# Ekultek/WhatBreach

OSINT tool to find breached emails, databases, pastes, and relevant information

Repository: https://github.com/Ekultek/WhatBreach
Canonical: https://ross.abutalabs.com/products/whatbreach
Language: Python
License Family: other
Topics: breaches, breach, osint, emails, domains
Last push: 2025-08-14T14:29:48+00:00

## Health v2 (maintenance only)
Score: 48/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 36, release rhythm 35, longevity 100
- inputs: {"age_days": 2693, "days_push": 384, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases, no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1662, forks 221 (observed 2026-08-28T04:05:18.601796+00:00)

## What it is
WhatBreach is a Python CLI OSINT tool that searches email addresses against known data breaches via services like HIBP, dehashed, hunter.io, and pastebin. It can download breach databases and pastes and gather domain and profile information for further investigation.

## Use cases
- find which data breaches an email address appears in
- download breach databases for an email
- download pastes containing an email address
- search a list of emails from a text file
- investigate the domain behind an email
- check if an email is a disposable ten-minute email

## When to choose
- you need a scriptable CLI for bulk email breach lookups
- you want to automatically download publicly available breach databases and pastes
- you are doing OSINT investigations involving email addresses and domains

## When to avoid
- you need a GUI or web dashboard for breach monitoring
- you cannot obtain the required API keys (HIBP, hunter.io, weleakinfo)
- you need guaranteed ongoing support - the project has no license and depends on third-party APIs that change frequently

## Facets
- artifact type: cli-tool
- maturity: maintenance
- function: osint, search-engine, http-client, cli
- domain: security, osint, privacy
- platform: python, cli, cross-platform
- tags: breach-search, email-lookup, haveibeenpwned, pastebin, data-breach-databases, command-line

## Member repositories
- Ekultek/WhatBreach (main) score 48

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:05:18.601796+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T03:44:32.979374+00:00, confidence not recorded.
  - readme: https://github.com/Ekultek/WhatBreach (fetched 2026-08-28T04:05:18.601796+00:00, sha c9eb72aacf28)
- Data as of 2026-08-30T08:39:29.467469+00:00.
