Is github.com legit?
GitHub.com is a highly trusted platform with excellent security and a strong online presence. The only minor concern is the high number of external scripts, which warrants a security best practice review for potential third-party risks.
Software & Downloads average: 78/100 · based on 75 sites
Checked: April 21, 2026 at 4:07 AM UTC
Is github.com a scam? Here's what we found.
The site uses modern TLS 1.3, has HSTS and CSP configured, and is deemed clean by Google Web Risk. The only notable concern is the large number of external scripts, which introduces potential supply chain vulnerabilities.
With a domain age of almost 19 years and registration through a reputable registrar like MarkMonitor, GitHub demonstrates a very strong and established identity.
Ranked as one of the most visited websites globally, GitHub has an outstanding reputation. It's clean on DNS blacklists, reinforcing its trustworthiness and widespread acceptance.
The site provides clear contact information, complete branding, and an active social media presence, indicating a high level of transparency in its operations.
GitHub effectively meets compliance expectations by providing both privacy and terms of service pages, which are essential for user trust and legal obligations.
The site benefits from robust infrastructure, including DMARC for email authentication, multiple name servers for redundancy, and fast page load times, signaling reliability and efficiency.
Signals Detected
This is one of the most visited websites globally
No structured data markup found
This business has no Trustpilot presence — not unusual for smaller or newer companies
Valid certificate, expires in 43 days
Certificate issued by Sectigo Limited
Connection uses TLS 1.3
Domain created 2007-10-09T18:20:50Z (18 years, 9 months ago)
Registered through MarkMonitor Inc.
Expires in 171 days
DNSSEC status from WHOIS
crt.sh returned status 429
robots.txt has 89 directives
Site has custom branding and social media metadata
Excessive number of external scripts — may indicate malicious injection
Site enforces HTTPS via HSTS
Site has Content Security Policy configured
X-Frame-Options: deny
Web server: github.com
No threats detected by Google Web Risk
Resolves to: 140.82.112.4
Mail servers: github-com.mail.protection.outlook.com.
Domain has DMARC email authentication configured
DNS providers: dns1.p08.nsone.net., dns2.p08.nsone.net., dns3.p08.nsone.net., dns4.p08.nsone.net., ns-1283.awsdns-32.org., ns-1707.awsdns-21.co.uk., ns-421.awsdns-52.com., ns-520.awsdns-01.net.
No sitemap found — common for smaller sites
Website is live and responding
Website appears to have contact information
Website has both privacy policy and terms of service pages
Website links to multiple social media platforms
Not found on any DNS blacklists
Could not query Wayback Machine
Fast page load
Stay Safe Online
Good habits to protect yourself, no matter the scan result.
Never reuse passwords across sites.
Add a second layer of security to your accounts.
Always verify unfamiliar stores before entering payment info.