DeviceShelf
DeviceShelf is a local-first alternative for people who want to see every device on their network without an account, telemetry, or a subscription.
Cost / License
- Pay once
- Proprietary
Application types
Platforms
- Mac
- Windows
- Linux
- Android
- Android Tablet
- Self-Hosted
Features
Properties
- Privacy focused
Features
- Dark Mode
- Ad-free
- Portable
- Command line interface
- No Tracking
- No registration required
- Internet Speed Test
DeviceShelf News & Activities
Recent activities
- POX updated DeviceShelf
- c-mueller updated DeviceShelf
- c-mueller rated DeviceShelf
- c-mueller liked DeviceShelf
- POX updated DeviceShelf
- c-mueller added DeviceShelf
c-mueller added DeviceShelf as alternative to Fing, Angry IP Scanner, Nmap and Advanced IP Scanner
DeviceShelf information
What is DeviceShelf?
One click scans your LAN and shows what each device actually is: vendor, hostname, OS, type, open ports and services.
I built it after my router showed a device I couldn't identify — just a MAC address and an IP. The scanners I tried were either ad-heavy, cloud-bound, or stopped at a flat list of IPs.
DeviceShelf also includes service/banner detection and a prioritized security report with exposed services, default-credential checks, weak-TLS flags, CVE hints and a 0–100 risk score. It can alert you when an unknown device joins, export reports, and — where supported — show topology information and per-device bandwidth.
There is also a headless server edition for always-on monitoring: Docker image, .deb, or a Windows service, with alerts via ntfy, Gotify or webhook. It is part of the same one-time license rather than a separate subscription tier.
The core design goal is local-first as architecture, not a tagline. There is no account, no telemetry and no cloud backend for your scan data. The license is verified offline with an ed25519 signature, so there is no activation server.
Data leaves the device only if you explicitly enable an optional feature: AI device identification with your own API key, Fingerbank lookup, or WAN-IP lookup. These are off by default.
It is closed-source, so don't take the "no phone-home" claim on faith: run it behind Little Snitch, LuLu, pfSense/OPNsense, or Wireshark. With optional online features off, you'll see local LAN discovery and scan traffic, but no app-initiated internet-bound traffic to DeviceShelf servers: no telemetry, analytics, update checks, or online license checks. DNS resolution uses your system's configured resolver. OS/runtime traffic such as WebView2, SmartScreen, OCSP, or system update checks is separate from DeviceShelf's scan, license, telemetry, and update behavior.
Scans are read-only TCP-connect scans. DeviceShelf observes your network; it does not change devices, router settings or firewall rules.
Stack: Go scanner engine + Wails, with a Go backend and webview frontend.
Honest disclosures: proprietary and paid. €59 one-time, no subscription, 7-day trial, no card, 14-day refund. One license covers desktop, mobile and the server edition for one person across all their devices. Desktop is available now for macOS, Windows and Linux; Android ships as a direct APK and iOS is in TestFlight.
Linux note: I currently ship .deb, .rpm and AppImage builds for amd64 and arm64. They target glibc >= 2.34, GTK3, webkit2gtk-4.1 and libpcap. Debian 12 ARM has been tested directly; the other builds are dependency-checked, and I'd genuinely like feedback from more distros.
It is not a pentest tool, not an IDS and not an enterprise asset-management system.





