Understanding the holehe `--no-password-recovery` Flag: Service Exclusions and Current Implementation
The --no-password-recovery flag in holehe does not exclude any services because the codebase currently lacks password-recovery implementations for all supported platforms.
The holehe tool by megadose is an OSINT framework designed to check if an email address is registered across various online services. When investigating CLI options for security audits, users often question whether the --no-password-recovery (or -NP) flag filters out specific service modules. This article examines the actual implementation in the source code to clarify exactly which services are affected when this flag is activated.
What Does the --no-password-recovery Flag Do?
The --no-password-recovery flag is defined in holehe/core.py as a simple Boolean switch that instructs the CLI not to attempt password-recovery routines (source).
Despite being available as a command-line option, the flag currently controls a capability that does not exist in the implementation. When parsed by the argument parser, it sets an internal state that would theoretically skip password-recovery attempts, but since no service modules contain this logic, the flag produces no functional filtering effect.
Why No Services Are Currently Excluded
The Holehe codebase does not implement password-recovery logic for any of its service modules. Consequently, toggling this flag does not exclude any specific services from the email enumeration process.
All services continue to operate normally when the flag is present, executing only their standard email-existence checks. The tool queries each platform for account registration status regardless of whether -NP is specified, because none of the current modules attempt password-reset flows that would need suppression.
Code Examples and CLI Usage
In practice, running holehe with or without the --no-password-recovery flag produces identical behavior in the current version:
# Standard execution - checks all services for email existence
holehe -e example@example.com
# Execution with password-recovery disabled - behavior is identical
# because no service implements password-recovery logic
holehe -e example@example.com --no-password-recovery
Both commands will iterate through the same service list and perform equivalent HTTP requests to verify if the target email is registered. The flag acceptance does not trigger service exclusion logic because the underlying recovery modules are absent from the codebase.
Future Implications of the Flag
If future versions of holehe add password-recovery support for particular services, the --no-password-recovery flag will automatically suppress those attempts for all services that include such logic.
At that point, the Boolean switch defined in core.py would function as a master kill-switch, preventing any configured password-recovery routines from executing while still allowing standard account-existence enumeration to proceed. Until such features are implemented, the flag remains a placeholder for forward compatibility.
Summary
- The
--no-password-recoveryflag is defined inholehe/core.pyas a Boolean CLI option but currently has no services to suppress. - Zero service modules are excluded when using
-NPbecause no password-recovery implementations exist in the current codebase. - All standard email existence checks continue to run regardless of flag state.
- Future implementations of password-recovery features would respect this flag globally across all affected modules.
Frequently Asked Questions
Does --no-password-recovery skip specific service modules?
No. The flag does not filter or skip any service modules in the current implementation. According to the source code analysis, no modules contain password-recovery logic, so there are no services to exclude. The flag is parsed but does not alter the service execution list.
Where is the flag defined in the holehe source code?
The flag is defined in holehe/core.py around line 190 as a command-line argument. It accepts both the long form --no-password-recovery and the short form -NP, storing the value as a Boolean that controls whether password-recovery attempts should be permitted (though currently no such attempts are implemented).
Will using -NP speed up holehe scans?
No. Since the flag does not currently disable any actual functionality, scan speed remains identical whether you include --no-password-recovery or omit it. The tool performs the same HTTP requests and processing steps in both scenarios because no password-recovery routines are being bypassed.
Can I use --no-password-recovery with other flags?
Yes. The flag can be combined with other holehe CLI options such as --only-used or specific rate-limiting parameters. Being a simple Boolean toggle, it does not conflict with other arguments and will simply remain dormant until future versions implement the features it is designed to suppress.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →