whatsmyname.app
The free, browser-based interface built on the dataset by Chris Poulter of OSINT Combine. It filters by category and exports to CSV, per the project.
OSINT Combine review →WhatsMyName OSINT work starts with one question: which websites have an account under this username? WhatsMyName answers it with a community-maintained list of more than 700 site checks that powers a free web app and many other tools. Here is how it works, where it misleads, and when you need an analyst.
The WhatsMyName OSINT project is a free, open dataset of username checks for 700+ websites, started in 2015 by Micah Hoffman and maintained on GitHub under a Creative Commons BY-SA 4.0 license. You search it through whatsmyname.app or tools such as Blackbird. It suits investigators, researchers and people auditing their own footprint. There is no paid tier.
A data project, not a search engine: one JSON file that tells other tools how to check whether a username exists on each listed site.
WhatsMyName (WMN) was created in 2015 by Micah "WebBreacher" Hoffman because the username checkers of the time returned too many false positives. It has since become one of the most widely used username enumeration datasets in OSINT (WhatsMyName repository).
In May 2023 the project removed its bundled checker scripts and now maintains only the data file, wmn-data.json. Other tools read that file and do the checking, so accuracy depends on two things: the quality of the entry and the behavior of the tool running it.
This review draws on the repository, contribution guide and data file as published on 10 October 2026.
Each entry tells a checker which URL to request, what a real profile returns, what a missing profile returns, and which known accounts prove the check still works.
| Field | What it holds | Why it matters |
|---|---|---|
uri_check | The URL to request, with a placeholder where the username goes | Only sites whose profile URL contains the handle can be listed |
e_code, e_string | The HTTP status and a unique text fragment seen when the account exists | A vague string matches unrelated pages and creates false hits |
m_code, m_string | The status and text seen when the account does not exist | Lets a checker tell "missing" apart from "blocked" |
known | At least two real usernames for testing | Maintainers re-test entries when sites change |
cat, valid, protection | Category, a flag to skip a broken site, and anti-bot measures | Filters searches and warns where checks are likely to fail |
Inclusion rules require a publicly accessible site, the username in the profile URL, and no transformation of the username, for example into a numeric ID (CONTRIBUTING.md). The same rules put login-only networks and ID-based platforms out of scope by design.
Most people use the free web app; technical teams run command-line checkers or plug the data into larger OSINT platforms.
The free, browser-based interface built on the dataset by Chris Poulter of OSINT Combine. It filters by category and exports to CSV, per the project.
OSINT Combine review →Python tools such as Naminter run the same checks from a terminal, which suits batch work and logging.
A command-line tool that uses WhatsMyName for its username checks and adds email lookups, exports and an AI summary.
Blackbird review →SpiderFoot uses the data in its account module, and community-built Maltego transforms check usernames against the file.
SpiderFoot review →717 entries in 21 categories on 10 October 2026, weighted toward social, gaming and technical communities, with known blind spots.
Counting the live data file on 10 October 2026 gives 717 site entries across 21 categories (wmn-data.json). The largest groups are social (203), gaming (71), tech (57), hobby (50) and coding (47). Smaller groups include dating (12) and political (11) sites, plus an adult category of 39 entries.
Sixty-two entries carry a protection flag, most often Cloudflare (34 entries). Those checks most often come back blocked or inconclusive. The count changes as contributors add and remove sites, so any figure is a snapshot.
Free. The dataset is licensed CC BY-SA 4.0, which matters if you build it into a product.
| Option | Cost | Terms to note |
|---|---|---|
| WhatsMyName dataset | Free | Creative Commons Attribution-ShareAlike 4.0: credit the project, and share adaptations under the same license (CC BY-SA 4.0) |
| whatsmyname.app | Free, browser-based | No installation; your searches run through a third-party site, so consider what you type into it |
| Tools built on the data | Varies | Each tool has its own license or terms; check them separately |
Prices and terms checked 10 October 2026 on the project repository. A company adapting the file inside its own product should review the share-alike condition with counsel.
A hit means a page exists under that handle, not that it belongs to your subject. A miss means the check did not find it, not that no account exists.
The most common error is not technical. Short names and gaming tags are shared by many unrelated people, and every one comes back as a hit.
The contribution guide warns that a plain phrase such as "joined at" can appear on unrelated pages. Loose strings, or sites that return the same page for any name, report accounts that do not exist.
Anti-bot services, rate limits and redesigned pages make a real account look missing. Entries marked invalid are skipped until repaired.
Checks look for the exact string you enter. john.doe, johndoe and john_doe are three searches, and login-only platforms are not in the dataset at all.
Checking your own handle is harmless; compiling where a private person has accounts is processing personal data and needs a lawful purpose.
Accounts tied to an identifiable person are personal data. Under the GDPR, that means a lawful basis, a defined purpose and minimization (GDPR). Data protection authorities have also stated jointly that personal information that is publicly accessible online is still protected by data protection law (joint statement on data scraping, 2023).
The dataset's categories make this concrete. A hit on a dating, adult or political site can reveal information about sex life or political opinions, which the GDPR treats as special category data. Leave such results out unless a lawful purpose requires them. Never use username searches to locate, monitor or harass anyone, or pose as someone to see more.
It suits anyone who needs a fast, free first pass. It does not suit anyone who needs to prove who is behind an account.
| Good fit | Poor fit |
|---|---|
| Journalists and researchers mapping where a known public handle appears | Deciding whether two accounts are the same person |
| Security teams checking staff or brand handles for impersonation | Evidence for a court, regulator or employment decision; login-only platforms |
| Individuals auditing their own digital footprint | Buyers who want an answer rather than a list of URLs |
Sherlock and Maigret keep their own site lists; Blackbird reuses WhatsMyName and adds email checks.
For a wider map of tools by investigation task, see our OSINT tools guide.
If a username sits at the center of a harassment, impersonation or fraud matter, the work is ruling matches in or out, not listing them.
A search returns dozens of hits in seconds; deciding which belong to your subject takes corroboration such as original photos, shared contact details and cross-links. Our username investigations grade each link and document why false matches were rejected, and our social media investigations take confirmed accounts further. Work is quoted at a fixed price after written scoping, and a senior analyst reviews every report.
If the handle in question is your own, a personal digital footprint check is the better starting point. For everything else, see the full range of OSINT services we provide.
Send the handle and what you need to decide. We reply with a scope, a fixed quote and a delivery date.
WhatsMyName is a free dataset, not a program: one JSON file describing how to check 700+ websites for a username, licensed CC BY-SA 4.0. Most people use it through whatsmyname.app, a free browser interface, or tools such as Blackbird and SpiderFoot. There is no paid version; the project has published only the data since May 2023 (repository).
No, you cannot assume that. A hit only means a page exists under that exact handle; common handles are shared by many unrelated people, and some checks report accounts that do not exist. Linking an account to a person needs independent signals, such as the same original photo, shared contact details or cross-links between profiles. Also ask whether you have a lawful reason to compile her accounts at all.
It requires attribution and, for adaptations you share, the same license. Under CC BY-SA 4.0 you must credit the project and indicate changes, and if you distribute an adapted version of the data it must carry the same license. Whether your product counts as sharing an adaptation depends on its design, so have counsel review it before launch. This is not legal advice.
Usually because the check was blocked or the site has changed. Sixty-two entries in the data file carry anti-bot flags such as Cloudflare, and those often fail from scripts or data-center IP addresses. Redesigned profile pages also break the text a check looks for. A missing result is inconclusive, never proof that no account exists.
It is risky and rarely sensible. Results include dating, adult and political sites that reveal special category information, and hits on common handles often belong to someone else. Under the GDPR you need a lawful basis, transparency and minimization; in the US, screening done by a third party for employment decisions can fall under the FCRA. Use a documented screening process instead.
Yes, it is one of the better free starting points for that. Search each handle you have used, including variants with dots, underscores and numbers, because checks look for the exact string. Open each hit to confirm it is yours, and request deletion where you no longer use the site. Check login-only platforms manually.
Sources checked 10 October 2026. Figures about third-party firms and tools are as published by them or by the cited source on that date.