Skip to content
View maximilianfeix's full-sized avatar

Block or report maximilianfeix

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
maximilianfeix/README.md

Maximilian Feix. Backend and infrastructure at a hosting company in Germany. Currently shipping proxy-scraper, spillage and RepoAtlas.

projects · open source · how i work · stack · activity

Software developer from Germany, working at a hosting company. Most of my time goes into the parts users never see: APIs, deployment pipelines, database schemas and the automation that keeps all of it running without me. In my own time I build developer tools that do one job properly and show their work – tested, documented, released.

What I do

  • Backend services in Node.js, TypeScript, PHP and Python, with Vue where a UI is needed
  • The ops half of the job: Linux, Apache, Redis, MariaDB, cron and shell glue
  • Automation that removes repetitive work – CI pipelines, scripts, bots

Right now

  • 🔐 Shipping spillage – secret scanning for coding-agent logs
  • ⚡ Maintaining proxy-scraper and RepoAtlas
  • 🔨 Building devprofile.dev
  • 📚 Learning microservices – service boundaries, messaging, observability

Projects

proxy-scraper: scrapes 700+ sources and keeps only proxies that pass real checks, with the live number of verified proxies spillage: finds the API keys your coding agents spilled into their logs

RepoAtlas: an architecture map of any TypeScript repo, every import traced to its line gha-preview: see a GitHub Actions run as a job graph before you push

Real screenshots, live numbers – rebuilt every 3 hours by this repository's workflow.

proxy-scraper  Python

Free proxies that actually work. Scrapes HTTP/SOCKS4/SOCKS5 proxies from 700+ sources and verifies every hit: honeypot filter, catches proxies that inject scripts (one in five does), HTTPS with verified TLS, anonymity, country, provider and spam blocklists – and learns with every run which sources are worth it. Comes with a rotating proxy server (SOCKS5 + HTTP, sticky sessions, Prometheus metrics), an MCP server for AI agents, a live dashboard and a Discord bot.

tests release live proxies stars

700+ ~1M 25 s ~500
sources candidates per run to check them tests on Linux · macOS · Windows

→ Browse the live list, re-checked every hour by GitHub Actions.

spillage  Python

Find the API keys your coding agents spilled into their logs. Claude Code, Codex, Gemini CLI, Cursor and the rest keep every conversation on disk as plain text – including each .env they read and every key you pasted "just to test". spillage reads the logs of thirteen agents, tells you which keys leaked and how (you pasted it, a tool printed it, the model repeated it), links to the page where you rotate each one, scrubs them without breaking --resume, and installs hooks that block the next leak.

  • 56 rules that know each key's exact shape – GitHub tokens are checked against their CRC32, JWTs have to decode, placeholders are skipped
  • Zero dependencies, zero network – standard library only, secrets are only ever shown masked
  • Fits into CI – HTML, JSON, Markdown and SARIF reports, a GitHub Action and a pre-commit hook
brew install maximilianfeix/tap/spillage && spillage

release zero dependencies website

RepoAtlas  TypeScript

Understand any TypeScript repo in one interactive map. RepoAtlas parses every import with the TypeScript compiler API and turns a project into a standalone architecture map. Unlike a diagram guessed from prose, every connection links to the exact import statement and line that proves it – with a Focus map for direct neighbours, an Impact map for everything that transitively depends on a module, and circular import groups isolated edge by edge.

npx --yes --package=github:maximilianfeix/repoatlas -- repoatlas https://github.com/pmndrs/zustand -o zustand-map.html

tests CodeQL release

Try it on real projects: Zustand 18 modules · Ky 51 modules · Hono 247 modules, 676 connections

gha-preview  TypeScript

See the run before the run. Paste a GitHub Actions workflow and explore it as a job graph: which jobs a push or pull_request would start, what a matrix expands to, how a proposed change reshapes the pipeline – and jump from any job straight back to its YAML line. Everything is parsed in the browser; no account, no upload.

checks release live demo

Smaller things
Repository What it is
free-proxy-list The hourly proxy list from proxy-scraper, per country, as JSON and CSV
homebrew-tap Homebrew formulae – brew install maximilianfeix/tap/spillage
AxonPHPCLI Tiny PHP CLI that generates GitHub Actions CI/CD configuration for PHP projects
Mini-Laravel Laravel-style PHP framework from scratch: router, DI container, controllers, middleware
CurrentlyFreeDomains Currently free .de domains
C++ template for macOS · vocational school C++ Starter template with VS Code tasks, and exercises from my apprenticeship

Open source

Recently shipped

Contributions to other projects

How I work

Principle In practice
Tested Tests that run offline and in CI – proxy-scraper runs almost 500 of them on Linux, macOS and Windows, against fake proxies and honeypots on localhost
Reviewed Changes start as an issue and land through a reviewed pull request – see the proxy-scraper history
Automated Lint, CodeQL, Dependabot, tagged releases and scheduled jobs on GitHub Actions – this profile updates itself too
Minimal As few dependencies as the job allows – spillage has none, because it's a tool you point at your secrets
Documented READMEs with a quick start, a changelog, contributing and security guides
From commit to production – and which tool for which job
flowchart LR
    dev["Local dev<br/>Vue + Vite"] --> push["git push"]
    push --> ci["GitHub Actions<br/>lint, test, build"]
    ci --> art["Artifact"]
    art --> web["Apache / Node.js"]
    web --> api["API layer<br/>PHP, Node"]
    api --> cache[("Redis<br/>cache, sessions")]
    api --> db[("MariaDB<br/>MongoDB")]
    web --> obs["Logs, metrics,<br/>alerting"]
    obs -.->|"something broke"| dev

    classDef node fill:#1C1C1F,stroke:#C6F36B,stroke-width:1px,color:#EDEBE4
    classDef store fill:#161618,stroke:#A3A29D,stroke-width:1px,color:#EDEBE4
    class dev,push,ci,art,web,api,obs node
    class cache,db store
Loading

What I reach for, and when

flowchart TD
    q{"What kind of job?"}
    q -->|"HTTP API, realtime"| n["Node.js"]
    q -->|"classic web app, CMS"| p["PHP"]
    q -->|"CLI tools, scripting, glue"| py["Python"]
    q -->|"user interface"| v["Vue + Vite"]
    n --> d1{"Data shape?"}
    p --> d1
    d1 -->|"relational"| m["MariaDB / MySQL"]
    d1 -->|"documents"| mo["MongoDB"]
    d1 -->|"hot, short-lived"| r["Redis"]
    d1 -->|"single file, embedded"| s["SQLite"]

    classDef node fill:#1C1C1F,stroke:#C6F36B,stroke-width:1px,color:#EDEBE4
    classDef decision fill:#161618,stroke:#A3A29D,stroke-width:1px,color:#EDEBE4
    class n,p,py,v,m,mo,r,s node
    class q,d1 decision
Loading

Stack

TypeScript, JavaScript, Python, PHP, Java, C++, Node.js, Vue, Vite, HTML, CSS

Linux, Bash, Docker, MySQL, MongoDB, Redis, SQLite, Prometheus, GitHub Actions, Git, GitLab

Also at home in Figma, Photoshop, After Effects and Blender.

Activity

GitHub metrics: activity, community, repositories, languages and contribution calendar

Contribution snake

How this profile updates itself
Workflow Status What it does When
Profile Profile renders the banner and project cards with live data (text set with HarfBuzz, so it looks the same everywhere), plus Recently shipped and Contributions (script) every 3 hours
Metrics Metrics activity, languages and calendar via lowlighter/metrics nightly
Contribution snake Snake turns the contribution graph into the snake above nightly
Link check Link check makes sure every link in this README still works weekly

Open to interesting backend and infrastructure work – the easiest way to reach me is an issue or discussion on one of my repositories.

Pinned Loading

  1. community-content community-content Public

    Forked from hetzneronline/community-content

    Hetzner Online Community Project

    Markdown

  2. elsbrock/hetzner-radar elsbrock/hetzner-radar Public

    🕵️Track prices of the Hetzner dedicated server auction

    TypeScript 395 18

  3. community/community community/community Public

    Public feedback discussions for: GitHub Mobile, GitHub Discussions, GitHub Codespaces, GitHub Sponsors, GitHub Issues and more!

    Ruby 8.8k 4.5k

  4. proxy-scraper proxy-scraper Public

    Free proxies that actually work: 700+ sources, every hit verified (honeypots, injected scripts, TLS), a live list every hour, a rotating proxy server and an MCP server for AI agents.

    Python 33 7