WebCheck: Self-Host Your Website OSINT Instead of Renting It

Website recon used to mean four tabs and a notepad. dig for DNS, curl -I for headers, openssl s_client for the certificate, whois for ownership, then a guess about the stack from the response. The ritual worked, slowly. WebCheck replaces that pile with one input field. Paste a domain and the dashboard fills with DNS records, certificate details, headers, and cookies. Scroll further for WHOIS, robots.txt, security.txt, linked pages, email addresses, server location, and a fingerprint of the tech stack. No extraction, no account, no browser extension.

Run it yourself

The hosted instance at web-check.xyz does the same job in a browser tab. Sending every target you investigate to a third-party service is the part worth skipping, no matter how clean their privacy page reads. WebCheck is open source, and the maintained fork (WebCheck-OSINT) runs on your own box with under a minute of setup. Node.js backend, Astro frontend, one REST API, rate-limited out of the box so it cannot be turned into a scanning hammer.

git clone https://github.com/mwakidenis/WebCheck-OSINT.git
cd WebCheck-OSINT
cp .env.example .env   # optional: VirusTotal, Shodan keys
npm install
npm run dev

Optional API keys for VirusTotal and Shodan extend the checks further. Basic recon needs none of them. For day-to-day work the default install is the whole tool, and the fork carries the original web-check project forward. Everything stays free and local. The project stores nothing by default, per its own security notes, and your query history never lives on someone else’s server.

What one dashboard actually gives you

A few checks earn their keep on every engagement. The TLS certificate shows the issuer, the SAN list, and the expiry date; a certificate covering names the domain never advertises is a fast way to spot shadow infrastructure. HTTP headers reveal the server and show whether HSTS and CSP are real or decorative. security.txt and robots.txt tell you how the operator wants to be contacted and what the crawlers already know. Email addresses and linked pages sketch the surface before you touch anything.

The checks are mostly passive: DNS lookups, TLS handshakes, public records. That makes it a good first pass, the recon you do before pointing anything noisier at the target. Treat the output as leads, not facts. A header can lie, a CDN hides the origin, and stale WHOIS entries are the norm, not the exception.

The tech fingerprint deserves its own mention. Knowing the framework under a site tells you which published CVEs to check before you dig deeper. It is the difference between probing blind and walking in with a list.

“WebCheck-OSINT makes requests to third-party websites. Ensure you have permission to scan targets under investigation.”

That warning from the project’s security policy is the whole job in one sentence. The practical part: run it from the machine you already trust, point it at domains you own first so the output shape is familiar before you rely on it elsewhere. If you do recon on a regular schedule, the ten-minute setup pays for itself inside one engagement. One URL in, one dashboard out, nothing left on someone else’s server.

Press Cmd K to search برای جستجوی سایت از Cmd+K استفاده کنید