Skip to main content

Nodeprobe

Local CLI security scanner for websites, multi-chain RPC nodes, and EVM smart contracts.

Probe HTTP/TLS, JSON-RPC and GraphQL RPC, and contract posture from your terminal. Local-first for infrastructure you operate or are authorized to assess. No account. No cloud. No telemetry.

pip install nodeprobe
nodeprobe web https://example.com

Default profile is Standard. Use --profile Quick for a fast pass, or --profile Deep for a larger budget.

What it covers

Surface What Nodeprobe looks at
Web TLS, security headers (presence + HSTS/CSP policy grading), security.txt, robots.txt, server disclosure
RPC Protocol families: EVM, Solana, Substrate/Polkadot, Cosmos, Aptos, Sui, Starknet, NEAR — auto-detect or --family
Contracts EVM code presence, proxies, bytecode heuristics, Sourcify verification (read-only)

EVM networks share one engine. nodeprobe scan <rpc> works for any EVM chain. Chain names come from a bundled Chainlist snapshot; unknown IDs still scan with a generic name.

Quick start

# Website
nodeprobe web https://example.com

# EVM RPC — any EVM chain
nodeprobe scan https://rpc.example.com

# Other protocol families
nodeprobe rpc https://api.mainnet-beta.solana.com
nodeprobe substrate https://rpc.polkadot.io
nodeprobe cosmos https://rpc.cosmos.directory:443
nodeprobe aptos https://fullnode.mainnet.aptoslabs.com/v1
nodeprobe sui https://graphql.mainnet.sui.io/graphql
nodeprobe starknet https://rpc.starknet.lava.build
nodeprobe near https://rpc.mainnet.near.org

# Contract (read-only)
nodeprobe contract 0x… --rpc https://rpc.example.com --chain 1

Human reports are the default. Use --html -o report.html or --json --pretty for other formats.

Safety by design

  • Blocks SSRF paths: private IPs, localhost, cloud metadata
  • Enforces per-profile request, RPS, and duration budgets
  • Kill switch: touch /tmp/nodeprobe-kill or set NODEPROBE_KILL_SWITCH
  • Escalation confirms impact — no exploit payloads, no funded transactions

Authorized use only. Scan systems you own or have permission to assess.

Docs and source

Full examples, screenshots, and development setup: github.com/ehsanhajian/nodeprobe

License

MIT

Release files for nodeprobe 0.1.3

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for nodeprobe 0.1.3
File Size Uploaded
nodeprobe-0.1.3.tar.gz 129.2 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for nodeprobe 0.1.3
File Interpreter ABI Platform
nodeprobe-0.1.3-py3-none-any.whl Python 3 none any Details

Total release size: 273.0 kB

Release files / nodeprobe-0.1.3.tar.gz

Download URL nodeprobe-0.1.3.tar.gz
Size 129.2 kB
Tags Source
SHA-256 checksum
How to use checksums
a07647619560ff5f8cd693c96d2a626957b98146bc08765eb5c212e504661d1a
BLAKE2b-256 checksum
How to use checksums
d9fd4646deed1b1c97c85fb98314d28510764a885e2f389b3aabfb8fcdb52dfd
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 18, 2026.

Transparency log

Release files / nodeprobe-0.1.3-py3-none-any.whl

Download URL nodeprobe-0.1.3-py3-none-any.whl
Size 143.8 kB
Tags Python 3
SHA-256 checksum
How to use checksums
e56359548726bb917c2fb11890493b7eac3e62c27594820c4d90578a7f23ce53
BLAKE2b-256 checksum
How to use checksums
f54b7ba10e81a38d5428a3bd82b9892b18425891176913f36236e697d425b909
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 18, 2026.

Transparency log

Release history Release notifications | RSS feed

0.1.5

2 release files

0.1.4

2 release files

This release

0.1.3 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page