# s-rah/onionscan

OnionScan is a free and open source tool for investigating the Dark Web.

Repository: https://github.com/s-rah/onionscan
Canonical: https://ross.abutalabs.com/products/onionscan
Homepage: https://twitter.com/OnionScan
Language: Go
License: NOASSERTION
License Family: other
Last push: 2024-08-09T23:55:59+00:00

## Health v2 (maintenance only)
Score: 23/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 0, release rhythm 8, longevity 100
- inputs: {"age_days": 3799, "days_push": 754, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 3290, forks 627 (observed 2026-08-28T04:07:53.874296+00:00)

## What it is
OnionScan is a free and open source Go CLI tool for investigating Tor hidden services (.onion sites) on the Dark Web. It scans sites for operational security leaks and misconfigurations, producing risk reports for operators and researchers.

## Use cases
- scan a tor hidden service for security misconfigurations
- audit my onion site for operational security leaks
- investigate dark web sites as a researcher
- extract EXIF metadata from images on onion sites
- get a JSON report of hidden service vulnerabilities
- crawl .onion sites through a tor SOCKS proxy

## When to choose
- you run a Tor hidden service and want to find opsec leaks before attackers do
- you need automated scanning and reporting of .onion site misconfigurations
- you want JSON output to integrate dark web scanning into other tooling

## When to avoid
- you need to scan regular clearnet websites rather than Tor onion services
- you need actively maintained tooling with modern Go version support
- you need a GUI or hosted service rather than a command-line tool

## Facets
- artifact type: cli-tool
- maturity: maintenance
- function: security, vulnerability-scanning, web-scraping, osint, cli
- domain: security, privacy, osint, crawlers, networking
- platform: windows, cli, go
- tags: tor, dark-web, hidden-services, onion-services, anonymity, opsec-audit, linux, macos

## Member repositories
- s-rah/onionscan (main) score 23

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:07:53.874296+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-29T18:43:12.499280+00:00, confidence not recorded.
  - readme: https://github.com/s-rah/onionscan (fetched 2026-08-28T04:07:53.874296+00:00, sha c849002d3435)
- Data as of 2026-08-30T08:39:29.467469+00:00.
