Reproduce the 4ryanwalia case study

This is a recorded, owner-requested case study from 30 September 2026. It is separate from the daily 30-check regression sample.

Use Python 3.12 in an isolated environment. Install requests and the repository's backend/tools/requirements-benchmark.txt. These pin Sherlock and Maigret to immutable source revisions. Sherlock also uses its current official exclusion list, whose URL and hash are recorded. Future runs can differ as that list and platform responses change.

python backend/tools/username_benchmark.py --username 4ryanwalia --output-dir output/benchmark-4ryanwalia
python backend/tools/review_username_benchmark.py --username 4ryanwalia --output-dir output/benchmark-4ryanwalia
python backend/tools/review_profile_controls.py --username 4ryanwalia --output-dir output/benchmark-4ryanwalia
python backend/tools/build_username_benchmark.py --input-dir output/benchmark-4ryanwalia --output frontend/data/username-benchmark.json

The builder also requires the recorded OSINTsearch preview, the earlier MyRecon runs, source-review observations and the unfiltered Sherlock diagnostic. These are evidence inputs, not invented tool outputs. Download those recorded inputs and save each top-level item as its corresponding JSON filename in the output directory. Preserve fresh local measurements if you rerun the engines. Recorded source reviews retain their observation dates and may be stale; they are not fresh measurements.

Public normalized checks, source reviews and methodology retain all reported native hits, including claims quarantined by HTTP-error normalization. The full and shared views reuse these same measurements. The shared view intersects exact profile addresses for three local engines; it does not assume different endpoints are equivalent.

OSINTsearch was run through its public preview with the user completing the CAPTCHA. It showed 19 grouped matches, 21 endpoint hits, 14 named platforms and five hidden matches. All profile URLs were hidden. View the captured result. Those hidden results are unscored. The 15-second elapsed display is the provider's own timer, not an independently measured ranking.

Reference checks use typed official API objects, explicit missing responses, different account handles, or separately recorded profile/control evidence. HTTP 200 and agreement between tools never establish truth. Parking destinations are contradicted as public-profile leads, not as claims about whether an account ever existed. Unknown results are not false positives. Ownership is unverified.

The initial MyRecon run mistakenly included RubyGems' fermion profile. A digit-prefixed URL can resolve to a numeric account ID. We added an exact-handle check and reran the full engine, retaining the original mistake in the recorded inputs.

We also added exact active creator records for Buy Me a Coffee, exact profile identities for OpenStreetMap, and typed Reddit account checks. The fresh full scan recovered Buy Me a Coffee. OpenStreetMap passed a direct check but blocked the full run, and Reddit was challenged locally. Those full-run verdicts remain unknown even though separate source review confirmed the profiles. The rules apply to any username; no saved account result is used by the scanner.

No whole-catalogue accuracy percentage, zero-error guarantee or speed ranking follows from this one username. Some local runs overlapped. No customer history, authentication, proxies, retries or block bypass was used.

Back to the benchmark