01 / The verdict
The short answer
Yes - the record supports it. Valid encryption, a reachable operator and a real footprint: this software service looks like a business built to stay, not a storefront built to vanish.
In short: LegitVerdict rates GitHub (github.com) 77/100 - the evidence supports it as legitimate. The score breaks down into risk 27/100 (lower is safer), trust 81/100 and buyer-safety 70/100 (higher is safer to transact), at 70% confidence, computed from published, weighted signals.
On its public pages, github.com runs a software service operating from DE. Valid HTTPS from a trusted authority, published contact details, a multi-year domain history and a measurable traffic footprint are on record. That combination is exactly the kind of transparency a trustworthy operation provides and a throwaway site usually hides.
Instead of one blended number, this report keeps risk, trust and buyer-safety apart. The business earns its result on each axis independently - the breakdown below shows the contribution of every signal, weighted by the published methodology.
A reminder on scope: this is an automated assessment of the website and domain - not a legal finding, not financial advice, and not an endorsement of what the operator publishes or sells.
Analysed 7 Jul 2026 3 days ago
Re-check this domain02 / The three scores
Risk, trust & buyer-safety
Three separate scores, each from its own evidence, so it is always clear what is being measured. Here is how github.com performs on each - and the signal breakdown that rolls up into them.
Low danger, with caveats. The hard safety checks pass for github.com, but a few transparency gaps - the ones flagged below - stop the risk reading from dropping into the cleanest tier.
The operator hides nothing we test for: identity, company registration, working contacts, a physical footprint. Full marks on transparency are rare and github.com earns them.
Where it counts for a shopper, github.com checks out: protected payment, visible contact and policy detail, an operator who can be reached if an order goes wrong.
Signal breakdown
The three scores above roll up these signal groups - each a grouped level from the live evidence, not the individual weights.
- Domain & registration
- 88/100
- Technical & server
- 80/100
- Reputation & reviews
- 82/100
- Business & transparency
- 59/100
- Social & content
- 84/100
Higher is stronger. Grouped from the live signals in the itemised evidence below - the exact weights are public on the methodology page.
03 / At a glance
Highlights & points to note
The fastest read on the domain: what is working in its favour, and the items worth attention. The full evidence for each is further down the report.
04 / The full record
Every detail, on file
The raw data behind the scores, grouped by area - registration, security, hosting, performance, reputation. Open any tab to inspect the evidence yourself.
05 / The evidence, itemised
Every signal, explained
Open any signal to read what it means for github.com and why it scores the way it does. Each one is tagged with the score it feeds.
Domain age18 years oldClean - risk
18 years old of continuous existence is on record for github.com - a track record that predates most scam domain lifecycles many times over.
Fraudulent storefronts are typically abandoned within months of registration, so domain age is one of the strongest cheap signals available.
Registration periodregistered for 19 yearsClean - trust
Github.com is registered for 19 years - a multi-year commitment visible directly in the registry record.
Scam domains are nearly always registered for the single cheapest year; a long horizon is a quiet but honest trust marker.
WHOIS privacyregistrant details publicClean - risk
The registrant is publicly identifiable in the registration record: registrant details public.
Public registrant data has become rare since GDPR, so when an operator volunteers it, it counts as extra transparency.
Registrar reputationMarkMonitor Inc.Clean - risk
MarkMonitor Inc. Holds the registration - an established registrar that polices its zone.
Reputable registrars suspend abusive customers quickly, which makes their zones structurally safer.
TLD risk profilestandard TLD (.com)Clean - risk
The extension here - standard TLD (.com) - carries no abuse history worth mentioning.
Nothing about the extension moves the risk needle.
Server locationhosted in DEClean - risk
Hosting checks out - hosted in DE, with stable DNS records behind it.
Where a site is hosted matters less than how stably it is hosted - both look normal for the operation.
SSL certificatevalid DV certificate (Sectigo Limited)Clean - risk
Encryption is in order: valid DV certificate (Sectigo Limited), verified end to end during our handshake.
Certificates are cheap but discipline is not - a correctly maintained TLS setup is table-stakes competence made visible.
Response speedresponds in 197 msClean - ai
Response times are healthy - responds in 197 ms on our last measurement.
Fast responses indicate maintained infrastructure and help every crawler - search and AI alike - index every page fully.
Search engine blockingopen to search enginesClean - risk
The business is fully open to search engines (open to search engines).
Visibility is accountability: a site that wants to be found accepts being examined.
Mail infrastructureoperational mail server (MX)Clean - risk
We could not obtain this measurement for github.com during the latest check.
LegitVerdict treats absent measurements as unknowns, not negatives; they will fill in on a future recompute.
Email authenticationenforced email authentication (DMARC p=quarantine, SPF)Clean - risk
This data point was unavailable when the business was last analysed.
LegitVerdict treats absent measurements as unknowns, not negatives; they will fill in on a future recompute.
Security hardeningHSTS, CSP, nosniff, HTTPS-forcedClean - risk
This data point was unavailable when the business was last analysed.
LegitVerdict treats absent measurements as unknowns, not negatives; they will fill in on a future recompute.
Traffic popularity (Tranco)Tranco rank 29Clean - trust
Independent traffic data confirms a real audience: Tranco rank 29 in the research-grade Tranco list.
An audience this measurable means thousands of users already vote for github.com with their visits.
Contact detailstwo of three contact channels publishedClean - risk
Reaching the operator is straightforward: two of three contact channels published.
Full contact data also enables the recourse that separates a dispute from a loss.
Address specificityaddress details on the pageClean - risk
Address details appear on the page (address details on the page).
A published address is a falsifiable claim - and falsifiable claims are what transparency is made of.
Product category risksoftware serviceClean - risk
The business falls in the software service category.
Everyday categories carry no inherent risk premium.
Social presenceinstagram, linkedin, tiktok, x, youtubeClean - trust
Linked social profiles are present: instagram, linkedin, tiktok, x, youtube.
Social history is expensive to fabricate at scale, which makes it a useful corroborating signal.
Technology stackmagento, shopifyClean - ai
Under the hood the business uses magento, shopify - mainstream, maintained technology.
A standard platform implies updates, payment-module vetting and an ecosystem of accountability.
Contact email typethird-party business emailNeutral - risk
Contact runs through a third-party business address (third-party business email).
This is a minor note rather than a warning - reachable is what matters most.
Industry associationslimited public affiliationsNeutral - trust
We found limited public affiliations during the page analysis.
This signal only ever adds; it never subtracts.
Trust sealsno trust seals displayedNeutral - trust
No trust seals displayed on the pages we analysed.
The engine notes the absence purely for completeness.
Company registration (BG registry)no company ID published (not all jurisdictions publish one)Neutral - risk
No company identifier is published on github.com for registry verification.
Many jurisdictions do not require publishing one, so absence is treated gently.
Payment methodsno payment methods detectedNeutral - risk
Payment methods were not detectable from the public pages of github.com.
Some checkouts reveal options only after login; the engine treats this as unknown, not negative.
Review independenceon-site testimonials treated as unverifiedNeutral - risk
On-site testimonials for github.com are counted as marketing, not as evidence.
Only independent, third-party review footprints move this part of the analysis.
Content quality2634 words, 2/4 legal pages linkedNeutral - trust
The business publishes a workable but not deep public surface - 2634 words, 2/4 legal pages linked.
Nothing here moves the score much in either direction.
06 / The AI-readiness lens
How AI search reads github.com
A secondary, owner-facing lens - it does not affect the safety verdict above. Users increasingly ask an assistant before a search box, so these checks measure whether the models can actually read, understand and cite github.com. AI-readiness scores 8.3/10.
Users asking AI assistants about github.com get answers grounded in a crawlable, structured source rather than guesswork - the position every business wants to be in, and github.com is close.
LegitVerdict reads the live page the way a browser and an AI crawler do - these checks reflect what models actually see. Accuracy is the entire product.
07 / Staying safe
How to protect yourself
Practical, evidence-based steps for this domain - whether you are about to transact or want to be sure.
Nothing in the record suggests github.com is unsafe. Standard online-shopping hygiene still applies:
- Pay with a method that offers buyer protection - a card or PayPal lets you dispute a charge if an order goes wrong.
- Keep the order confirmation and any correspondence until the goods arrive as described.
- Check that prices and delivery terms match elsewhere - a clean trust profile does not guarantee the best price or product.
- If something feels off during checkout, stop and contact the operator using the published details before paying.
Multi-source safety check
The live abuse and phishing sources could not be reached for github.com this analysis, so no listing result is shown. A missing check is not read as danger.
| Source | What it checks | Result |
|---|---|---|
| abuse.ch Feodo Tracker Licence: CC0 (abuse.ch) | The hosting IP address against known botnet command-and-control servers. | Source unavailable Could not be reached for this analysis. |
| abuse.ch SSL Blacklist Licence: CC0 (abuse.ch) | The hosting IP address against malicious-SSL and C2 fingerprints. | Source unavailable Could not be reached for this analysis. |
| Criminal / hijacked netblock list Licence: Free for commercial use (internal signal) | The hosting netblock against a list of criminal or hijacked IP ranges. | Source unavailable Could not be reached for this analysis. |
| Open phishing-domain blocklist Licence: MIT (Phishing.Database) | The domain name against an open-source phishing-domain blocklist. | Source unavailable Could not be reached for this analysis. |
Each row reflects only what that authoritative source publishes. A domain absent from a list is shown as “no listing found”, never as an endorsement - absence of a listing is not proof of safety, and a source we could not reach is not read as danger. Sources and their licences are documented on the methodology page.
08 / How LegitVerdict scores
Method & limits
Scoring methodology reviewed by The LegitVerdict Team, Search & AI-visibility engineering, technical SEO. This report was generated automatically on 7 Jul 2026 from live sources and states its own confidence (70%).
Registration and ownership records, security and hosting signals, reputation and popularity data, and the domain's own public pages - contacts, payments, content and structured data. Where a business is officially registered, we cross-check the public company record too.
Signals are sorted into risk, trust and buyer-safety and scored independently against a documented methodology - so a strong score in one area can never paper over a weakness in another, and every point is explainable. A secondary AI-readiness lens measures machine visibility only.
An automated assessment of a website and domain - not a legal finding, financial advice, or an endorsement of any product. A trust score is a probability signal stated with its confidence; owners can verify and correct the record for free.
Verifying takes a few minutes and the only condition is control of the domain. Verified owners can add details, respond on the record, and unlock the full AI-readiness fix list.
- 01 Add a DNS TXT record, or upload a small HTML file
- 02 We confirm you control the domain - that is the only condition
- 03 Verified badge goes live - a followed link is granted above the trust threshold
Verification proves control, not endorsement. Links are nofollow by default and only become followed for verified domains above the trust threshold.
09 / Questions
People also ask
Is github.com legit?
The record says yes: Valid HTTPS from a trusted authority, published contact details, a multi-year domain history and a measurable traffic footprint are on record. Together these are the marks of a real operation rather than a disposable storefront.
What do reviews say about github.com?
Rather than aggregate reviews that are trivial to game, this report checks the record itself. It comes back clean for the operation: Valid HTTPS from a trusted authority, published contact details, a multi-year domain history and a measurable traffic footprint are on record. Testimonials github.com publishes about itself prove nothing either way.
Is github.com safe to use?
The checks that matter for a purchase - encryption, operator reachability, payment rails - come back positive. Standard buyer hygiene applies, but the record supports transacting.
Is github.com a scam?
Nothing in the record matches the patterns fraud systems are trained to catch. Valid HTTPS from a trusted authority, published contact details, a multi-year domain history and a measurable traffic footprint are on record. On the evidence, github.com does not read as a scam.
Is github.com trustworthy?
The record supports trust: Valid HTTPS from a trusted authority, published contact details, a multi-year domain history and a measurable traffic footprint are on record. Nothing here undermines the credibility of this software service, though the usual online caution still applies.
What is github.com's LegitVerdict Trust Score?
The LegitVerdict Trust Score for github.com is 77/100 (3.9 out of 5) - an algorithmic rating of the domain's trustworthiness. It breaks down into risk 27/100 (lower is safer), trust 81/100 and buyer-safety 70/100 (higher is safer to transact), at 70% confidence, from 25 live signals. The methodology and weights are public.
Who is behind github.com?
For github.com, the public record shows an operation based in DE, an email address and address details published openly and linked social profiles. The operator can verify ownership to attach full company details to this report.
How is this different from other scam checkers?
Most checkers output one blended number, then sell a paid review to change it. LegitVerdict reports risk, trust and buyer-safety as separate scores, opens the full technical record, publishes its weights, states confidence honestly, and lets owners correct the record for free.