mrkeyoor.com_
Thu 01 Oct 19:42 UTC
Dataevaluationupdated 26 Aug 2026

Crucix review

Crucix is a self-hosted dashboard that polls 27 public-data and OSINT sources every 15 minutes, then combines news, markets, aircraft, fires, radiation, satellites, and conflict signals in one interface. Optional LLM, Telegram, Discord, and Alpaca connections add summaries, alerts, commands, and trading actions.

+35stars / 7d
Verdict

Our Crucix install took 14 seconds and 31 MB, but there was no build or test target and npm audit found 6 known vulnerabilities, so this is a localhost experiment rather than an intelligence system to trust. Its 27-source dashboard is useful for spotting topics to investigate. Do not expose it publicly, automate trades from its output, or cite a location or timestamp without opening the original source.

We ran it

Lab card: what happened when we ran CrucixScreenshot of Crucix (crucix.live)
Install✓ · 14s89 packages · 31 MB
Buildn/ano build script
Testsn/ano test script
Known vulns60 critical · 4 high · 1 moderate · 1 low (npm audit)
Repo93 files~10,202 lines of source · 3 MB · 1 CI workflows · Dockerfile · tests dir

Answers from our run

Does Crucix build from source?

Dependencies installed in 14 seconds (89 packages), and the project has no separate build step. We cloned commit 3db7068 into a clean Debian container with 3 CPUs and no project-specific setup.

Does Crucix have tests you can run?

Not through a standard command: the project exposes no test script or target that our harness could run.

Does Crucix have known vulnerabilities in its dependencies?

npm audit flagged 6 known advisories in the dependency tree at the time of our run.

Who should not use Crucix?

Anyone treating map positions as evidence: issue 112 says news coordinates are randomly shifted, and issue 116 says unmatched stories can be pinned to publication centroids.

What are the alternatives to Crucix?

Grafana, Dashy, Metabase. Our Crucix install took 14 seconds and 31 MB, but there was no build or test target and npm audit found 6 known vulnerabilities, so this is a localhost experiment rather than an intelligence system to trust.

Setup4/514-second install, though useful feeds need several keys
Docs4/5Extensive setup and source tables, but safety limits are understated
Community3/511,566 stars; last push May 2026 and 75 issues and PRs
Maturity1/5No tests or releases, plus open data-integrity and access flaws

Discussed on

  1. hnA self-hosted intelligence terminal that watches the world for signals4 points

Who it’s for

OSINT hobbyists who want a local screen for many public feeds.
Researchers willing to verify every important signal against its original source.
Developers studying a small Node.js aggregation service with SSE updates.
Users who can keep the dashboard private and supply only low-risk API keys.

Who it’s NOT for

Anyone treating map positions as evidence: issue 112 says news coordinates are randomly shifted, and issue 116 says unmatched stories can be pinned to publication centroids.
Users relying on ticker recency: issue 115 says GDELT article times are replaced with the current clock.
Public internet deployments: issue 111 reports unauthenticated data, health, locale, and SSE endpoints with no rate limit or CORS restriction.
Automated traders: the README can connect Alpaca, while the repository has no test script and our audit found 6 known vulnerabilities.

Setup reality

Our sandbox installed 89 npm packages in 14 seconds and used 31 MB on disk. Commit 3db7068 had no build script and no test script, so both steps were skipped. Npm audit found 6 known vulnerabilities: 4 high, 1 moderate, and 1 low, with 0 critical.

Node.js 22 or newer is required. Eighteen or more feeds are described as keyless, while FRED, NASA FIRMS, EIA, ACLED, flight, LLM, Telegram, Discord, and Alpaca functions need separate credentials depending on the chosen coverage.

The server listens on port 3117 and writes run data locally. Keep it behind localhost or a private authenticated gateway. Source outages degrade individual panels, and current issues show that some fallbacks can make stale or approximate data look current or precise.

Twenty-seven feeds make a useful watch screen, not verified intelligence

Crucix polls 27 sources covering markets, fires, flights, radiation, satellites, conflict events, sanctions, news, and social channels. Every 15 minutes it synthesizes a new briefing, computes changes, and pushes the result to browsers over server-sent events. The dashboard offers a globe, flat map, tickers, risk gauges, source status, and filters. For one person monitoring broad themes, that is an appealing amount of context on one screen.

The interface also compresses very different evidence into a common visual language. A satellite measurement, a financial quote, a Telegram post, and a geotag inferred from a headline do not carry equal reliability. Crucix can show where to look next. It cannot make those sources mutually confirming merely by drawing them together, so every consequential item needs a link back to its origin and an independent check.

A 14-second install hides the absence of build and test gates

We cloned commit 3db7068 into an unprivileged Debian container with 3 CPUs and 8 GB of RAM. The 3 MB checkout contained 93 files and about 10,202 source lines. Npm installed 89 packages in 14 seconds and used 31 MB on disk. The repository has 1 CI workflow, a Dockerfile, a Compose file, and a tests directory.

Package metadata did not define a build script or test script, so our harness skipped both steps. The presence of a tests directory therefore did not give us a runnable project-wide check. Npm audit found 6 known vulnerabilities in the installed dependency tree: 4 high, 1 moderate, and 1 low, with 0 critical. We did not determine whether each advisory is reachable from the server.

What happened when we ran it

Our sandbox measured installation only: 89 packages in 14 seconds and 31 MB on disk. We did not start port 3117, query the 27 feeds, wait for a sweep, render the WebGL globe, send a bot message, call an LLM, or connect a brokerage account. There are no lab timings for those operations, and the README's 30-to-60-second initial sweep estimate is not our measurement.

With no build or test target, the repository gave us no automated evidence that all source adapters parse current upstream responses or that failed feeds degrade safely. A serious evaluation should add fixture-based tests for every adapter, timestamp preservation, coordinate provenance, stale-data handling, authentication, alert deduplication, and trade-action approval before treating the dashboard as more than exploratory software.

Map coordinates may be approximate or deliberately displaced

Issue 112 points to code that adds random latitude and longitude offsets to geotagged news. A marker may therefore be moved by roughly a degree from the inferred anchor, according to the report. Issue 116 describes another path where an unmatched headline from selected publications receives a hardcoded source-level centroid. Both behaviors favor a populated, readable map over geographic truth.

That trade is unacceptable when the interface looks like an intelligence map and does not make the uncertainty obvious. Use markers as navigation cues only. Open the article, identify a stated place, and compare it with a trusted map before reporting an event location. If geographic accuracy matters, disable news markers until the selected commit has deterministic coordinates, an unknown-location state, and visible provenance.

Current-looking data can come from an older event or run

Issue 115 says GDELT items receive new Date().toISOString() when entering the unified ticker, replacing the article's source time with synthesis time. That can make an older story appear newly published whenever a sweep includes it. Issue 113 says empty OpenSky results can fall back to a prior non-empty run file and expose the old hotspot data with fallback metadata.

The latter report notes that source and prior timestamp information exist in the synthesized output, which is better than a wholly invisible replay. A user scanning the visual layer may still mistake presence for freshness. Panels should display source time, ingest time, and fallback state separately. Until then, treat any urgent-looking ticker or flight signal as unconfirmed and check the source service directly.

Port 3117 belongs on a private interface

The Docker and local instructions expose the dashboard at port 3117. Issue 111 reports that /api/data, /api/health, /api/locales, and /events have no authentication, rate limiting, or CORS restriction. The described data endpoint returns the full briefing, while the health endpoint exposes some configuration state. A public instance could therefore become a feed paid for by the operator's API keys.

Keep Crucix bound to localhost, a private network, or an authenticated reverse proxy whose behavior you have tested. Do not assume an obscure URL is access control. The same caution applies to Telegram, Discord, LLM, and Alpaca secrets in .env. A process with market data, messaging, model access, and trading credentials is a high-value target even if the application code has only one required runtime dependency.

May 2026 activity has no published release checkpoint

GitHub showed 11,566 stars, 75 combined issues and pull requests, and a last push on May 20, 2026. The latest-release endpoint returned Not Found, so there is no GitHub release to pin or use as a changelog checkpoint. The repository is AGPL-3.0 licensed. Teams distributing or offering a modified network service should review those license obligations with appropriate counsel.

Crucix is unusually easy to install for the breadth it attempts, and 18 or more sources reportedly work without keys. Its current trust defects matter more than its visual polish. Run it privately, remove unneeded integrations, retain raw source records, and regard every alert as a lead. A 27-feed collage can save browsing time; it cannot substitute for timestamp, location, transport, and source verification.

Alternatives

ProjectWhat it isPick it when
Grafana gh↗A mature dashboard platform for data sources a team chooses and operates.pick this instead when provenance, access control, alerts, and explicit queries matter more than a prebuilt OSINT screen.
DashyA self-hosted dashboard for links, status data, and widgets.pick this instead when you want a private home dashboard without Crucix's intelligence and trading claims.
Metabase gh↗A self-hosted analytics application for querying controlled data stores.pick this instead when analysts need traceable questions over stored data rather than a live feed collage.

What people are saying

  1. [github-trending] calesthio/Crucix

Sources

  1. Crucix README
  2. Crucix repository facts
  3. Issue 111: unauthenticated endpoints
  4. Issue 112: randomized map coordinates
  5. Issue 113: historical flight fallback
  6. Issue 114: plaintext RSS feeds
  7. Issue 115: rewritten GDELT timestamps
  8. Issue 116: publication-centroid fallback

More data reviews

INSLIB · HowToLiveBetter · TradeGenuis-box · awesome-submitlist · ccf-deadlines · instagram-private-graph · the whole board →