Website Intelligence Analyzer (OSINT) avatar

Website Intelligence Analyzer (OSINT)

Pricing

from $16.00 / 1,000 results

Go to Apify Store
Website Intelligence Analyzer (OSINT)

Website Intelligence Analyzer (OSINT)

All-in-one website analysis tool. Run 30 OSINT checks on any URL — DNS, SSL, WHOIS, tech stack, security headers, email security, open ports, and more. Get a complete site profile in seconds.

Pricing

from $16.00 / 1,000 results

Rating

5.0

(2)

Developer

One Scales

One Scales

Maintained by Community

Actor stats

3

Bookmarked

2

Total users

1

Monthly active users

3 hours ago

Last modified

Share

Get a complete intelligence profile of any website in one run — 30 checks, 38 structured output fields, no API keys required.


Features

CategoryChecks
DomainWHOIS, registrar, age, expiry, nameservers
DNSA/AAAA/MX/NS/CNAME/TXT/SOA/CAA, DNSSEC, DoH support, cache poisoning check
SSL/TLSCertificate chain, cipher suites, protocol assessment, 5-client handshake simulation
SecurityHTTP security headers, full raw headers, WAF detection, open ports, HSTS preload, security.txt, 17 DNS blocklists
EmailSPF, DKIM (7 selectors), DMARC, BIMI, MX records
Tech StackCMS, frameworks, analytics, CDN — 40+ signatures
SEO & Contentrobots.txt, sitemap, Open Graph/Twitter Cards, internal/external links, redirect chain
ReputationGlobal Tranco ranking, URLHaus + PhishTank threat checks
ServerIP geolocation, ASN, hosting provider, traceroute
ExtrasCookies, site features (PWA/WebSocket/Canvas/WebRTC), quality metrics

How to Use

Input

Paste one or more URLs in any format — example.com, https://www.example.com, or full URLs with paths. The actor normalizes everything automatically. Separate multiple URLs with commas, semicolons, or newlines. Optionally configure a residential proxy to avoid rate limits on large batches.

Output

Results are available as JSON, CSV, or Excel from the Apify console. Each URL takes 30–90 seconds and produces one dataset row with the following fields:

FieldTypeDescription
urlstringInput URL
finalUrlstringURL after redirects
ipstringResolved IP
domainstringDomain name
serverStatusobjectStatus code, response time, online/offline
whoisobjectRegistrar, dates, nameservers
domainInfoobjectAge in days, TLD
serverInfoobjectServer software, ASN, hosting provider
serverLocationobjectCountry, city, lat/lng, timezone, ISP
dnsRecordsobjectA, AAAA, MX, NS, CNAME, TXT, SOA, CAA
txtRecordsarrayRaw TXT records
dnsServerobjectResolver IPs, DoH support, cache poisoning check
dnssecobjectDNSSEC enabled/disabled
sslCertobjectIssuer, validity, protocol, chain
tlsCipherSuitesarrayCipher suites
tlsSecurityConfigobjectmodern / intermediate / outdated
tlsHandshakeSimulationarray5-client compatibility results
securityHeadersobjectCSP, HSTS, X-Frame-Options, etc.
hstsobjectEnabled, preloaded, max-age, includeSubDomains
securityTxtobjectContact, policy, expiry
firewallobjectWAF detected, provider
malwarePhishingobjectURLHaus + PhishTank threat checks
blockListsobjectStatus across 17 DNS blocklists
openPortsarrayPort, protocol, service, state
traceroutearrayHop, IP, latency
associatedHostsarrayReverse DNS hostnames
emailConfigobjectSPF, DKIM, DMARC, BIMI, MX
techStackarrayTechnology, category, confidence
siteFeaturesobjectPWA, AMP, WebSocket, WebGL, Canvas, WebRTC, iframe
cookiesarrayName, domain, path, flags, expiry
crawlRulesstringrobots.txt content
sitemapUrlsarrayURLs from sitemap.xml
socialTagsobjectOpen Graph, Twitter Card
linkedPagesobjectInternal/external links and counts
redirectChainarrayEach redirect hop
rawHeadersobjectFull raw HTTP response headers
globalRanknumberTranco ranking
qualityMetricsobjectViewport, charset, title, H1, page size
checkedAtstringISO 8601 timestamp
checksCompletedarrayModules that succeeded
checksFailedarrayModules that errored or timed out
runDurationMsnumberTotal runtime

API

This actor can also be called via the Apify API for programmatic access — pass your URLs as input and retrieve structured JSON results.

Example Input

{
"proxyConfiguration": {
"useApifyProxy": true,
"apifyProxyGroups": [
"RESIDENTIAL"
]
},
"urls": [
"https://example.com"
]
}

Limitations

  • WHOIS privacy — some domains hide registration details behind privacy protection.
  • Open ports & traceroute — require nmap and traceroute in the Docker image (included). Results depend on network conditions.
  • Quality metrics — basic HTML-based assessment only; full Lighthouse scores would require a Google Cloud API key.
  • Tech stack — signature-based fingerprinting with 40+ patterns. For deeper detection, the full Wappalyzer engine would be needed.

Credits & Licenses

Based on Lissy93/web-check (MIT © Alicia Sykes 2023). Adapted by One Scales Inc.

External APIs used (no keys required): ip-api.com · hstspreload.org · tranco-list.eu · dns.google · urlhaus-api.abuse.ch · checkurl.phishtank.com

System tools in Docker: nmap · traceroute · whois · dnsutils (dig)


Support

Contact Support — feature requests and custom integrations welcome.

Built with care by One Scales Inc.

osint website-analysis dns ssl whois tech-stack security-headers email-security seo web-check reconnaissance domain-intelligence open-ports waf-detection certificate traceroute hsts dmarc spf dkim phishtank blocklists