Self-Hosted Setup

Get your own free instance of Web Check, running locally or on your server.

Option #1

Deploy with Docker

Just one command, and you'll have your own Web Check instance running on your server in minutes.

docker run -p 3000:3000 lissy93/web-check
Option #2

1-Click Deploy

Don't have a server? Not a problem! Deploy Web Check with one click on Vercel, Netlify, Render or Hostinger.

Option #3

Build from Source

Want to customize Web Check? Clone the repository and deploy it on your server.

Configuration

Web Check runs without any configuration, so everything below is optional.
Set values as environment variables, in .env, your host's dashboard, or with docker run -e.

API keys

Unlock extra checks, or raise rate limits on the external APIs some checks use.
GOOGLE_CLOUD_API_KEY
Runs the quality and Safe Browsing checks. Enable the PageSpeed Insights and Safe Browsing APIs for itGet a key
SHODAN_API_KEY
Runs the host names, server info and vulnerabilities checksGet a key
TRANCO_API_KEY
Raises the Tranco rate limit for the rank checkGet a key
TRANCO_USERNAME
Your Tranco account email, used with the key above
GITHUB_TOKEN
Raises the GitHub rate limit for the social presence checkGet a key
CERTSPOTTER_TOKEN
Raises the CertSpotter rate limit for the subdomains checkGet a key

Settings

Change how the server and API behave. The frontend reads PUBLIC_ values at build time, so rebuild after changing them.
PORT
Port the server listens on (e.g.3000)
DISABLE_GUI
Serve only the API, without the web interface (e.g.true)
PUBLIC_API_ENDPOINT
Where the frontend sends API requests (e.g./api)
PUBLIC_API_TIMEOUT_LIMIT
Timeout for each check, in milliseconds (e.g.25000)
API_ENABLE_RATE_LIMIT
Rate-limit requests to the API (e.g.true)
API_CORS_ORIGIN
Origin allowed to call the API. Defaults to any (e.g.https://example.com)
API_ENABLED_CHECKS
If set, only these checks run (e.g.get-ip,ssl,dns,headers)
API_DISABLED_CHECKS
Checks to turn off (e.g.trace-route,ports)
API_BLOCKED_HOSTS
Hosts, IPs or CIDR ranges that must never be scanned (e.g.lan.example.com,192.168.0.0/16)
PORTS_TO_CHECK
Ports the open ports check scans (e.g.22,80,443)
CHROME_PATH
Path to Chromium, for screenshots and tech stack (e.g./usr/bin/chromium)
TRUST_PROXY
Set behind a reverse proxy, as a hop count, true, or CIDR list (e.g.1)
LOG_LEVEL
One of debug, info, warn, error or silent (e.g.warn)