Skip to content
CAI
Software that uses CAICheck a score

lissy93/web-check

42.6

Weak · 28 September 2026

12k

lines of production code

TypeScript

with JavaScript

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a web-based infrastructure and security auditing tool called 'Web Check' that analyzes websites for security posture, DNS configuration, and compliance. It provides a comprehensive suite of backend checks—including SSL/TLS validation, mail authentication, and threat intelligence lookups—alongside a client-side engine that processes these results into severity-rated findings. The application features a modern Astro-based frontend with a dark/light theme, supporting multi-platform deployment and offering interactive API documentation for developers.

How it got here

2022 — Migration to Astro framework

4 changes.

The project underwent a comprehensive migration from Create React App to the Astro framework, replacing the legacy frontend structure with a modern, multi-platform deployment architecture. This shift introduced a dedicated Express server for API endpoints, updated build tools, and support for various hosting providers via centralized configuration. The update also included upgrading core dependencies like React and TypeScript, switching to Yarn, and customizing static assets for a branded user experience.

2023–2026 — Astro migration and API expansion

12 changes.

The project underwent a significant frontend migration to Astro, introducing a new design system, centralized layout components, and a redesigned homepage with interactive elements. Concurrently, the backend API was expanded with a comprehensive suite of new endpoints for security and infrastructure analysis, supported by unified middleware and robust client-side result rendering.

Features

The site now includes a new navigation bar and footer component. The navigation bar features the 'Web Check' logo, links to the Check, API, and Login pages, and includes hover and focus styling. The footer displays the project name, a link to the GitHub repository, the MIT license information, and the author's details, with responsive styling for mobile devices.

src/components/scafold · high confidence

Client-side security analysis engine and UI components introduced

The client application now includes a comprehensive, rule-based analysis engine that processes scan results into structured security findings. This engine evaluates 22 distinct areas—including HTTP security headers, HSTS, SSL/TLS configuration, DNSSEC, mail authentication (SPF/DMARC/DKIM), cookie attributes, open port risks, and threat intelligence feeds (Google Safe Browsing, PhishTank, URLhaus)—and outputs severity-rated findings (critical, issue, warning, info, pass). The UI layer supporting this feature includes a new React Router configuration, reusable form components (Button, Card, Input, Modal, Heading, Row), and dedicated result display components (Archives, etc.), enabling the presentation of these audit results directly in the browser.

src/client · high confidence

Introduces base layout and centralized meta tag management

The application now uses a new Base layout component that establishes the core HTML structure, including dark mode support, global styles, and client-side routing. A dedicated MetaTags component centralizes SEO and social sharing metadata, automatically handling Open Graph and Twitter card tags, canonical links, and favicon definitions. This component also integrates a non-tracking analytics script and supports structured data (JSON-LD) for breadcrumbs and custom schemas, ensuring consistent metadata across all pages.

src/layouts · high confidence

New API endpoints for site analysis and security checks

The API now exposes a comprehensive suite of new endpoints for analyzing website infrastructure and security posture. Users can now query Wayback Machine archives, check DNS blocklists against multiple providers, calculate local carbon footprint estimates, and inspect cookies via both headers and browser rendering. Additional endpoints provide detailed DNS records, DNSSEC validation, WAF/firewall detection, HTTP security header checks, and HSTS compliance. The API also supports geolocation lookups, mail configuration analysis (MX, DKIM, DMARC), open port scanning, quality reports via Google PageSpeed, global rank lookups, redirect chain tracing, robots.txt parsing, screenshot generation, security.txt validation, Shodan data retrieval, sitemap parsing, and social media presence verification across platforms like X, Bluesky, and Mastodon.

api · high confidence

New Astro-based pages for Home, Account, and Self-Hosted Setup

The site now uses Astro to render three new pages: the Home page (index.astro) which features a hero form and an automatic redirect to /check on non-boss servers; the Account page (account/index.astro) which displays a placeholder message indicating that account management is under development; and the Self-Hosted Setup page (self-hosted-setup.astro) which provides deployment instructions for Docker, one-click options for Vercel, Netlify, and Render, and a build-from-source guide.

src/pages · high confidence

New Icon component with Font Awesome support

A new Icon component has been added to the molecules directory, enabling the display of specific icons (check, plus, github, code, rocket, copy) using Font Awesome. Users can now render these icons by passing a name, size, color, and additional styles, leveraging the integrated @fortawesome/svelte-fontawesome library.

src/components/molecules · high confidence

New landing page and interactive documentation for the Web Check API

Users can now access a dedicated landing page at /web-check-api that provides an overview of the API's capabilities and direct links to the OpenAPI specification, account management, and source code. Additionally, a new documentation page at /web-check-api/spec renders the interactive Swagger UI, allowing users to explore available endpoints, usage, and examples directly in the browser.

src/pages/web-check-api · high confidence

Behavioural changes

Added ESLint configuration for Astro and TypeScript

A new ESLint configuration file has been added to the project to enforce code quality standards. It integrates the recommended rules for Astro components and configures the TypeScript parser for .ts and .tsx files, while explicitly ignoring build and deployment directories such as dist, node\_modules, and .astro.

.config · high confidence

Homepage redesign with animated UI and new sections

The homepage has been completely redesigned with a new layout and interactive elements. The hero section now features an animated URL input with rotating placeholder examples and a button with a rotating conic-gradient border. A new 'About' section displays a list of over 30 supported checks, while a 'Screenshots' section showcases a scrolling gallery of analysis results. The background now includes an animated meteor effect with a dot grid pattern. Additionally, a new 'SponsorSegment' promotes Terminal Trove, and a 'TempDisabled' banner is available to display service status messages.

src/components/homepage · high confidence

Introduces unified API middleware and check-skipper logic

The API now uses a shared middleware layer that standardizes request handling across Netlify, Vercel, and Node.js environments, including consistent timeout enforcement and error formatting. A new check-skipper module centralizes logic for skipping scans based on environment variables (e.g., disabling specific checks or blocking hosts) and target type (e.g., skipping public-only checks for private IPs). This refactoring replaces scattered per-route logic with a unified approach, improving reliability and configurability for self-hosted instances.

_api/\common · high confidence

Migrate check page to Astro with URL parameter redirection

The check page has been rebuilt as an Astro component that renders a React client application. A key behavioral change is that providing a 'url' query parameter on the home or check route now automatically redirects the user to the specific check result page for that target, both on the server side and via a JavaScript fallback for client-side navigation. The page also dynamically sets the browser tab title based on the target being checked.

src/pages/check · high confidence

Migrates source code from Create React App to Astro

The application's frontend framework has shifted from a Create React App (CRA) structure to Astro. This change removes CRA-specific boilerplate and dependencies, including the default App component, React DOM entry point, Web Vitals reporting, and Jest testing setup, replacing them with Astro's environment type definitions. Users will no longer see the default React landing page; instead, the site is now built on Astro, which changes how pages are rendered and served.

src · high confidence

Migration to Astro and multi-platform deployment support

The application has been rebuilt using the Astro framework, replacing the previous Create React App setup. This change introduces a new build and deployment architecture that supports multiple hosting providers (Netlify, Vercel, Fly.io, and Docker) via a centralized configuration system driven by the PLATFORM environment variable. The new setup includes a dedicated Express server for API endpoints, a multi-stage Dockerfile for optimized container images, and updated configuration files (astro.config.mjs, tsconfig.json) to support the new stack. Users can now deploy to various platforms with specific configuration files (netlify.toml, vercel.json, fly.toml) and benefit from improved rate-limiting and health-check capabilities.

(repo-wide) · high confidence

New design system with CSS variables and theme support

The application now uses a centralized style system defined in SCSS files, introducing CSS custom properties for colors, typography, and spacing. This change adds support for a light theme via the \html\[data-theme='light'\]\ selector, allowing users to switch between dark and light modes. It also establishes a consistent visual language with specific font families (Hubot Sans, PTMono), a color palette, and responsive typography adjustments for mobile devices.

src/styles · high confidence

Replaces React scaffolding with custom static assets and error pages

The public directory has been restructured to remove the default Create React App template (index.html) and replace it with custom static files. This includes new error and placeholder pages with a dark theme, a security.txt file for vulnerability reporting, and an updated manifest.json that defines the app as "Web Check" with specific PWA icons and colors. These changes provide a branded, standalone experience for users encountering errors or installing the site on mobile devices.

public · high confidence

Dependencies

Migrate from React Create-React-App to Astro with Node.js backend

The project has been upgraded from a legacy React application (version 0.1.0) to a modern Astro-based architecture (version 2.2.5). This change replaces the \react-scripts\ build tool with Astro, introducing new dependencies such as \@astrojs/node\, \@astrojs/react\, and \@astrojs/svelte\, while upgrading core libraries like React to version 19 and TypeScript to version 6. The package manager has switched from npm to Yarn, evidenced by the removal of \package-lock.json\ and the addition of \yarn.lock\, and the Node.js engine requirement has been raised to version 22.12.0 or higher.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 41 → 43 (+2.0)
  • Rubric changed (rubric-2026.08.15 → rubric-2026.09.16) — scores are not directly comparable.

Lenses

  • Code Health 59 → 55 (-3.9)
  • Architecture 72 (new)
  • Maturity 55 → 49 (-6.5)
  • Readiness 25 → 32 (+7.3)
  • Security 56 → 72 (+15.5)
  • Accessibility 44 (new)
  • Performance 100 (new)

Resolved (56)

  • Dimension evaluation failed
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High IaC: DS-0017 (Dockerfile)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • …and 36 more

New (108)

  • Critical vulnerability: [GHSA redacted] (yarn.lock)
  • Documentation: no project overview (.github/README.md)
  • FancyBackground.FancyBackground (cyclomatic 36) (src/client/components/misc/FancyBackground.tsx)
  • FileTooLong: utils/docs.ts (src/client/utils/docs.ts)
  • FunctionTooLong: About.About (src/client/views/About.tsx)
  • FunctionTooLong: FancyBackground.FancyBackground (src/client/components/misc/FancyBackground.tsx)
  • FunctionTooLong: Home.Home (src/client/views/Home.tsx)
  • FunctionTooLong: Results.Results (src/client/views/Results.tsx)
  • FunctionTooLong: useJobs.useJobs (src/client/hooks/useJobs.ts)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • …and 88 more

Changes since last survey

  • 18 commits — 16 feature/other, 2 fixes

By area

  • (root) — 7 commits
  • (repo) — 5 commits
  • src/client — 3 commits
  • .github/README.md — 2 commits
  • api/social-presence.js — 1 commit

Notable commits

  • fix: Fix server startup on Windows
  • fix: Merge pull request #342 from kaanisthatyou/fix/windows-server-paths
  • change: Adds Hostinger one-click deploy button
  • change: Adds Hostinger sponsorship <3
  • change: Builds site social proof fetching and UI
  • change: Bump version to 2.2.3
  • change: Bump version to 2.2.4
  • change: Bump version to 2.2.5
  • change: Cleans up the new Docker build process
  • change: Fetches a websites announced twitter profile
  • change: Improved Mastadon vrification robustness
  • change: Merge branch 'master' of github.com:lissy93/web-check into feat/docker-optimizations
  • change: Merge pull request #330 from lissy93/feat/docker-optimizations
  • change: Merge pull request #339 from lissy93/feat/social-data
  • change: Merge pull request #344 from lissy93/docs/hostinger
  • change: Neatens output value for social verified field
  • change: New Dockerfile, and healthcheck
  • change: Removes .env and smaller items from .dockerignore

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

lissy93/web-check was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 28 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 7c5fdee2a984f7036299143384ce1050279cf80a — the exact code this score is about.
  • Scored under rubric-2026.09.16 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-24a00d372a4b.