Self-Hosted Setup
Get your own free instance of Web Check, running locally or on your server.
Option #1
Deploy with Docker
Just one command, and you'll have your own Web Check instance running on your server in minutes.
docker run -p 3000:3000 lissy93/web-checkOption #2
1-Click Deploy
Don't have a server? Not a problem! Deploy Web Check with one click on Vercel, Netlify, Render or Hostinger.
Option #3
Build from Source
Want to customize Web Check? Clone the repository and deploy it on your server.
Configuration
Web Check runs without any configuration, so everything below is optional.
Set values as environment variables, in .env, your host's dashboard, or with docker run -e.
API keys
Unlock extra checks, or raise rate limits on the external APIs some checks use.
- GOOGLE_CLOUD_API_KEY
- Runs the quality and Safe Browsing checks. Enable the PageSpeed Insights and Safe Browsing APIs for itGet a key
- SHODAN_API_KEY
- Runs the host names, server info and vulnerabilities checksGet a key
- TRANCO_API_KEY
- Raises the Tranco rate limit for the rank checkGet a key
- TRANCO_USERNAME
- Your Tranco account email, used with the key above
- GITHUB_TOKEN
- Raises the GitHub rate limit for the social presence checkGet a key
- CERTSPOTTER_TOKEN
- Raises the CertSpotter rate limit for the subdomains checkGet a key
Settings
Change how the server and API behave. The frontend reads PUBLIC_ values at build time, so rebuild after changing them.
- PORT
- Port the server listens on (e.g.
3000) - DISABLE_GUI
- Serve only the API, without the web interface (e.g.
true) - PUBLIC_API_ENDPOINT
- Where the frontend sends API requests (e.g.
/api) - PUBLIC_API_TIMEOUT_LIMIT
- Timeout for each check, in milliseconds (e.g.
25000) - API_ENABLE_RATE_LIMIT
- Rate-limit requests to the API (e.g.
true) - API_CORS_ORIGIN
- Origin allowed to call the API. Defaults to any (e.g.
https://example.com) - API_ENABLED_CHECKS
- If set, only these checks run (e.g.
get-ip,ssl,dns,headers) - API_DISABLED_CHECKS
- Checks to turn off (e.g.
trace-route,ports) - API_BLOCKED_HOSTS
- Hosts, IPs or CIDR ranges that must never be scanned (e.g.
lan.example.com,192.168.0.0/16) - PORTS_TO_CHECK
- Ports the open ports check scans (e.g.
22,80,443) - CHROME_PATH
- Path to Chromium, for screenshots and tech stack (e.g.
/usr/bin/chromium) - TRUST_PROXY
- Set behind a reverse proxy, as a hop count, true, or CIDR list (e.g.
1) - LOG_LEVEL
- One of debug, info, warn, error or silent (e.g.
warn)