200+ modules
Most modules need no API key, and many that do have a free tier, according to the README.
SpiderFoot OSINT automation takes one target, such as a domain, IP address, email or username, and runs it through more than 200 modules to collect what is publicly known about it. This review covers what the open-source tool does, how current it is, who owns it now and where it needs care.
SpiderFoot is a free, MIT-licensed OSINT automation tool written in Python. You give it a target and it queries 200+ modules, then flags notable findings with YAML correlation rules. It suits security teams mapping an organization's external exposure. The last tagged release is v4.0 from April 2022; the commercial SpiderFoot HX belongs to Intel 471 since 2022.
An open-source reconnaissance tool that automates the collection of public data about a target and links the results.
SpiderFoot was created by Steve Micallef and is published on GitHub, where the repository describes it as MIT-licensed, written in Python 3, with over 200 modules, a web interface and a command-line mode (GitHub). It is also packaged in Kali Linux, which lists version 4.0 (Kali tools).
It can be used offensively, to see what an attacker would find before a penetration test, or defensively, to audit what an organization exposes. In our guide to OSINT tools it sits under domains and infrastructure.
Modules collect data, correlation rules flag what matters, and results export to CSV, JSON or GEXF for graph tools.
Most modules need no API key, and many that do have a free tier, according to the README.
Added to the open-source version in 4.0, with 37 predefined YAML rules and support for your own (release notes).
An embedded web server for browsing scans, or fully command-line runs for scripting.
GEXF output opens in graph tools, so results can move into link analysis.
Version 4.0 added modules for tools such as Nuclei, nbtscan, TruffleHog and Wappalyzer.
Dockerfiles for container deployment and Tor integration for dark web searches.
Ten target types, from IP ranges and domains to emails, phone numbers, usernames, names and Bitcoin addresses.
The README lists these target types: IP address, domain or subdomain, hostname, network subnet (CIDR), ASN, email address, phone number, username, person's name and Bitcoin address (GitHub). Sources range from DNS and certificate data to search engines, breach services and threat lists. Some, such as Shodan, Censys and Intelligence X, are marked as tiered APIs; Have I Been Pwned is marked commercial.
Coverage therefore depends on which API keys you add. A scan with no keys is useful for infrastructure; people-related findings get thin without paid sources.
The open-source tool is free under the MIT license; API keys for third-party sources may cost money, and the commercial HX edition's current availability is unclear.
| Edition | Price | Status on 10 October 2026 |
|---|---|---|
| SpiderFoot (open source) | Free, MIT license | On GitHub; last tagged release v4.0 |
| Third-party API keys | Free tiers to paid plans | Set by each data provider |
| SpiderFoot HX (cloud) | Not public | Still promoted in the README; spiderfoot.net now redirects to Intel 471 |
Intel 471 announced the acquisition of SpiderFoot on 2 November 2022 and said it would integrate SpiderFoot's capabilities into its own platform; the founder joined as Vice President of Attack Surface Technology (Intel 471). We could not confirm a current public price or sign-up page for HX, so ask Intel 471 directly.
Install from the official GitHub repository or Kali package; the project still receives commits, but no tagged release has followed v4.0 from April 2022.
The README requires Python 3.7 or later and installs dependencies from requirements.txt; Dockerfiles are included. The v4.0 release, announced in April 2022, is still marked as the latest, and the release page shows 138 commits to master since then (release page). That means fixes land in the main branch without a new version number, so pin a commit and test before upgrading.
One supply-chain warning: the package named spiderfoot on PyPI is a placeholder that PyPI quarantined in September 2026, not the official project (PyPI). Do not install SpiderFoot by name from PyPI.
It suits technical teams auditing their own exposure; it is a poor fit for non-technical users or people searches.
| Good fit | Poor fit |
|---|---|
| Security teams mapping their organization's attack surface | Users who need a finished report rather than raw scan data |
| Authorized penetration testers and red teams in the reconnaissance phase | Background checks on individuals, which need a lawful process |
| Analysts who can run Python or Docker and manage API keys | Teams that need vendor support and a release schedule |
Automated scans produce noise and false positives, some modules touch the target directly, and scanning assets you do not own needs authorization.
Recon-ng and theHarvester are open-source alternatives; Maltego adds link analysis; Shodan and Censys provide internet-wide scan data.
GPL-3.0 reconnaissance framework for web-based information gathering, built around modules (GitHub).
Recon-ng review →Python tool that gathers hostnames, emails, IPs and URLs for a domain from search engines, certificate logs and DNS data (GitHub).
theHarvester review →Graph-based investigation platform with a free Community Edition and paid plans from €3,000 a year.
Maltego review →Search engines for internet-connected hosts and services, also available as SpiderFoot modules.
Shodan and Censys review →If you need a reviewed picture of your external exposure rather than raw scan output, an analyst-led review is the faster route.
A SpiderFoot scan lists what is out there; a security decision needs to know which findings matter and what to fix first. Our red team OSINT reconnaissance runs under written authorization, and an organizational OSINT exposure audit turns findings into a prioritized list. For a single site, see website and domain investigations.
Every report gets a senior analyst review, with a fixed quote after written scoping. See our OSINT services for the full range.
Tell us your domains, the scope you are authorized to test and your deadline. We scope it in writing and quote a fixed fee.
Yes, the open-source SpiderFoot is free under the MIT license. It needs Python 3.7 or later, or Docker, and runs from a web interface or the command line (GitHub). Many of its 200+ modules work without API keys, but richer results depend on third-party keys, some paid. Install it from the official GitHub repository or the Kali package, not from a package named spiderfoot on PyPI.
The latest tagged release is still v4.0 from April 2022, but the release page shows 138 commits to master since then, so work continues without new version numbers. For audits, pin a specific commit, test it in your environment and check that the modules you rely on still return data, since provider APIs change. Treat output as a starting point that an analyst reviews, not as an audit on its own.
Intel 471 announced its acquisition of SpiderFoot on 2 November 2022 and said it would fold SpiderFoot's capabilities into its own platform (Intel 471). The README still promotes SpiderFoot HX, but spiderfoot.net now redirects to Intel 471's site, and we could not find a public HX price or sign-up page. Ask Intel 471 sales whether HX is sold standalone or only within its products.
Get written authorization first. Passive modules only read public sources, but SpiderFoot also integrates tools such as Nuclei and nbtscan that probe systems directly, and running those without permission can breach computer misuse laws and hosting terms. If you want a pre-contract view, limit the scan to passive modules and say so in your proposal; keep active testing for after the scope and rules of engagement are agreed.
SpiderFoot can scan emails, phone numbers, usernames and names, but it is built for infrastructure reconnaissance, not people screening. Results are raw, need verification and collect personal data that the GDPR requires you to minimize. In the US, background checks used for hiring decisions fall under the FCRA when a consumer reporting agency prepares them. A screening process with consent and verification is the safer route.
Sources checked 10 October 2026. This review is based on the public repository, release notes and announcements, not on a commercial license. OSINT-S has no affiliation with SpiderFoot or Intel 471 and does not resell tools.