Add perimeterlens to Domain Name > Subdomains - #774
Open
NicklasSandin wants to merge 1 commit into
Open
NicklasSandin wants to merge 1 commit into
NicklasSandin wants to merge 1 commit into
Conversation
Zero-dependency Node.js CLI: passive CT-log subdomain discovery, email spoofability (SPF/DMARC/DKIM/BIMI/MTA-STS), and TLS certificate health, rolled into one composite score. MIT licensed, no telemetry, 73 passing tests. https://github.com/NicklasSandin/perimeterlens
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Adds perimeterlens under
Domain Name > Subdomains, alongside the other CT-log/subdomain-discovery entries in that category (crt.sh, certgraph, etc.).What it is: a free, MIT-licensed, zero-runtime-dependency Node.js CLI that gives a passive exposure read on a domain you own — certificate-transparency-log subdomain discovery, email spoofability (SPF/DMARC/DKIM/BIMI/MTA-STS), and TLS certificate health (expiry, chain trust, protocol), rolled into one composite 0-100 score.
Why this category: its subdomain-discovery mechanism (CT-log search) is the same technique as
crt.sh/certgraph, already listed here — the local-install(T)marker andopsec: passivematch that pattern.Honesty note (per the guidelines in this repo's README): it does not do HTTP security-header grading — that's explicitly out of scope, and the tool's own README points users to Mozilla HTTP Observatory / SecurityHeaders.com for that instead of duplicating it.
I'm the maintainer of this tool, flagging that per the framework's own contribution note ("you don't have to be the author of the tool" implies authorship should be disclosed when it applies).