ThreatLens is a local URL safety and phishing analysis tool. It checks links for suspicious URL structure, redirects, TLS and SSL issues, DNS signals, domain age, typosquatting, brand mismatch indicators, content signals, and threat intelligence matches.
The packaged Windows build runs as a single executable:
- UI:
http://localhost:8080 - API:
http://localhost:8080/api/v1 - Health check:
http://localhost:8080/api/v1/health
No Docker, Go, or Node.js is required for normal use.
- Download or clone this repository.
- Open the project folder.
- Double-click
start-all.bat. - Wait for the command window to show that ThreatLens is listening.
- Open
http://localhost:8080.
If port 8080 is already busy, the launcher automatically uses 8090 and prints the correct URL.
Double-click:
start-all.bat
This starts the embedded UI and API from:
server/safesurf.exe
cd server
$env:PORT="8080"
$env:CACHE_DISABLED="1"
.\safesurf.exeThen open:
http://localhost:8080
curl http://localhost:8080/api/v1/healthExpected:
{"status":"ok"}Note: http://localhost:8080/api/v1 by itself returns not found. Use /api/v1/health or /api/v1/analyze.
curl "http://localhost:8080/api/v1/analyze?url=https%3A%2F%2Fexample.com"server/ Go backend and packaged executable
server/safesurf.exe Single executable serving UI + API
web/website/ Svelte frontend source
docs/ Documentation
start-all.bat One-click app launcher
start-backend.bat Backend/UI launcher
build-single-exe.bat Rebuilds frontend and embeds it into safesurf.exe
Only needed if you change source code.
Install:
- Go 1.24 or newer
- Node.js with npm
Then run:
build-single-exe.bat
That command:
- Builds the Svelte frontend.
- Writes static files into
server/internal/web/dist. - Rebuilds
server/safesurf.exewith the frontend embedded.
Frontend dev server:
cd web/website
npm install
npm run dev -- --host 0.0.0.0Backend from source:
cd server
$env:PORT="8080"
$env:CACHE_DISABLED="1"
go run ./cmd/safesurfFor normal users, prefer start-all.bat.
- URL structure and suspicious pattern checks
- Redirect chain analysis
- TLS and SSL certificate inspection
- Domain age and registration information
- Typosquatting and homoglyph checks
- Page content and form analysis
- Threat intelligence lookup
- Clear verdict, trust score, and detailed evidence
If the page is blank:
- Close any old ThreatLens/SafeSurf command windows.
- Run
start-all.batagain. - Open the URL printed in the terminal.
If 8080 is busy:
- The launcher will try
8090. - Open the URL shown in the command window.
If Windows blocks the executable:
- Right-click
server/safesurf.exe. - Open Properties.
- Click Unblock if shown.
- Run
start-all.batagain.