Ross ROSS = Recommend OSS · open-source software intelligence for agents

zidansec/CloudPeler

CrimeFlare is a useful tool for bypassing websites protected by CloudFlare WAF, with this tool you can easily see the real IP of websites that have been protected by CloudFlare. The resulting information is certainly very useful for conducting further penetration testing, and analyzing websites with the same server. observed · 2026-08-28

github.com/zidansec/CloudPeler · homepage · PHP · MIT (permissive) · archived observed · 2026-08-28

Health v2 · maintenance only

10/100

  • Activity 0
  • Release rhythm 8
  • Longevity 100

Flags: archived

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 1574
  • days_rel: n/a
  • days_push: 1097
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

1576 stars · 192 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

CrimeFlare is a PHP command-line OSINT tool that attempts to reveal the real origin IP address behind websites protected by Cloudflare's WAF. It gathers DNS records, nameservers, hostname, organization, and geolocation data useful for further penetration testing reconnaissance.

Use cases

  • find the real IP behind a Cloudflare-protected website
  • gather DNS and nameserver info for a target domain during recon
  • locate the hosting organization and geolocation of a hidden origin server
  • enumerate websites sharing the same origin server
  • prepare reconnaissance data before a penetration test
  • check whether a domain's Cloudflare protection can be bypassed

When to choose

  • you need a quick, simple CLI tool to attempt Cloudflare origin IP discovery
  • you are doing authorized penetration testing or OSINT research on a target
  • you want DNS, WHOIS-style, and geolocation details in one run

When to avoid

  • you need a guaranteed bypass - the tool explicitly does not guarantee 100% success
  • you are not authorized to test the target website
  • you need a maintained, actively updated tool - the project has had periods of being non-functional
  • you need a GUI or a non-PHP environment

Facets

cli-tool · maturity maintenance

security osint networking cli security penetration-testing osint networking cli php cloudflare-bypass waf-bypass dns-lookup real-ip-discovery pentest-recon php-tool information-gathering linux

2 sources

Member repositories

RepositoryRoleHealth v2
zidansec/CloudPelermain10

For agents

markdown · JSON · MCP: product_card(name="zidansec/CloudPeler")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem