Tblue
614 passive security scanners for any website, runs locally
Details
- External ID
- 49420650
- Source
- HN
- Company
- —
- Product
- Tblue
- Website domain
- github.com
- Launched
- Aug. 24, 2026
- Cohort
- —
- Upvotes
- 15
- Upvotes percentile
- 0.6975806451612904
- Tags
- —
- Fetched at
- Sept. 10, 2026, 5:32 a.m.
- Updated at
- Sept. 10, 2026, 5:32 a.m.
Enrichment
- Theme
- web development and browser utilities
- Vertical
- Security
- Function
- Observability & eval
- Audience
- B2B
- AI stance
- Not AI
- Project type
- Commercial product
- Normalized one-liner
- local security scanning for websites
- Manually corrected
- False
Could you build this?
Partial The scanning CLI and network inspection framework are straightforward to vibe-code, but curating and tuning over 600 accurate passive security checks requires deep AppSec domain knowledge.
What it would actually take: The architecture involves a concurrent network crawler written in Go or Python that passively evaluates HTTP headers, SSL/TLS certificates, DNS records, and DOM artifacts. The hard part is authoring and continuously testing 600+ vulnerability and misconfiguration heuristics against real-world assets to minimize false positive rates, requiring extensive specialized application security expertise.
Discussion
4 comments analyzed.
Concerns raised: Passive mode is not actually passive - performs active scanning by default (port scanning, DNS enumeration, CORS fuzzing), Authenticated scans leak credentials to third parties (crt.sh, HackerTarget, AlienVault OTX, NVD, OSV), Sends potentially consequential payloads (XXE, XSS, Redis commands) without adequate safeguards, Automatically sends findings to Anthropic API for AI analysis unless explicitly disabled, Immature project with suspicious provenance - 160 commits in one day, no releases/tags, misleading documentation
Feature requests: GitHub Actions / CI integration to fail PRs on critical header misconfigurations
Competitors
Other products that read as similar to this one — 414 launches clear the similarity bar, closest 8 shown.
Attention rank: #113 of 415 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).
Launched 292 days after the earliest competitor.
- Smart Scan · hn · 2025-11-24 · 15 upvotes · similarity 0.55
- KhanyaSec · ph · 2026-09-27 · 2 upvotes · similarity 0.54
- web-stealth-farm · github · 2026-09-17 · 12 upvotes · similarity 0.54
- web-stealth-farm · github · 2026-09-20 · 12 upvotes · similarity 0.54
- NC Web · hn · 2026-03-18 · 10 upvotes · similarity 0.54
- OpenHack · hn · 2026-06-04 · 12 upvotes · similarity 0.54
- GetBlocked · hn · 2026-06-27 · 7 upvotes · similarity 0.53
- Sentrint, a security scanner for projects build with LLMs · hn · 2026-08-20 · 6 upvotes · similarity 0.51
Other launches for this product
- No other launches for this product.
Same idea, different domain
Nobody's really built a observability & eval tool for Media & entertainment yet.