Appearance
Status and diagnostics
The Status item in the lower (global) part of the sidebar opens the diagnostics page in a new browser tab. It is the same origin as the console, at /nikto-diag.
Use it for a health check of the running product: build identity, database connectivity, crawler/browser availability, disk use, and a live tail of application logs — without opening a project.
Same theme as the console
The diagnostics page follows the console's light/dark theme, including when you toggle theme in the app. It has no retro palette of its own, so Retro terminal shows the dark one.
What the page shows
Sections are laid out in two columns on wide screens (single column on narrow viewports).
| Section | What it reports |
|---|---|
| Build / Runtime | Build identity (the API version and the commit it was built from), operating system, and how long the process has been up |
| Capabilities | IPv6 egress; headless Chromium / crawler availability |
| License | The current license state (red when new scans are blocked) and the clock high-water mark — the latest time the platform has seen, red when the host clock is more than 36 hours behind it (see License) |
| Memory | Process memory use |
| Container / Docker | Whether the process appears to be in a container |
| Database | Whether the database is reachable, and applied schema updates |
| Stored Data | Row counts and on-disk sizes for major tables (projects, scans, artifacts, activity log, app log, wordlists, LFIC files, …), oldest scan age, top five largest tables, heaviest scans by artifact bytes and by activity-log rows |
| Nikto Seed / LFIC Seed | Counts of built-in test/seed rows |
| HTTP/3 (QUIC) | Whether QUIC egress appears usable (observed, not a live probe on page load) plus a Test HTTP/3 egress form — see HTTP/3 scanning |
The console's own version is shown next to the API's under Global Settings → License → Platform version.
Bad values (for example database unreachable) are highlighted in red. Storage counts are informational — they help answer “what is using disk?” rather than enforcing limits.
App Log inset
Below the diagnostics columns, a full-width App Log panel tails platform-wide application logs:
- Columns: Time, Level, Component, Message
- Loads the latest entries on open; Load older pages backward
- Polls every five seconds for new rows
Project HTTP audit traffic remains under each project's Logs sidebar item.
When to use Status vs project Logs
| Need | Where to look |
|---|---|
| Is the product up? Database reachable? Browser available? | Status → /nikto-diag |
| Disk growing — which table or scan? | Status → Stored Data |
| Platform errors, worker issues, startup problems | Status → App Log inset |
| Two API processes at once (each enforces request-rate limits on its own) | App Log — a loud warning if a second instance is detected |
| Every HTTP request sent to a target during scans | Project Logs → Scan Activity |
| Project audit trail (scan created, finding reviewed, …) | Project Logs → Events |
| These diagnostics plus recent logs, secrets removed, to attach to an issue | Support bundle |
Security note
/nikto-diag requires a signed-in operator session, like the rest of the console (see Operator Login). With AUTH=off it is open to anyone who can reach the console. It does not show credentials or scan response bodies, but it does show counts and live app-log messages.
On the host, the same diagnostics are available as text without signing in: nikto-launcher admin diag — see Host Commands. A support bundle includes them.