onionscout
onionscout is a lightweight CLI tool for auditing Tor hidden services (.onion) for common security misconfigurations, clearnet dependencies, metadata leaks, fingerprinting indicators, and basic de-anonymization risks.
It is designed as a first-pass audit helper, not a full penetration-testing framework.
Use only against systems you own or are authorized to assess.
Features
Network and origin handling
- Tor SOCKS5h support
- onion v3 hostname sanity check
- smart HTTP/HTTPS origin selection
.onion-safe redirect policy- initial clearnet URL blocking for policy-managed fetches
- cross-onion redirect blocking
- redirect leak detection to clearnet
- retry handling for common onion/Tor network errors
- separate HTTP, SSH, and TLS timeouts
Web fingerprinting
- web server header detection
- default error-page fingerprinting
- favicon discovery and Shodan-compatible favicon hash
- ETag extraction and Shodan query helper
- TLS reachability, TLS version, cipher, certificate SHA256, issuer, subject, and validity
Leak and de-anonymization checks
- clearnet redirects
- external active resources
- external links
- CSP / CSP-Report-Only external allowances
- Report-To / NEL / Link header leakage
- canonical / alternate / OpenGraph / Twitter metadata leaks
- protocol-relative external links
- meta-refresh redirects
- clearnet form actions
- clearnet WebSocket endpoints
- Onion-Location header
- optional clearnet mirror Onion-Location validation with
--clearnet-url - proxy-related headers
- common fingerprinting headers
- baseline security headers
- CORS misconfiguration classification
- JavaScript URL, IP, source-map, and secret-candidate leak checks
- lightweight image metadata sniffing for EXIF/XMP-style markers, URLs, IPs, and GPS hints
Hidden-service hygiene checks
- Apache
mod_status - Apache
mod_info - nginx
stub_status - WebDAV exposure
- HTTP method exposure checks, including TRACE, PUT, DELETE, PATCH, PROPFIND, and MKCOL
- common sensitive files and paths
- directory listing detection
.well-known/*endpointsrobots.txtsitemap.xml- clearnet URL detection inside
robots.txtandsitemap.xml security.txtat root and.well-known- basic
security.txtExpires, Canonical, and clearnet URL review - CAPTCHA-related external resource leakage
- Set-Cookie attributes:
- Secure
- HttpOnly
- SameSite
- Domain
Content indicators
- minimal same-host crawler
- email extraction
- obfuscated email extraction, for example
name(at)domain(dot)tld - placeholder email separation, for example
example.com - BTC / ETH / XMR address indicators
- HTML comments review
- comment-based IP, URL, JWT, private key, and secret-candidate detection
Output
- human-readable Rich table
- JSON output for automation
- optional report file export
Requirements
- Python 3.10+
- Tor SOCKS proxy:
- Tor daemon:
127.0.0.1:9050 - Tor Browser:
127.0.0.1:9150 - Whonix Gateway example:
10.152.152.10:9050
- Tor daemon:
Installation
From PyPI
pipx install onionscout
From GitHub
pipx install git+https://github.com/h0ek/onionscout.git
For local development:
git clone https://github.com/h0ek/onionscout.git
cd onionscout
python3 -m venv .venv
source .venv/bin/activate
python3 -m pip install -U pip
python3 -m pip install -e .
python3 onionscout.py -u <ONION_URL> --skip-tor-check
Usage
onionscout -u <ONION_URL>
Example:
onionscout -u http://exampleonionaddress.onion --skip-tor-check
Use Tor Browser SOCKS:
onionscout -u http://exampleonionaddress.onion --socks 127.0.0.1:9150 --skip-tor-check
Force HTTP:
onionscout -u exampleonionaddress.onion --scheme http
Force HTTPS:
onionscout -u exampleonionaddress.onion --scheme https --insecure-https
Validate a clearnet mirror Onion-Location header against the target onion:
onionscout -u exampleonionaddress.onion --clearnet-url https://mirror.example
Save TXT report:
onionscout -u exampleonionaddress.onion -o report.txt
Save JSON report:
onionscout -u exampleonionaddress.onion --json -o report.json
Disable crawler:
onionscout -u exampleonionaddress.onion --no-crawl
Tune crawler:
onionscout -u exampleonionaddress.onion --max-urls 150 --depth 2
Tune timeouts:
onionscout -u exampleonionaddress.onion --http-timeout 20 --ssh-timeout 8 --tls-timeout 12
Authenticated scans
Some onion services require an authenticated session. You can pass a raw HTTP Cookie header with --cookie. The cookie is scoped by onionscout to the selected target onion host and is not sent to the Tor connectivity check or blocked off-target URLs.
Example:
onionscout -u http://exampleonionaddress.onion --cookie 'access=abcd1234'
For multiple cookies, use the normal HTTP header format:
onionscout -u http://exampleonionaddress.onion --cookie 'access=VALUE; session=VALUE2; csrftoken=VALUE3'
How to get the cookie value from a browser:
- Log in to the target service.
- Open Developer Tools.
- Go to Storage / Cookies.
- Select the target onion domain.
- Copy the cookie name and value.
- Pass it as
name=value.
Do not share session cookies. They are equivalent to temporary access tokens for your logged-in session.
Options
-u, --url Target .onion URL
--scheme Origin scheme mode: auto, http, https
--socks SOCKS5h proxy, default 127.0.0.1:9050
--skip-tor-check Skip check.torproject.org connectivity check
--http-timeout HTTP timeout
--ssh-timeout SSH timeout
--tls-timeout TLS timeout
--ssh-port SSH port for fingerprint check
--retries Retries for transient onion/Tor errors
--cookie Raw HTTP Cookie header, e.g. 'access=VALUE; session=VALUE2'
--clearnet-url Optional clearnet mirror URL for Onion-Location validation
--insecure-https Disable HTTPS certificate verification for HTTP requests
--no-crawl Disable crawler-based checks
--max-urls Crawler URL limit
--depth Crawler depth
--json Output JSON
-o, --output Save report to file
Notes
- Most onion services use plain HTTP internally; HTTPS is supported when present.
- In
automode, onionscout tests available origins and chooses a working HTTP or HTTPS origin. - Redirects are followed only when they stay on the selected target onion host; clearnet and cross-onion redirects are reported instead of being fetched.
- Some findings are context-dependent. For example, public social links may be intentional, while active clearnet scripts are usually more relevant for anonymity risk.
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file onionscout-0.2.0.tar.gz.
File metadata
- Download URL: onionscout-0.2.0.tar.gz
- Upload date:
- Size: 29.8 kB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.12
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
94272b3d0c967f0647b4c9f35a2abb822dea92f9b0f4824875969676b7dd3926
|
|
| MD5 |
c5ddf8599f8aead9a78f698a6286f5d9
|
|
| BLAKE2b-256 |
59ecb3bee36d86f60432412286715df66bc562a93300c1ce8aabbeedb51158e2
|
Provenance
The following attestation bundles were made for onionscout-0.2.0.tar.gz:
Publisher:
release.yml on h0ek/onionscout
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
onionscout-0.2.0.tar.gz -
Subject digest:
94272b3d0c967f0647b4c9f35a2abb822dea92f9b0f4824875969676b7dd3926 - Sigstore transparency entry: 2058603996
- Sigstore integration time:
-
Permalink:
h0ek/onionscout@c197dbba1efa49a7957e0552a29873669a1ba911 -
Branch / Tag:
refs/tags/v0.2.0 - Owner: https://github.com/h0ek
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@c197dbba1efa49a7957e0552a29873669a1ba911 -
Trigger Event:
push
-
Statement type:
File details
Details for the file onionscout-0.2.0-py3-none-any.whl.
File metadata
- Download URL: onionscout-0.2.0-py3-none-any.whl
- Upload date:
- Size: 29.8 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.12
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
8b28f05e84cbe2116527a71e2a53d877602f3ab925e55dc9ffa16adcd738306b
|
|
| MD5 |
f5dfc89cad7d39e27fb2a756081912aa
|
|
| BLAKE2b-256 |
3b19c28735bb2ba8a7798aa5e2421575f924f0746238aa258eb606d47b460ca9
|
Provenance
The following attestation bundles were made for onionscout-0.2.0-py3-none-any.whl:
Publisher:
release.yml on h0ek/onionscout
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
onionscout-0.2.0-py3-none-any.whl -
Subject digest:
8b28f05e84cbe2116527a71e2a53d877602f3ab925e55dc9ffa16adcd738306b - Sigstore transparency entry: 2058604176
- Sigstore integration time:
-
Permalink:
h0ek/onionscout@c197dbba1efa49a7957e0552a29873669a1ba911 -
Branch / Tag:
refs/tags/v0.2.0 - Owner: https://github.com/h0ek
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@c197dbba1efa49a7957e0552a29873669a1ba911 -
Trigger Event:
push
-
Statement type: