Profile parsing
Pulls public details and linked accounts from profile pages; enabled by default and can be switched off.
Maigret OSINT searches go further than most username tools: Maigret checks thousands of sites, reads what it finds on each profile, and uses new usernames and IDs from those pages to search again. The output is closer to a dossier than a list of links, which makes it powerful and makes errors and privacy problems spread faster.
Maigret is a free, open-source Maigret OSINT tool that collects a dossier on a person from a username alone. It checks thousands of sites, extracts profile details, follows linked accounts and produces HTML, PDF and graph reports. It is written in Python under the MIT license. The developer also offers a private database and API for commercial users; prices are not published.
It finds accounts by username, extracts what each profile publicly shows, and starts new searches from the usernames and IDs it discovers.
The documentation describes Maigret as a tool "for collecting a dossier on a person by a username (alias) only", with no API keys required (Maigret docs). Three things set it apart from simple checkers. It parses account pages and site APIs to pull out details such as names, locations, avatars, creation dates and links to other profiles. It runs recursive searches using the usernames and IDs found in those details. And it turns the results into reports rather than a plain list.
The project is active. On 10 October 2026 the repository showed about 37,300 stars and 1,576 commits, and four releases reached PyPI between July and September 2026, the latest being 0.6.6 on 18 September (PyPI). This review is based on the repository, changelog and documentation as published on 10 October 2026.
Search, extraction, recursion and reporting, with several ways to run it.
Pulls public details and linked accounts from profile pages; enabled by default and can be switched off.
Searches again with newly found usernames and IDs, or starts from a profile URL you supply.
Also JSON, CSV, TXT, an interactive graph and a Neo4j export for graph databases.
A default run checks the 500 highest-ranked sites; tags narrow by category or country, and one flag scans everything.
A command-line tool, a local web interface with a results graph, Docker images and a Python library.
Routes checks through proxies, Tor or I2P, with an experimental Cloudflare challenge workaround.
It depends where you look: the 0.6.6 changelog says 5,203 enabled sites, the README says 5,900 supported, and the GitHub description still says 3,000+.
The changelog for 0.6.6 states that the site database doubled, from 2,611 enabled sites in 0.6.5 to 5,203 (CHANGELOG). The README speaks of 5,900 supported sites and the repository description of 3,000+ (repository). Treat any headline count as approximate; the changelog figure is the one tied to a specific release.
Two practical points matter more than the headline. First, a default run checks only the top 500 sites by traffic; the full database runs only when you ask for it. Second, Maigret fetches an updated site database from GitHub once every 24 hours, so two runs a week apart may check different sites. Record the version and date of every run you rely on.
Recursion finds accounts a simple checker misses, but one false match early in the chain carries every later result with it.
Suppose a handle matches an unrelated person's profile on a forum, and that profile links to a second username. Maigret will search the second username, parse what it finds, and present the whole chain in one report. Every result after the first wrong step belongs to someone else, yet it looks just as authoritative as the rest.
The safeguard is to treat each hop as a separate claim. Before relying on anything found recursively, confirm the link that led to it with independent signals such as the same original photo, shared contact details or reciprocal links. Extracted fields such as "location" or "full name" are whatever the profile owner typed, which may be a joke, an old city or someone else's name.
The open-source tool is free, including for commercial use. A private, daily-updated database and a username-check API are sold separately on request.
| Option | Cost | Notes |
|---|---|---|
| Open-source Maigret (pip, Docker, Snap, Windows executable) | Free | MIT license; free for commercial use, per the README |
| Community Telegram bot | Free | Community-maintained; may move between hosting providers |
| Private site database (5,000+ sites, updated daily) | Not published | Contact the developer by email |
| Username-check API | Not published | For integrating Maigret into products |
Checked 10 October 2026 on the repository. The README lists commercial tools built on Maigret, including Social Links products; see our Social Links review for that platform.
The features that make Maigret useful also raise data protection and terms-of-service questions you should settle before running it.
The optional AI mode sends a report of the findings to an OpenAI-compatible API and returns a summary including likely real name, location and occupation. That is a transfer of personal data to a third party, which needs a lawful basis and a processing agreement.
The Telegram bot is community-run, and the README notes that its one-click hosted web interface has no login, so anyone with the URL can use it. Do not route sensitive matters through either.
Rotating proxies and the experimental Cloudflare workaround can conflict with site terms that prohibit automated access. Decide in advance which features your policy allows.
Maigret's own disclaimer limits it to lawful use and names GDPR and CCPA compliance as the user's responsibility. A compiled profile of a private person needs a purpose that justifies it.
Run it for a defined, lawful purpose, collect only what that purpose needs, and never to profile or track a private person without justification.
Under the GDPR, building a profile of an identifiable person needs a lawful basis, transparency where required, and data minimization (GDPR). Regulators have said jointly that personal data posted publicly is still protected (joint statement on data scraping). In practice, switch off extraction or recursion when the purpose does not need them, delete what turns out to be irrelevant, and keep special category details such as health, sex life or political opinions out of reports unless strictly necessary.
Use Sherlock for a quick yes-or-no pass; use Maigret when you need profile details and linked accounts, and have time to verify them.
Sherlock checks about 480 sites and reports URLs. Maigret checks far more and returns structured details, reports and a graph, at the cost of longer runs and more material to verify. WhatsMyName offers a free browser interface and an open dataset, and Blackbird adds a small set of email checks. For tools beyond username search, see our OSINT tools guide.
If a decision depends on who is behind a username, you need verified links and a documented method, not a raw dossier.
A Maigret report can contain hundreds of findings, some about the wrong person. Our username investigations test each candidate link, grade it and record rejected matches, and our social media investigations analyze confirmed accounts in context. Work is quoted at a fixed price after written scoping, and a senior analyst reviews every report before delivery. Read more about our OSINT services and how we work.
Send the username and the decision you need to make. We reply with a scope, a fixed quote and a delivery date.
Maigret goes beyond confirming that accounts exist. It parses public profile details, follows linked usernames and IDs in recursive searches, and produces HTML, PDF and graph reports. The open-source tool is MIT-licensed, and the README states it is free for commercial use (repository). A private, daily-updated database and an API are offered separately, with prices available only on request.
The documentation describes the Telegram bot as community-maintained and notes it may move between hosting providers (Maigret features). Its source code is public, but you do not control the instance. Avoid it for confidential matters, because whoever operates it can see what you search. The Windows executable, Snap package or Docker image avoid a Python install while keeping searches on your own machine.
The 0.6.6 changelog of 18 September 2026 reports 5,203 enabled sites, up from 2,611 (CHANGELOG). The README says 5,900 supported and the repository description still says 3,000+. A default run checks only the top 500 sites by traffic; the full database is scanned only when you request it. The database also updates daily, so note the version and date of each run.
Treat them as claims, not facts. Extracted fields are whatever the profile owner entered, which may be outdated, invented or copied. A recursive search can also attach details from an unrelated person's profile if one early match was wrong. Confirm any detail you intend to act on with independent sources, and check that the profile it came from is linked to your subject by more than a shared handle.
The AI mode sends a report of findings to an OpenAI-compatible API, so personal data about your subject leaves your environment. Under the GDPR that requires a lawful basis, a processing agreement with the provider and attention to international transfers. The summary also infers attributes such as real name and occupation, which may be wrong. Many teams keep AI summaries off for casework involving private individuals.
Yes, an exposure review of your own executives, with their knowledge, is a legitimate and common use. Agree the scope with them, run it from a managed environment, and store results securely because the report itself is a target. Expect false matches on common handles and verify before acting. A structured digital footprint assessment adds removal advice and covers sources beyond username search.
Sources checked 10 October 2026. Figures about third-party firms and tools are as published by them or by the cited source on that date.