Dependencies for user-scanner: Core Requirements and Optional Extras Explained

The user-scanner CLI requires five core Python packages—httpx[http2], socksio, colorama, curl_cffi, and rich—for asynchronous networking, proxy support, and terminal output, alongside optional extras for PDF reporting and MCP server functionality.

The user-scanner repository by kaifcodec is a pure-Python tool designed for asynchronous user enumeration and web scanning. Understanding the dependencies for user-scanner ensures proper environment configuration and reveals which optional features require additional packages beyond the core runtime.

Core Dependencies for user-scanner

All mandatory dependencies are pinned in requirements.txt and the dependencies array of pyproject.toml. These five packages power the networking, proxy handling, and CLI presentation layers.

  • httpx[http2] (>=0.27,<0.29): The asynchronous HTTP client driving all web requests. In user_scanner/core/orchestrator.py, the make_request function relies on this library for concurrent HTTP/2 connections.

  • socksio (>=1.0,<2): Provides SOCKS proxy support integrated via the get_proxy function in the same orchestrator module.

  • colorama (>=0.4,<1): Enables cross-platform ANSI color handling for terminal output, ensuring consistent display of category headings across Windows and Unix systems.

  • curl_cffi (>=0.7,<1): A CFFI-backed libcurl wrapper used in user_scanner/core/impersonate.py for sites requiring browser impersonation and advanced TLS fingerprinting.

  • rich (>=13.0.0): Supplies progress bars, formatted console output, and styled logging throughout the scanning engine.

Optional Dependency Extras

user-scanner declares three optional groups under [project.optional-dependencies] in pyproject.toml to enable extended functionality without bloating the core install.

PDF Generation (pdf)

Install with pip install "user-scanner[pdf]". This extra includes:

  • reportlab (>=4.0.0): PDF generation engine
  • pillow (>=10.0.0): Image processing for embedded graphics
  • svglib (>=1.5.0): SVG conversion utilities

These enable the generate_pdf function in user_scanner/core/pdf_generator.py.

MCP Server (mcp)

Requires mcp (>=1.2.0,<2) to run the micro-service server implementation found in user_scanner/mcp/server.py. Install via pip install "user-scanner[mcp]".

Development Tools (dev)

Includes pytest, pytest-cov, pytest-anyio, and anyio[trio] for running the test suite in the tests/ directory. Install with pip install -e ".[dev]" for editable development installs.

Installation and Usage Examples

Install the core package from source:

git clone https://github.com/kaifcodec/user-scanner.git
cd user-scanner
pip install -r requirements.txt

Install with PDF support:

pip install "user-scanner[pdf]"

Basic Python usage utilizing the core dependencies:

from user_scanner.core.orchestrator import run_user_full
from user_scanner.core.helpers import ScanConfig

config = ScanConfig(username="example_user")
results = run_user_full("example_user", config)

for r in results:
    print(r)  # Rich-styled output requires the rich dependency

Generate PDF reports (requires the pdf extra):

from user_scanner.core.pdf_generator import generate_pdf

generate_pdf(results, output_path="report.pdf")

How Dependencies Are Used in Source Files

Specific modules isolate imports to optimize performance and prevent loading unused packages:

Summary

  • Five core packages are mandatory: httpx[http2], socksio, colorama, curl_cffi, and rich
  • Three optional extras extend capabilities: pdf for report generation, mcp for micro-service server functionality, and dev for testing
  • Version constraints in pyproject.toml and requirements.txt prevent breaking changes from upstream updates
  • Heavy dependencies like reportlab are isolated in specific modules (e.g., pdf_generator.py) to keep the core tool lightweight

Frequently Asked Questions

What is the minimum Python version for user-scanner dependencies?

The use of httpx>=0.27 and modern asynchronous syntax in orchestrator.py requires Python 3.8 or higher. The rich library further enforces compatibility with recent Python releases.

Can I run user-scanner without installing curl_cffi?

No, curl_cffi is a mandatory dependency listed in requirements.txt. While httpx handles standard requests, the impersonate.py module requires curl_cffi for sites with advanced bot protection mechanisms.

Why are strict version upper bounds enforced on core dependencies?

Constraints like <0.29 for httpx and <2 for socksio prevent breaking changes from future major version updates. According to the pyproject.toml specification, these bounds ensure the scanning engine remains compatible with tested API surfaces.

How do I install dependencies for contributing to the project?

Clone the repository and install with the dev extra: pip install -e ".[dev]". This installs pytest, pytest-cov, and anyio necessary for running the test suite located in the tests/ directory.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →