About Web Check
Web-Check gathers information about a website or host and puts it in one place. Give it a URL, and it collects, collates and presents whatever it can find in the open.
The report covers potential attack vectors, the security measures already in place, and the connections between the parts of a site's architecture. The same data is just as useful for the everyday jobs: tuning server responses, untangling redirects, auditing cookies, checking DNS records.
Whether you're a developer, sysadmin, security researcher, penetration tester, or simply curious about how a particular site is put together, there should be something here worth knowing.
It's built and maintained by Alicia Sykes, and the source is on GitHub.
Support the project
Web-Check is free to use without restriction.
All the code is open source, so you're also free to deploy your own instance, as well as fork, modify and distribute the code in both private and commercial settings.
Running web-check does cost me a small amount of money each month, so if you're finding the app useful, consider sponsoring me on GitHub if you're able to. Even just $1 or $2/month would be a huge help in supporting the ongoing project running costs.
Otherwise, there are other ways you can help out, like submitting or reviewing a pull request to the GitHub repo, upvoting us on Product Hunt, or by sharing with your network.
But don't feel obliged to do anything, as this app (and all my other projects) will always remain 100% free and open source, and I will do my best to ensure the managed instances remain up and available for as long as possible :)
Fair use
- Please use this tool responsibly. Do not use it for hosts you do not have permission to scan. Do not use it as part of a scheme to attack or disrupt services.
- Requests may be rate-limited to prevent abuse. If you need more bandwidth, please deploy your own instance.
- There is no guarantee of uptime or availability. If you need to make sure the service is available, please deploy your own instance.
- Please use fairly, as excessive use will quickly deplete the lambda function credits, making the service unavailable for others (and/or empty my bank account!).
Privacy
Analytics are used on the managed instance, via a self-hosted Plausible instance. This records only the URL you visited, and no personal data. There's also basic error logging, via a self-hosted GlitchTip instance, which is only used to help fix bugs.
Neither your IP address, browser, OS or hardware info, nor any other data will ever be collected or logged. You can verify that yourself, either by inspecting the source code or by using your browser devtools.
License
Web Check is distributed under the MIT license, © Alicia Sykes2026. It's free to use, modify and distribute in both personal and commercial settings.
The MIT License (MIT) Copyright (c) Alicia Sykes <alicia@omg.com> Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, subject to the following conditions: The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software. THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.