npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@herenickname/whoz

v0.1.1

Published

A fast, pretty WHOIS & RDAP CLI for domains and IPs — registrar, ASN, network, geolocation, decoded statuses and availability.

Readme

whoz

A fast, pretty WHOIS & RDAP CLI for the terminal — human-readable domain and IP intelligence with a smooth animated reveal.

npm version npm downloads CI license node

whoz is a modern whois client and RDAP client that prints clean, colorized domain information in your terminal: registrar, registration and expiry dates, decoded EPP status codes (in plain English, not cryptic clientTransferProhibited strings), nameservers, DNSSEC, and domain availability. It queries RDAP first for structured, consistent data and falls back to WHOIS automatically for TLDs that have no RDAP server (most ccTLDs like .gg, .sh, .ai).

Pass an IPv4 or IPv6 address and whoz switches to a dedicated network view: allocation range and CIDRs, netname, RIR, organization, route, origin ASN, abuse contact, reverse DNS, location and anycast status. IPs are discovered through the official IANA RDAP bootstrap too, with IP WHOIS as a fallback.

It also resolves the domain live — following the CNAME chain to the final A/AAAA records — and shows the hosting country flag + ISO2 code, plus the registrant/owner when it isn't redacted.

No ads. No API key. Just npx @herenickname/whoz example.com.

╭─ example.com ────────────────────────────────────────────────────╮
│ ● registered  — via rdap                                          │
│                                                                   │
│ registrar    RESERVED-Internet Assigned Numbers Authority         │
│ owner        redacted (privacy / GDPR)                            │
│ created      1995-08-14 (30.8y ago)                               │
│ expires      2026-08-13 (in 76d)                                  │
│ dnssec       signed                                               │
│                                                                   │
│ nameservers                                                       │
│   › a.iana-servers.net                                            │
│   › b.iana-servers.net                                            │
│                                                                   │
│ dns                                                               │
│   A      93.184.215.14  🇺🇸 US                                     │
│                                                                   │
│ status                                                            │
│   ● Transfer Locked (registrar)                                   │
│     Registrar blocks transfers — the common anti-hijack lock.     │
╰───────────────────────────────────────────────────────────────────╯

Features

  • 🎨 Pretty, colorized output in a clean rounded box — readable at a glance.
  • 🧠 Decoded EPP status codes — clientTransferProhibited becomes "Registrar blocks transfers — the common anti-hijack lock."
  • 🌐 RDAP first, WHOIS fallback — structured data where it exists, full coverage everywhere else. One consistent output regardless of source.
  • ✅ Domain availability — clearly tells you registered vs. available, without false positives on RDAP-less TLDs.
  • 🌍 Live DNS resolution — follows the CNAME chain to the final A/AAAA records and shows the hosting country flag + ISO2 for the primary IP.
  • 📡 Full IPv4/IPv6 intelligence — allocation range, CIDRs, RIR, network type, route, ASN/provider, abuse contact, reverse DNS and geolocation.
  • 👤 Owner / registrant — shows organization, name, country and email when the registry exposes them (and says so plainly when it's redacted).
  • ⚡ Smooth animated reveal — spinner while looking up, staggered reveal of results (auto-disabled when piped or in CI).
  • 🧩 --json mode — normalized, machine-readable output for scripts.
  • 📦 Tiny & dependency-light — two small deps, zero build step, no API key.
  • 🔌 Programmatic API — import { lookup } from '@herenickname/whoz'.

Install

Run it instantly with npx:

npx @herenickname/whoz example.com

Or install globally:

npm install -g @herenickname/whoz
whoz example.com

Usage

whoz <domain-or-ip> [domain-or-ip...] [options]

Examples

whoz example.com                 # pretty WHOIS/RDAP for one domain
whoz 178.234.19.55               # network, ASN, RIR, abuse and location for an IP
whoz 2606:4700:4700::1111        # IPv6 works too
whoz cleave.dev cleavekit.io     # several domains in one go
whoz openai.gg --whois           # force WHOIS (ccTLD with no RDAP)
whoz example.com --json          # normalized JSON for scripts
whoz example.com | cat           # auto-plain output when piped

Options

| Option | Description | | --- | --- | | --json | Print the normalized result as JSON (disables animation) | | --rdap | Force RDAP only (skip the WHOIS fallback) | | --whois | Force WHOIS only (skip RDAP) | | --no-dns | Skip live DNS resolution (CNAME → A/AAAA or IP reverse DNS) | | --no-geo | Skip IP geolocation lookups | | --no-animation | Disable the spinner | | --no-color | Disable colors (also honors the NO_COLOR env var) | | --timeout <ms> | Per-lookup timeout in milliseconds (default 12000) | | -h, --help | Show help | | -v, --version | Show version |

Programmatic API

whoz is also a library. The normalizer functions are pure and network-free, so they are easy to test and reuse.

import { lookup, explainStatus } from '@herenickname/whoz';

const rec = await lookup('example.com');
console.log(rec.registrar, rec.expires, rec.available);

for (const s of rec.statuses) {
  console.log(s.label, '→', s.human);
}

// Decode a single EPP status code yourself:
console.log(explainStatus('clientHold').human);
// → "Registrar pulled it from the DNS zone — it will not resolve."

const ip = await lookup('1.1.1.1');
console.log(ip.network.range, ip.route, ip.asns, ip.abuse?.email);

Domain records retain the normalized shape below. IP records have kind: 'ip' and expose ip, version, registry, network, route, asns, abuse, geo and reverseDns alongside the original raw response.

{
  domain: string,
  available: boolean | null,
  source: 'rdap' | 'whois',
  registrar?: string,
  registrarUrl?: string,
  registrarId?: string,
  created?: string,
  updated?: string,
  expires?: string,
  statuses: Array<{ key, label, human, tone, raw }>,
  nameservers: string[],
  dnssec: boolean | string | null,
  raw: unknown // the original RDAP/WHOIS payload
}

How it works

  1. Official server lists. whoz resolves the authoritative server for each TLD or IP allocation from IANA, not a third-party redirector:
    • RDAP from the official IANA RDAP bootstrap (dns.json, ipv4.json and ipv6.json), which maps every RDAP-enabled TLD or address range to its authoritative base URL.
    • WHOIS from whois.iana.org per TLD (whoiser ships a static map that goes stale — e.g. .co still points at the long-dead whois.nic.co).
  2. Local cache. The domain and IP RDAP bootstrap files are refreshed every 7 days under ~/.whoz/; WHOIS servers are cached lazily per TLD, so the server lists aren't fetched on every lookup. Override the location with WHOZ_CACHE_DIR.
  3. RDAP first, WHOIS fallback. If the TLD is in the RDAP bootstrap, whoz queries its authoritative RDAP server directly for structured JSON. If not (many ccTLDs: .gg, .sh, .ai, …) it falls back to WHOIS via whoiser, pointed at the IANA server, which normalizes field names across registrars.
  4. One normalized shape. Whichever source answered, you get the same record and the same pretty output. The source field tells you which was used.

Because availability comes from the authoritative server's 404 (not a redirector's), whoz doesn't fall into the classic trap of reporting a registered domain as "available" just because a TLD lacks RDAP.

  1. IP intelligence. IPv4/IPv6 inputs use IANA's official IP RDAP bootstrap, the responsible RIR's RDAP service, RIPE NCC routing data for the announced prefix/origin ASN, and IP WHOIS as a registration fallback.
  2. Live DNS + geo. For a registered domain, whoz also queries the system DNS resolver to follow the CNAME chain and collect the final A/AAAA records, then geolocates the primary IP. Direct IP queries also request reverse DNS. DNS uses your local resolver; geolocation sends only the IP being looked up to ipinfo.io. Disable with --no-geo (geo only) or --no-dns (DNS only).

Why whoz?

Plain whois output is a wall of inconsistent text that differs per registrar, and raw RDAP is JSON you have to read yourself. whoz gives you:

  • consistent, human-readable fields regardless of registry,
  • EPP status codes explained instead of memorized,
  • correct availability across both gTLDs and ccTLDs,
  • useful network and routing context for IPv4/IPv6 addresses,
  • and output that looks good enough to screenshot.

Related

  • whoiser — the WHOIS/RDAP library powering the fallback path.
  • RDAP — the modern, structured successor to WHOIS.
  • ICANN EPP status codes — the reference for the decoded statuses.

License

MIT © herenickname