The 200,000-row baseline serves one specific investigation loop
XCheck takes IP addresses from manual input or common log and spreadsheet formats, validates them, removes duplicates, asks a whitelist service for exclusions, and submits the remaining public addresses to ThreatBook. The README calls a 200,000-row CSV its current acceptance baseline. This is a focused analyst workflow, not a general threat-intelligence database. That focus makes the product legible within a few minutes.
Each task keeps the original upload, checkpoints, whitelist decisions, ThreatBook batches, diagnostics, and final intelligence in local storage. The browser gets paginated results and bounded dashboard summaries instead of the complete dataset. Operators can export TXT or XLSX files at processing stages such as valid, invalid, deduplicated, malicious, non-malicious, and failed. The evidence trail is the feature, especially when one source file becomes several external API batches.
Our 106-test run passed, while the audit found 2 vulnerabilities
Our sandbox installed commit c6c9661 in 33 seconds. The Python 3.12 environment added 66 packages and occupied 117 MB on disk. The build finished in 4 seconds, and pytest completed in 63 seconds with 106 passed and 0 failed. That is a clean functional result for the repository at the tested commit. Pip-audit separately reported 2 known vulnerabilities, so passing tests should not close the dependency review.
The checkout was modest at 102 files, roughly 10,647 source lines, and 1 MB before installation. It has one CI workflow, a Dockerfile, a Compose file, and a tests directory. Those pieces match the operational story in the README. They also make this easier to inspect than a sprawling security platform. The missing step is deciding whether the two audit findings affect your deployment, which the supplied measurement does not classify for us.
What happened when we ran it
Our run used an unprivileged Debian container with 3 CPUs, 8 GB of RAM, Python 3.12, and no secrets. Installation, build, and all 106 tests completed within 100 seconds combined. We did not connect to ThreatBook, call a whitelist service, upload a 200,000-row CSV, or measure query throughput. The result proves the local code checks passed, not that an external intelligence account or production rate limit will behave the same way.
Pip-audit found 2 known vulnerabilities after the 66-package install. The measurement block does not name their packages, advisories, or severities, so any stronger description would be guesswork. Before deployment, reproduce the audit against the pinned environment, identify the affected paths, and decide whether an upgrade is available. The project was only 117 MB after installation, which makes a clean-room recheck inexpensive.
Port 8086 belongs on a trusted network
XCheck listens on 0.0.0.0:8086, and the security boundary is unusually direct: there is no login or role system. Any user who can reach the service can inspect retained tasks, change integration endpoints, and replace or clear the saved ThreatBook credential. The app should sit behind a restrictive firewall. Public access also requires authentication, authorization, TLS, and request protections that this repository does not provide.
The workflow does place useful brakes around outbound queries. Unknown or invalid whitelist conclusions do not bypass the gate. An operator must confirm whitelist exclusions and then start the ThreatBook query. Batch size, safe IP rate, daily budget, and retry limits are configurable. That human checkpoint reduces accidental API spending, but it cannot distinguish two people who share network access because XCheck has no user identities.
Local persistence deserves the same care as the network edge. The bound data/ directory contains SQLite state and uploaded source files, while the database stores the ThreatBook key. Version 1 has no history-deletion feature. A backup must include the whole directory and preserve WAL consistency, either through a live-safe method or by stopping the container before copying the three SQLite files.
v0.1.0 is a good pilot, not a finished security control plane
XCheck v0.1.0 shipped on September 7, 2026, and the repository was pushed again on September 21. GitHub showed 71 stars, no open issues, and one closed documentation issue when checked. That is recent maintenance, but there is little public issue history from which to judge long-term support. The Apache-2.0 license is straightforward, while access to ThreatBook remains a separate commercial and policy question.
For an existing ThreatBook customer, XCheck is a credible pilot because our 106-test run passed and the docs state the security limits without euphemism. Its narrowness is a strength when analysts need to clean large IP lists and preserve every decision. Keep it private, resolve the 2 audit findings, and decide how records will eventually be deleted before calling it production infrastructure.

