Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
leakish — Browser privacy-leak detector — eight detection modules, risk scoring, and per-account history, all in your browser. | Kitploit
Tools/GitHubGitHub/qruiqai/leakish
OSINT (Open Source Intelligence)Network MappingVulnerability AnalysisInformation GatheringWeb SecurityPrivacyLearning & EducationAPI SecurityDNS AnalysisAnomaly Detection
GitHubqruiqai/leakish

leakish

71203 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Browser privacy-leak detector — eight detection modules, risk scoring, and per-account history, all in your browser.

View RepositoryWebsite

Leakish

Browser privacy-leak detector — eight detection modules, risk scoring, and per-account history, all in your browser.

Built with Verdent Next.js 14 React 18 TypeScript 5 Prisma

Built with Verdent — an agentic coding assistant. Every detection module, the analytics dashboard, the API-key auth flow, the bilingual UI and the Kubernetes-ready Docker image were designed and implemented in pair-programming sessions driven by Verdent.


What this is

Open a URL, click Run all, and within a few seconds Leakish tells you what your browser is leaking about you and your network — over WebRTC, fingerprinting APIs, DNS, and a server-side probe. Eight independent modules each produce a typed result + risk signals, an aggregated score (0–100) and a level (safe / warning / critical).

Signed-in users can save scans to MySQL, browse history, and open an analytics dashboard that shows distribution charts, fingerprint-hash repetition, IP / ASN timeline, outlier scans, and a pairwise compare. Everything else (the detector itself) works without an account — anyone can land on /app and run a scan.

Detection modules

IDModuleWhat it inspects
network-probeNetwork egress probeServer-observed public IP, ASN, country/region/city, VPN/proxy/Tor/hosting flags, TLS/HTTP
webrtcWebRTCPublic IPv4 + IPv6 via STUN, RFC1918 leaks, mDNS-obfuscated .local candidates
browser-fingerprintBrowser fingerprintUA, screen, timezone, plugins, CPU cores, device memory, language list, DNT, cookies
canvas-fingerprintCanvas / WebGL2D + WebGL renderer/vendor strings, text-rendering quirks, supported image formats
audio-fingerprintAudioAudioContext sample rate, channels, latency, oscillator output hash
font-detectionFonts40+ named-font probes via Canvas width-difference detection
dnsDNSDoH reachability, DNSSEC signal, resolver geolocation, DNS-leak heuristics
cdp-detectionAutomation / headlessnavigator.webdriver, CDP timing, Chromium-only API surface, port probes — confidence 0–1

Each module is registered through a single typed DetectionModule<T> interface and runs in isolation — one module throwing does not affect the others. Enable state per module is persisted in localStorage with a version key, survives refresh, and the Run all button only walks the enabled set.

Features

  • In-browser detection — every module runs in the user's tab. The server is only involved when (a) the user is signed in and saves a scan, (b) the network-probe module hits /api/detect/network to read its own server-observed IP, or (c) the DNS module talks to https://dns.google/resolve.
  • Bilingual UI — full English / Chinese parity. Locale is held in a leakish.locale cookie, drives <html lang>, page metadata, every screen, every API error response, and the magic-link sign-in email.
  • Authentication — NextAuth with Google OAuth + magic-link email (Mailgun); Prisma adapter on MySQL. Email is optional in dev — links print to the server log when Mailgun isn't configured.
  • Programmatic access — users can mint det_… API keys on the Integrations page (SHA-256 stored, plaintext shown once). Every /api/detect/* endpoint accepts either a session cookie or a Bearer key, so the same scan can be saved from a CLI / CI job.
  • Analytics dashboard at /scans/analytics — distribution charts across timezone / platform / language / screen / WebGL / ASN / country / font count, fingerprint-hash repetition with a per-kind risk grade, IP / ASN timeline, multi-axis outlier detector, pairwise compare with 0–100 similarity score.
  • Risk model with per-signal traceability — lib/risk/assess.ts produces typed RiskSignals with stable IDs (e.g. webrtc.public-ip-leak), per-module summaries, and a single aggregate score. Locale-aware via Messages injection.
  • Idempotent save + per-user pruning — POST /api/detect/scans accepts an Idempotency-Key header, caps each user at 200 scans, and rate-limits saves to 10/hour.
  • Production-grade Docker image — multi-stage build on node:22-alpine, Next.js standalone output, deploys to Kubernetes via the workflow under .github/workflows/.

Quick start

Prereqs: Node 22+ (anything 20+ works for local dev), Yarn 1.x, a running MySQL instance, and (optionally) a Google OAuth client.

yarn install
cp env.example .env.local      # fill in DATABASE_URL, NEXTAUTH_SECRET, IP_HASH_SALT at minimum
yarn prisma:generate
yarn db:push                   # provision tables on a fresh DB
yarn dev                       # http://localhost:3000

Minimum env to get a working sign-in:

  • DATABASE_URL — e.g. mysql://root:[email protected]:3306/detect
  • NEXTAUTH_SECRET — openssl rand -base64 32
  • NEXTAUTH_URL — http://localhost:3000 in dev
  • IP_HASH_SALT — openssl rand -base64 32

Optional:

  • GOOGLE_CLIENT_ID / GOOGLE_CLIENT_SECRET for Google sign-in
  • MAILGUN_API_KEY / MAILGUN_DOMAIN / EMAIL_FROM for real magic-link delivery (without these the link is printed to the dev server console)
  • IPINFO_TOKEN to enrich the network probe with ASN / VPN / proxy data

See env.example for the full annotated list.

Routes

PathPurpose
/Marketing landing (aurora hero, feature cards, FAQ, CTA)
/appThe detector — module list + result panel + overview
/loginStandalone sign-in page (Google / email / API key)
/scansSigned-in user's saved-scan history
/scans/[id]Single saved-scan detail
/scans/analyticsDistribution / repetition / timeline / outliers / compare
/integrationsManage det_… API keys (create / revoke / how-to)

Project layout

Download Tool