rendering quirks, supported image formats |
audio-fingerprint | Audio | AudioContext sample rate, channels, latency, oscillator output hash |
font-detection | Fonts | 40+ named-font probes via Canvas width-difference detection |
dns | DNS | DoH reachability, DNSSEC signal, resolver geolocation, DNS-leak heuristics |
cdp-detection | Automation / headless | navigator.webdriver, CDP timing, Chromium-only API surface, port probes — confidence 0–1 |
Each module is registered through a single typed DetectionModule<T> interface
and runs in isolation — one module throwing does not affect the others. Enable
state per module is persisted in localStorage with a version key, survives
refresh, and the Run all button only walks the enabled set.
/api/detect/network to read its own server-observed
IP, or (c) the DNS module talks to https://dns.google/resolve.leakish.locale cookie, drives <html lang>, page metadata, every screen,
every API error response, and the magic-link sign-in email.det_… API keys on the
Integrations page (SHA-256 stored, plaintext shown once). Every
/api/detect/* endpoint accepts either a session cookie or a Bearer key, so
the same scan can be saved from a CLI / CI job./scans/analytics — distribution charts across
timezone / platform / language / screen / WebGL / ASN / country / font count,
fingerprint-hash repetition with a per-kind risk grade, IP / ASN timeline,
multi-axis outlier detector, pairwise compare with 0–100 similarity score.lib/risk/assess.ts produces
typed RiskSignals with stable IDs (e.g. webrtc.public-ip-leak), per-module
summaries, and a single aggregate score. Locale-aware via Messages injection.POST /api/detect/scans accepts an
Idempotency-Key header, caps each user at 200 scans, and rate-limits saves
to 10/hour.node:22-alpine,
Next.js standalone output, deploys to Kubernetes via the workflow under
.github/workflows/.Prereqs: Node 22+ (anything 20+ works for local dev), Yarn 1.x, a running MySQL instance, and (optionally) a Google OAuth client.
yarn install
cp env.example .env.local # fill in DATABASE_URL, NEXTAUTH_SECRET, IP_HASH_SALT at minimum
yarn prisma:generate
yarn db:push # provision tables on a fresh DB
yarn dev # http://localhost:3000
Minimum env to get a working sign-in:
DATABASE_URL — e.g. mysql://root:[email protected]:3306/detectNEXTAUTH_SECRET — openssl rand -base64 32NEXTAUTH_URL — http://localhost:3000 in devIP_HASH_SALT — openssl rand -base64 32Optional:
GOOGLE_CLIENT_ID / GOOGLE_CLIENT_SECRET for Google sign-inMAILGUN_API_KEY / MAILGUN_DOMAIN / EMAIL_FROM for real magic-link delivery
(without these the link is printed to the dev server console)IPINFO_TOKEN to enrich the network probe with ASN / VPN / proxy dataSee env.example for the full annotated list.
| Path | Purpose |
|---|---|
/ | Marketing landing (aurora hero, feature cards, FAQ, CTA) |
/app | The detector — module list + result panel + overview |
/login | Standalone sign-in page (Google / email / API key) |
/scans | Signed-in user's saved-scan history |
/scans/[id] | Single saved-scan detail |
/scans/analytics | Distribution / repetition / timeline / outliers / compare |
/integrations | Manage det_… API keys (create / revoke / how-to) |