mrkeyoor.com_
Wed 30 Sept 15:08 UTC
Dev Toolsevaluationupdated 30 Sept 2026

GhostTrack review

GhostTrack is a small interactive Python menu for looking up IP metadata, phone-number metadata, and possible social profiles for a username. Its name overpromises: it does not provide live phone or device tracking, and its results are only as good as a public IP service, the phonenumbers database, and simple website status checks.

Verdict

Our GhostTrack run installed 36 packages and built in 26 seconds combined, but the repository had no test target and its last default-branch push was in January 2024. Treat it as a 316-line learning script, not a dependable tracking product. For real work, use a focused maintained tool, verify every result, and never mistake phone-number metadata or IP geolocation for a person's live position.

We ran it

Lab card: what happened when we ran GhostTrackScreenshot of GhostTrack (github.com/HunxByts/GhostTrack)
Install✓ · 19s36 packages · 60 MB
Build✓ · 7s
Testsn/ano test script
Known vulns0(pip-audit)
Repo8 files~316 lines of source · 0.2 MB · 0 CI workflows

Answers from our run

Does GhostTrack build from source?

Dependencies installed in 19 seconds (36 packages), and the build succeeded in 7 seconds. We cloned commit a5cb8ad into a clean Debian container with 3 CPUs and no project-specific setup.

Does GhostTrack have tests you can run?

Not through a standard command: the project exposes no test script or target that our harness could run.

Does GhostTrack have known vulnerabilities in its dependencies?

pip-audit found none in the dependency tree at the time of our run.

Who should not use GhostTrack?

Anyone trying to locate a phone or person in real time: the phone option returns numbering-plan metadata, not GPS or cell-tower data.

What are the alternatives to GhostTrack?

Sherlock, PhoneInfoga, IPinfo CLI. Our GhostTrack run installed 36 packages and built in 26 seconds combined, but the repository had no test target and its last default-branch push was in January 2024.

Setup4/519-second install and 7-second build, with a simple menu
Docs2/5Basic Linux and Termux steps, but no accuracy or data-source limits
Community2/515,821 stars, but no default-branch push since January 2024
Maturity1/5No tests, release, license, structured output, or network hardening

Who it’s for

Python beginners who want to read a compact command-line OSINT example.
Analysts doing a quick first pass on an IP address or their own phone-number formatting.
Investigators who will verify every username hit manually and have authorization to research the subject.
Termux users who accept a menu-only script with no export or automation interface.

Who it’s NOT for

Anyone trying to locate a phone or person in real time: the phone option returns numbering-plan metadata, not GPS or cell-tower data.
Professional username investigations: the script treats any HTTP 200 response as a found account, uses no site-specific checks, and includes a duplicate Snapchat entry.
Privacy-sensitive IP work: the code sends the queried address to ipwho.is over plain HTTP.
Teams that need a reusable library, structured output, timeouts, or error recovery: the interface is interactive and several network lookups index response fields directly.
Organizations that require clear reuse terms: GitHub reported no license for the repository.

Setup reality

Our sandbox installed commit a5cb8ad in 19 seconds, adding 36 Python packages and using 60 MB on disk. The build succeeded in 7 seconds. There was no test script or target, so tests were skipped; pip-audit reported 0 known vulnerabilities.

The script needs Python 3, requests, phonenumbers, and network access to ipwho.is, ipify, and every social site in its username list. It asks for values through an interactive menu and has no API keys or config file.

Phone numbers without a country prefix default to Indonesia, and location labels come back in Indonesian. IP lookups use plain HTTP and assume every expected response field exists. Username requests have no timeout, so one slow site can hold up the whole scan.

GhostTrack looks up metadata rather than tracking devices

The name and menu labels set the wrong expectation. GhostTrack does not follow a phone, open a GPS feed, or locate a person through cell towers. Its phone option parses a number with the Python phonenumbers package and prints region, timezone, carrier, validity, formatting, and number type. That can help normalize a number. It cannot tell you where the handset is now.

The entire project is 8 files and about 316 lines of source. Its main script offers 4 actions: IP lookup, show your public IP, phone-number lookup, and username lookup. Everything runs through a terminal menu. There are no command-line flags, reusable functions documented as an API, output files, or JSON export. The small size makes the code easy to inspect before use.

IP results come from one plain-HTTP request

The IP option sends the supplied address to http://ipwho.is/ and prints fields from the JSON response. Those fields include country, city, coordinates, postal code, ASN, organization, ISP, domain, and timezone. The map link rounds latitude and longitude down to integers, then opens Google Maps at zoom level 8. That is database geolocation, usually an estimate for a network block, not proof of a device's street address.

Plain HTTP is a poor choice for a research input. Anyone able to observe that connection may see the queried IP address or alter the response in transit. The function also indexes expected fields directly, so a missing timezone.current_time value can crash it. Open pull request 119 proposes a fallback for that exact field, but it had not been merged into the last pushed default branch.

What happened when we ran it

Our sandbox cloned commit a5cb8ad into an unprivileged Debian container with 3 CPUs, 8 GB of RAM, Python 3.12, and no secrets. Installation finished in 19 seconds, adding 36 packages and consuming 60 MB on disk. The package build succeeded in 7 seconds. Pip-audit reported 0 known vulnerabilities.

There was no test script or target, so tests were skipped. The scan found no CI workflow files, Dockerfile, or tests directory. We did not enter third-party phone numbers, IP addresses, or usernames into the interactive program. The run proves that the 0.2 MB checkout installs and builds in this container; it says nothing about lookup accuracy or the availability of outside services.

That distinction is especially important here because almost every useful result arrives from changing external data. IP records move, phone metadata ages, websites redesign their profile routes, and some services return a friendly 200 page for usernames that do not exist. A successful 7-second build cannot check any of those conditions without a maintained set of fixtures and network tests.

Phone metadata defaults to Indonesia

Numbers without an international prefix are parsed with ID as the default region. The geocoder also requests descriptions in Indonesian. A user who enters a local-format number from another country can therefore start with the wrong assumption. The screen does print validity, possibility, E.164 format, region, and number type, which gives a careful operator clues to inspect.

Open issue 130 says the phone search returned incorrect information, though the report contains no reproducible example. Other issue threads ask for a phone's location, showing how easily the label "Phone Tracker" can be misunderstood. The code never contacts a carrier location service. It reads static numbering metadata from the installed library.

Username matches are only HTTP status guesses

The username loop formats one name into a list of social URLs and sends a GET request to each. A status of 200 becomes a positive match; every other status becomes "not found." There is no site-specific error-page signature, redirect analysis, rate-limit handling, authentication, or response-body check. Snapchat appears twice in the list, and some named services have changed or closed since the script was written.

Each request also lacks a timeout. A slow or blocked site can delay the entire sequential scan, which helps explain the open 2026 pull request aimed at username timeout behavior. Professional username tools maintain per-site rules precisely because a 200 response may be a login page, soft error, bot challenge, or generic profile shell. Every GhostTrack hit needs a human visit and an identity check.

The repository has attention without maintainer movement

GitHub showed 15,821 stars and 123 combined open issues and pull requests on September 30, 2026. Fetching both API pages split that backlog into 92 issues and 31 pull requests. New submissions continued through September, yet the default branch's last push was January 11, 2024. No GitHub release exists, and the repository API reported no license.

That is activity around the project, not evidence that fixes are landing. Current reports include missing modules, incorrect phone information, and many low-information requests containing personal-looking numbers or names. The README offers installation and four screenshots but does not explain accuracy, consent, retention, or legal boundaries. Do not post a target's personal data to the public issue tracker.

GhostTrack is readable enough to teach a beginner how three lookup techniques work, and our 26-second combined install and build makes that lesson easy to start. It is a poor choice for an investigation you need to defend. Use IPinfo CLI for IP data, PhoneInfoga for phone research, or Sherlock for usernames, then document the source and verify each result. Whatever tool you choose, work only with lawful authorization and never call coarse metadata a live location.

Alternatives

ProjectWhat it isPick it when
Sherlock gh↗A dedicated username-search tool with site-specific handling and structured options.pick this instead when username discovery is the main task and false hits need better controls.
PhoneInfoga gh↗A phone-number information-gathering framework with a larger, documented workflow.pick this instead when phone metadata is the focus and you understand that it still cannot provide live location.
IPinfo CLIThe official command-line client for IPinfo's IP data service.pick this instead when you need scriptable IP lookups and a maintained data-service client.

What people are saying

  1. [github-trending] HunxByts/GhostTrack

Sources

  1. GhostTrack repository and README
  2. GhostTrack main Python script
  3. Phone information accuracy report, issue 130
  4. Missing IP response field fix, pull request 119

More dev tools reviews

Codex-Dream-Skin · TokenTracker · firebase-ios-sdk · awesome-cli-apps · swiftui-logo-draw · RTX40MFG-Unlock · the whole board →