Review 02 · Live Intelligence
Flights.
A drawn radar scope of the aircraft volunteer receivers can hear around fifteen cities. It will not guess where a plane is, which is both its principle and its limit.
- Tested 27 September 2026, 20:10–20:12 UTC
- Where the work happens through a narrow relay on the tool’s own site
- Against Flightradar24, ADS-B Exchange, adsb.lol
1What it is, and who it is for
Flights draws a radar scope over one of fifteen world cities: every aircraft community ADS-B receivers can hear, with range rings, short trails, emergency flags and a board sorted nearest first, carrying callsign, type, altitude, speed, climb rate, squawk, distance and bearing.
It is for anyone who wants to know what is flying over a big city right now and prefers plain numbers to a commercial tracker's layers.
2How it works
Your browser asks its own site, not the network. flights/assets/js/app.js polls sky-proxy.php every 10 seconds while the tab is visible, and stops when it is hidden (app.js 34, 86–87, 377). The relay exists for one reason: api.adsb.lol answers openly but sends no CORS header, so a page in a browser cannot read it directly (sky-proxy.php 2–9).
It is written so that it cannot become an open proxy. There is one hard-coded upstream route, api.adsb.lol/v2/point/{lat}/{lon}/{radius}; three numbers are checked with FILTER_VALIDATE_FLOAT and range tests; the radius is capped at 250 nautical miles; anything else gets a 400 and no fetch (10–18, 45–51, 77). A shared 10-second file cache per rounded point means a crowd watching one city costs one upstream call every 10 seconds (19–21, 61–69), and the relay re-encodes its own parse instead of passing the upstream's bytes through (117–123).
On the page, aircraft the network heard without a position are counted as heard only and never placed (app.js 118). Distance and bearing are computed on the sphere (51–60), and squawks 7500, 7600 and 7700 are named in plain words (35, 179).
3The test
We loaded the page from the local 537 copy and called its relay for New York at the default 50-nautical-mile radius, twice, then tried to misuse it.
Loaded the page.
HTTP 200, 52,348 bytes; app.js 15,743 bytes; sky-proxy.php 5,419 bytes.
Called the relay for New York, r=50.
HTTP 200 in 0.38 s, 88,819 bytes, X-Sky-Cache: miss. 191 aircraft, every one with a position; 93 reporting 'ground'; 8 without a callsign. Each record carried about 40 fields.
Sent the same request one second later.
HTTP 200 in 0.0007 s, the identical 88,819 bytes, X-Sky-Cache: hit.
Asked for r=900, then passed a url parameter.
Both refused with HTTP 400: 'r must be a radius in nautical miles, (0, 250]', then 'lat must be a number in [-90, 90]'. No url parameter is accepted at all.
4Against the field
Each rival was read on its own pages on the test day. Pencil marks what it does better; red, where Flights goes further.
Flightradar24
flightradar24.com · checked 27 September 2026, 20:13 UTC, from its own help pages via search (the site refused our fetch)
A commercial live tracker built on ADS-B receivers, multilateration from at least three ground receivers, and satellite ADS-B for aircraft outside ground coverage.
In pencil
- A worldwide map you can centre anywhere, not fifteen cities.
- It fills gaps with multilateration, satellite ADS-B and estimated positions, for up to 240 minutes where the route is known.
- Known routes, origin and destination, which the labs board does not have.
In red
- It never draws an estimated position: every wedge is a real last-heard report, and aircraft heard without a position are counted separately.app.js 7–9, 118
- Raw numbers for each aircraft (vertical rate, squawk, distance, bearing) on a nearest-first board with emergencies named.app.js 119–133, 179
ADS-B Exchange
adsbexchange.com · checked 27 September 2026, 20:13 UTC
Community-fed tracking that displays broadcasts as received, with, in its own words, ‘Over 25K active receivers’ and ‘High-fidelity archives’ for reconstruction and analysis.
In pencil
- History and archives for reconstruction; Flights keeps none.
- A far larger footprint, on a global map.
In red
- A deliberately small scope, with rings at 25 and 50 nm plus your radius, drawn on the page's canvas and re-inked for paper or dark.app.js 218–240
- A shared 10-second cache, so many viewers cost one upstream call.sky-proxy.php 19–21, 58–69
adsb.lol
adsb.lol · checked 27 September 2026, 20:13 UTC
The open-data, unfiltered tracker that Flights reads: a live globe, and a free API published under the ODbL 1.0 licence.
In pencil
- Its globe covers the whole network rather than fifteen circles.
- It is the data itself, openly licensed for anyone to build on.
In red
- It makes the API readable from a browser page by adding the missing CORS header, through a relay that cannot be aimed elsewhere.sky-proxy.php 2–18
- It turns 40-field records into a readable board with plain-words emergency flags.app.js 112–133, 179
5Where it falls short
- Fifteen fixed cities. You cannot centre the scope on your own location or any other point; app.js has no geolocation.
- No routes, airlines or photos. The board shows only what the ADS-B record carries.
- No history. Trails reach back at most 30 polls and vanish on reload; there is no playback.
- Coverage is the volunteers' coverage. With no satellite or estimated positions, a thinly covered area shows few aircraft or none.
6The verdict
Flights is the rare tracker that shows only what was heard, and its relay is a small, clean example of a safe cross-origin read; it is not the tool for tracing one flight's route or history.
- In red ink
- No interpolation, 'heard only' counted, emergency squawks named, and a locked relay with a shared cache.
- In pencil
- For routes, history or anywhere beyond fifteen cities: Flightradar24 or ADS-B Exchange.