mrkeyoor.com_
Thu 01 Oct 08:17 UTC
Self-Hostedevaluationupdated 01 Oct 2026

8086-xcheck-system review

XCheck is a self-hosted web app for cleaning large lists of IP addresses, removing whitelist matches, and sending the remainder to ThreatBook for reputation checks. The interface is English-first with complete Simplified Chinese switching, and the repository also provides a Chinese README.

Verdict

Our XCheck run installed 66 packages in 33 seconds and passed all 106 tests, but pip-audit still found 2 known vulnerabilities. Use it when your team already relies on ThreatBook, works on a trusted network, and wants a careful human gate before paid reputation queries. Skip it for public or multi-user deployment until you add authentication, authorization, TLS, and a supported deletion policy.

We ran it

Lab card: what happened when we ran 8086-xcheck-systemScreenshot of 8086-xcheck-system (github.com/LuckinSven/8086-xcheck-system)
Install✓ · 33s66 packages · 117 MB
Build✓ · 4s
Tests✓ · 63s106 passed · 0 failed of 106 (pytest)
Known vulns2(pip-audit)
Repo102 files~10,647 lines of source · 1 MB · 1 CI workflows · Dockerfile · tests dir

Answers from our run

Does 8086-xcheck-system build from source?

Dependencies installed in 33 seconds (66 packages), and the build succeeded in 4 seconds. We cloned commit c6c9661 into a clean Debian container with 3 CPUs and no project-specific setup.

Do 8086-xcheck-system's tests pass?

Yes: 106 of 106 passed when we ran the project's own test command (pytest). Some failures need services or credentials a bare container does not have.

Does 8086-xcheck-system have known vulnerabilities in its dependencies?

pip-audit flagged 2 known advisories in the dependency tree at the time of our run.

Who should not use 8086-xcheck-system?

Anyone planning to expose it directly to the internet: the README says XCheck has no login or role system, and any reachable user can change endpoints or replace the ThreatBook key.

What are the alternatives to 8086-xcheck-system?

IntelOwl, MISP, CrowdSec. Our XCheck run installed 66 packages in 33 seconds and passed all 106 tests, but pip-audit still found 2 known vulnerabilities.

Setup4/533-second install and 106 passing tests; integrations still required
Docs5/5Clear deployment, workflow, backup, and security boundaries
Community2/571 stars, one closed issue, and no open issue queue
Maturity3/5v0.1.0 is tested, but auth and history deletion are absent

Who it’s for

Security operations teams that already use ThreatBook and a whitelist service.
Analysts processing large CSV, spreadsheet, log, ZIP, or JSONL files on a trusted network.
Operators who need resumable checkpoints and exports for each stage of an IP investigation.
Small teams comfortable running one Docker Compose service with local SQLite storage.

Who it’s NOT for

Anyone planning to expose it directly to the internet: the README says XCheck has no login or role system, and any reachable user can change endpoints or replace the ThreatBook key.
ARM-only operators who need the published image: release tags currently publish AMD64 images.
Teams that require record deletion from the interface: version 1 intentionally has no history-deletion feature.
Security stacks that do not use ThreatBook or cannot supply a compatible whitelist service, since both integrations shape the main workflow.
Organizations that require a clean dependency audit before deployment: our pip-audit reported 2 known vulnerabilities.

Setup reality

Our sandbox installed commit c6c9661 in 33 seconds, adding 66 packages and using 117 MB on disk. The build succeeded in 4 seconds. Pytest then completed in 63 seconds with 106 passed and 0 failed, while pip-audit reported 2 known vulnerabilities.

A useful deployment needs Docker Compose, a ThreatBook API key, and a working whitelist endpoint. Operators must also choose batch size, query rate, daily budget, and retry limits. Saved settings live in the local database and override the first-start environment values.

The published container listens on port 8086 and targets AMD64. XCheck has no authentication, authorization, or TLS, so the host firewall or a trusted reverse proxy must supply the boundary. Backups must preserve SQLite WAL consistency and include uploaded source files.

The 200,000-row baseline serves one specific investigation loop

XCheck takes IP addresses from manual input or common log and spreadsheet formats, validates them, removes duplicates, asks a whitelist service for exclusions, and submits the remaining public addresses to ThreatBook. The README calls a 200,000-row CSV its current acceptance baseline. This is a focused analyst workflow, not a general threat-intelligence database. That focus makes the product legible within a few minutes.

Each task keeps the original upload, checkpoints, whitelist decisions, ThreatBook batches, diagnostics, and final intelligence in local storage. The browser gets paginated results and bounded dashboard summaries instead of the complete dataset. Operators can export TXT or XLSX files at processing stages such as valid, invalid, deduplicated, malicious, non-malicious, and failed. The evidence trail is the feature, especially when one source file becomes several external API batches.

Our 106-test run passed, while the audit found 2 vulnerabilities

Our sandbox installed commit c6c9661 in 33 seconds. The Python 3.12 environment added 66 packages and occupied 117 MB on disk. The build finished in 4 seconds, and pytest completed in 63 seconds with 106 passed and 0 failed. That is a clean functional result for the repository at the tested commit. Pip-audit separately reported 2 known vulnerabilities, so passing tests should not close the dependency review.

The checkout was modest at 102 files, roughly 10,647 source lines, and 1 MB before installation. It has one CI workflow, a Dockerfile, a Compose file, and a tests directory. Those pieces match the operational story in the README. They also make this easier to inspect than a sprawling security platform. The missing step is deciding whether the two audit findings affect your deployment, which the supplied measurement does not classify for us.

What happened when we ran it

Our run used an unprivileged Debian container with 3 CPUs, 8 GB of RAM, Python 3.12, and no secrets. Installation, build, and all 106 tests completed within 100 seconds combined. We did not connect to ThreatBook, call a whitelist service, upload a 200,000-row CSV, or measure query throughput. The result proves the local code checks passed, not that an external intelligence account or production rate limit will behave the same way.

Pip-audit found 2 known vulnerabilities after the 66-package install. The measurement block does not name their packages, advisories, or severities, so any stronger description would be guesswork. Before deployment, reproduce the audit against the pinned environment, identify the affected paths, and decide whether an upgrade is available. The project was only 117 MB after installation, which makes a clean-room recheck inexpensive.

Port 8086 belongs on a trusted network

XCheck listens on 0.0.0.0:8086, and the security boundary is unusually direct: there is no login or role system. Any user who can reach the service can inspect retained tasks, change integration endpoints, and replace or clear the saved ThreatBook credential. The app should sit behind a restrictive firewall. Public access also requires authentication, authorization, TLS, and request protections that this repository does not provide.

The workflow does place useful brakes around outbound queries. Unknown or invalid whitelist conclusions do not bypass the gate. An operator must confirm whitelist exclusions and then start the ThreatBook query. Batch size, safe IP rate, daily budget, and retry limits are configurable. That human checkpoint reduces accidental API spending, but it cannot distinguish two people who share network access because XCheck has no user identities.

Local persistence deserves the same care as the network edge. The bound data/ directory contains SQLite state and uploaded source files, while the database stores the ThreatBook key. Version 1 has no history-deletion feature. A backup must include the whole directory and preserve WAL consistency, either through a live-safe method or by stopping the container before copying the three SQLite files.

v0.1.0 is a good pilot, not a finished security control plane

XCheck v0.1.0 shipped on September 7, 2026, and the repository was pushed again on September 21. GitHub showed 71 stars, no open issues, and one closed documentation issue when checked. That is recent maintenance, but there is little public issue history from which to judge long-term support. The Apache-2.0 license is straightforward, while access to ThreatBook remains a separate commercial and policy question.

For an existing ThreatBook customer, XCheck is a credible pilot because our 106-test run passed and the docs state the security limits without euphemism. Its narrowness is a strength when analysts need to clean large IP lists and preserve every decision. Keep it private, resolve the 2 audit findings, and decide how records will eventually be deleted before calling it production infrastructure.

Alternatives

ProjectWhat it isPick it when
IntelOwlA broader threat-intelligence analysis platform with many analyzers and connectors.pick this instead when IP checks are one part of a wider observable-analysis workflow.
MISPA platform for storing, correlating, and sharing structured threat intelligence.pick this instead when collaboration and indicator sharing matter more than file-based ThreatBook triage.
CrowdSec gh↗A detection and remediation engine that turns logs into decisions about hostile IPs.pick this instead when automated blocking from live logs matters more than an analyst-led investigation queue.

What people are saying

  1. [velocity-scout] LuckinSven/8086-xcheck-system

Sources

  1. XCheck README
  2. XCheck repository
  3. XCheck v0.1.0 release
  4. Support and security guidance issue

More self-hosted reviews

Spun · bankmcp · fanzha-ai-proxy · homarr · search-plugins · vphone-web · the whole board →