Skip to content
CAI
Software that uses CAICheck a score

sherlock-project/sherlock

55.9

Adequate · 18 September 2026

1.4k

lines of production code

Python

primary language

1

measurement over time

CAI band scale
CAI lens gauges

What this system is

Sherlock is a username reconnaissance tool that checks the availability of specific usernames across a wide range of social networks and online platforms. It operates as a modular Python package with a command-line interface, supporting both local execution and serverless deployment via Apify. The system maintains an extensive, schema-validated list of supported sites and includes comprehensive testing to ensure accurate detection of user profiles while handling edge cases like NSFW content and Unicode errors.

Features

Automated site listing generation and CI validation summarization

The project now includes scripts to automate the maintenance of the supported sites documentation and improve CI feedback. The new \site-list.py\ script reads the site data, sorts it alphabetically, and generates the \sites.mdx\ documentation file, ensuring the list of supported sites is always up-to-date and correctly formatted. Additionally, \summarize\_site\_validation.py\ parses JUnit XML test results from the CI workflow to produce a human-readable summary table in issue comments, clearly indicating pass/fail status for false-positive and false-negative checks on modified sites.

devel · high confidence

Initial release of Sherlock Actor for Apify

This change introduces the complete definition for the Sherlock Actor on the Apify platform, enabling serverless username reconnaissance across social networks. The addition includes the Dockerfile for the runtime environment, the actor.json manifest, and input/output schemas that allow users to submit a list of usernames and receive found social media links as structured dataset records.

.actor · high confidence

Behavioural changes

Sherlock restructured as a proper Python package with Python 3.9+ requirement

The tool has been refactored from a script-based structure into a standard Python package (sherlock\_project), introducing a \py.typed\ marker file to support PEP 561 type checking. This change enforces a minimum Python version of 3.9, as the entry point now explicitly checks the runtime version and exits if an older interpreter is detected. The internal logic has been modularized into distinct modules for site information, query results, and notifications, providing a more stable foundation for future features.

_sherlock\project · high confidence

Test coverage

Comprehensive test suite for site validation, NSFW handling, and CLI behavior

Added a new pytest-based test suite covering core Sherlock functionality. Tests verify that the site manifest validates against both local and remote JSON schemas, and that site data is iterable with correct error types. Live integration tests check known positive and negative username probes across various sites (e.g., GitHub, GitLab, Docker Hub) and validate that illegal regex patterns are correctly rejected. The suite also includes regression tests for handling Unicode decode/encode errors in username lookups, verifies the NSFW site removal and explicit selection logic, tests wildcard username expansion, and ensures the CLI correctly reports versioning and errors when no usernames are provided.

tests · high confidence

Dependencies

Migration to Poetry build system and Python 3.9+ requirement

The project has switched its build backend from setuptools to Poetry, introducing a pyproject.toml that defines the build system (poetry-core\>=1.2.0) and manages dependencies. This change enforces a minimum Python version of 3.9 (dropping support for 3.8) and updates the dependency specifications, including allowing higher versions for certifi and pandas, while adding dev dependencies like pytest 8.4.2 and pytest-xdist 3.8.0.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Baseline

  • First survey — no prior run to compare against. CAI 56.

Lenses

  • Code Health 76
  • Architecture 69
  • Maturity 53
  • Readiness 48
  • Security 78

Changes since last survey

  • 300 commits — 216 feature/other, 84 fixes

By area

  • sherlock_project/resources — 126 commits
  • (repo) — 108 commits
  • .github/workflows — 26 commits
  • docs/README.md — 9 commits
  • (root) — 7 commits
  • sherlock_project/sherlock.py — 6 commits
  • sherlock_project/notify.py — 3 commits
  • docs/removed-sites.md — 2 commits
  • sherlock_project/sites.py — 2 commits
  • tests/conftest.py — 2 commits
  • tests/test_validate_targets.py — 2 commits
  • .actor/README.md — 1 commit
  • .github/CODEOWNERS — 1 commit
  • devel/site-list.py — 1 commit
  • devel/summarize_site_validation.py — 1 commit
  • docs/images — 1 commit
  • sherlock_project/result.py — 1 commit
  • tests/test_ux.py — 1 commit

Notable commits

  • fix: fix: Add error messages to BabyRu to prevent false positives
  • fix: Fix Cracked Forum false positives
  • fix: Fix LessWrong detection Issue #2634
  • fix: Fix Minor Capitalization Issue in README.md
  • fix: Fix Minor Capitalization Issue in README.md (#2716)
  • fix: Fix MuseScore URL endpoint
  • fix: Fix akniga false negatives
  • fix: Fix command injection vuln
  • fix: Fix: false positive for topcoder due to invalid regex
  • fix: Merge branch 'master' into fix/babyru-false-positive
  • fix: Merge branch 'master' into fix/babyru-false-positive
  • fix: Merge branch 'master' into fix/remediate-blitztactics
  • fix: Merge pull request #2561 from shreyasNaik0101/fix/remediate-deviantart
  • fix: Merge pull request #2564 from shreyasNaik0101/fix/remediate-allmylinks
  • fix: Merge pull request #2565 from shreyasNaik0101/fix/remediate-mydramalist
  • fix: Merge pull request #2568 from shreyasNaik0101/fix/remediate-blitztactics
  • fix: Merge pull request #2570 from shreyasNaik0101/fix/remediate-applediscussions
  • fix: Merge pull request #2574 from dollaransh17/fix/http-request-timeouts
  • fix: Merge pull request #2582 from dollaransh17/fix/boardgamegeek-false-positive
  • fix: Merge pull request #2588 from shreyasNaik0101/fix/correct-ci-diff
  • …and 280 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

sherlock-project/sherlock was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 18 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 376018708c0f6948d3f978a9ae2915024e794654 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-5d04157a340d.