s0md3v/Smap

a drop-in replacement for Nmap powered by shodan.io

View on GitHub ↗Jump to charts ↓

Data as of . Signed-in members get hourly updates — create a free account.

Summary Information

Updated 3 hours ago
Added to GitGenius on September 21st, 2026
Created on March 19th, 2022
Open Issues & Pull Requests: 1 (+0)
GitHub issues: Enabled
Number of forks: 321
Total Stargazers: 3,300 (+0)
Total Subscribers: 27 (+0)

Repository Insights (GitGenius)

Median issue/PR response: 3.1 days
Mean response time: 3.1 days
90th percentile: 3.1 days
Tracked items: 1

Charts & Analytics

Fetching additional details & charts...

Issue Activity (beta)

Open issues: 0
New in 7 days: 0
Closed in 7 days: 0
Avg open age: N/A days
Stale 30+ days: 0
Stale 90+ days: 0

Recent activity

Opened in 7 days: 0
Closed in 7 days: 0
Comments in 7 days: 0
Events in 7 days: 0

Top labels

No label distribution available yet.

Most active issues this week

Sign in to see which issues are moving.
Sign in

Detailed Description

Smap is a passive port scanner that serves as a drop-in replacement for Nmap powered by Shodan's free API.

Smap solves the problem of slow active network scanning by leveraging Shodan's existing database of publicly indexed hosts and their open ports. Rather than sending packets to targets, it queries Shodan's API to retrieve port information passively, making no contact with the scanned hosts. The tool accepts the same command-line arguments as Nmap and produces identical output formats, allowing users to swap it in without changing their workflows. It can scan hundreds of hosts per second and includes vulnerability detection and service fingerprinting capabilities derived from Shodan's data.

Smap suits security researchers, penetration testers, and network administrators who prioritize speed and stealth over active probing, or who want to quickly enumerate publicly known ports before running targeted active scans. It works best when passive reconnaissance is sufficient for your objectives. The tool offers an optional acceleration mode via the `--nmap` flag, which uses Smap's passive results to narrow the port range for a subsequent active Nmap scan, potentially saving time by eliminating unnecessary port checks. Users should note that Smap's results depend entirely on what Shodan has indexed; it cannot discover ports or services that haven't been publicly reported.

The project shows consistent maintenance with regular updates addressing user-reported issues and feature requests. Development activity includes responsive handling of bug reports and pull requests, with fixes deployed promptly when problems are identified. The maintainer actively documents the tool's capabilities and limitations, providing clear guidance on when Smap is appropriate versus when traditional Nmap scanning is necessary.