low risk85/100
github.com
The site uses HTTPS, has a privacy policy. Overall score 85/100 (low risk).
| Submitted URL | http://github.com |
|---|
| Normalized URL | http://github.com/ |
|---|
| Final destination | https://github.com/ |
|---|
| Scan date | 2026-06-11 18:17 UTC |
|---|
| Status | completed |
|---|
| Proxy mode | disabled |
|---|
| Proxy used | no |
|---|
| Final response hash | 256f6fa8250f1206d7a8a5b288e258157847beadc0452b1c1742f305b1a24168 |
|---|
| Rendered HTML hash | 771bd023e39ac2719edca14e9935f8b30a921ff0cd495ba7564cbd669dda3fe4 |
|---|
Technical: 25 Legal: 20 Stability: -10 Suspicious: 0
Positive signals
- Final destination uses HTTPS.
- HSTS header present.
- Content-Security-Policy present.
- Privacy policy found.
- Legal entity information found.
- VirusTotal: no engines flagged this domain.
- Domain is well established (~18 years old).
Neutral / informational
- Engines returned different final content (could be dynamic content).
Screenshot
Redirect history
| Engine | From | To | Status |
|---|
| requests | http://github.com/ | https://github.com/ | 301 |
Detected technologies
| Name | Category | Confidence | Evidence |
|---|
| Shopify | ecommerce | 80% | shopify assets |
Server / security headers
| content-security-policy | default-src 'none'; base-uri 'self'; child-src github.githubassets.com github.com/assets-cdn/worker/ github.com/assets/ gist.github.com/assets-cdn/worker/; connect-src 'self' uploads.github.com www.githubstatus.com collector.github.com raw.githubusercontent.com api.github.com github-cloud.s3.amazonaws.com github-production-repository-file-5c1aeb.s3.amazonaws.com github-production-upload-manifest-file-7fdce7.s3.amazonaws.com github-production-user-asset-6210df.s3.amazonaws.com *.rel.tunnels.api.visualstudio.com wss://*.rel.tunnels.api.visualstudio.com github.githubassets.com objects-origin.githubusercontent.com copilot-proxy.githubusercontent.com proxy.individual.githubcopilot.com proxy.business.githubcopilot.com proxy.enterprise.githubcopilot.com *.actions.githubusercontent.com wss://*.actions.githubusercontent.com productionresultssa0.blob.core.windows.net productionresultssa1.blob.core.windows.net productionresultssa2.blob.core.windows.net productionresultssa3.blob.core.windows.net productionresultssa4.blob.core.windows.net productionresultssa5.blob.core.windows.net productionresultssa6.blob.core.windows.net productionresultssa7.blob.core.windows.net productionresultssa8.blob.core.windows.net productionresultssa9.blob.core.windows.net productionresultssa10.blob.core.windows.net productionresultssa11.blob.core.windows.net productionresultssa12.blob.core.windows.net productionresultssa13.blob.core.windows.net productionresultssa14.blob.core.windows.net productionresultssa15.blob.core.windows.net productionresultssa16.blob.core.windows.net productionresultssa17.blob.core.windows.net productionresultssa18.blob.core.windows.net productionresultssa19.blob.core.windows.net github-production-repository-image-32fea6.s3.amazonaws.com github-production-release-asset-2e65be.s3.amazonaws.com insights.github.com wss://alive.github.com wss://alive-staging.github.com api.githubcopilot.com api.individual.githubcopilot.com api.business.githubcopilot.com api.enterprise.githubcopilot.com edge.fullstory.com rs.fullstory.com; font-src github.githubassets.com; form-action 'self' github.com gist.github.com copilot-workspace.githubnext.com objects-origin.githubusercontent.com; frame-ancestors 'none'; frame-src viewscreen.githubusercontent.com notebooks.githubusercontent.com www.youtube-nocookie.com; img-src 'self' data: blob: github.githubassets.com media.githubusercontent.com camo.githubusercontent.com identicons.github.com avatars.githubusercontent.com private-avatars.githubusercontent.com github-cloud.s3.amazonaws.com objects.githubusercontent.com release-assets.githubusercontent.com secured-user-images.githubusercontent.com user-images.githubusercontent.com private-user-images.githubusercontent.com opengraph.githubassets.com marketplace-screenshots.githubusercontent.com copilotprodattachments.blob.core.windows.net/github-production-copilot-attachments/ github-production-user-asset-6210df.s3.amazonaws.com customer-stories-feed.github.com spotlights-feed.github.com explore-feed.github.com objects-origin.githubusercontent.com *.githubusercontent.com images.ctfassets.net/8aevphvgewt8/; manifest-src 'self'; media-src github.com user-images.githubusercontent.com secured-user-images.githubusercontent.com private-user-images.githubusercontent.com github-production-user-asset-6210df.s3.amazonaws.com gist.github.com github.githubassets.com assets.ctfassets.net/8aevphvgewt8/ videos.ctfassets.net/8aevphvgewt8/; script-src github.githubassets.com; style-src 'unsafe-inline' github.githubassets.com; upgrade-insecure-requests; worker-src github.githubassets.com github.com/assets-cdn/worker/ github.com/assets/ gist.github.com/assets-cdn/worker/ |
|---|
| content-type | text/html; charset=utf-8 |
|---|
| server | github.com |
|---|
| strict-transport-security | max-age=31536000; includeSubdomains; preload |
|---|
Privacy & legal identity
Privacy policy found: https://docs.github.com/site-policy/privacy-policies/github-privacy-statement
Legal entity indicators:
- linked to you. It applies to the Personal Data that GitHub, Inc.
- It applies to the Personal Data that GitHub, Inc. or GitHub B.V.
External reputation
| Domain age | 6819 days — registered 2007-10-09T18:20:50Z |
|---|
| Registrar | MarkMonitor Inc. |
|---|
| VirusTotal | malicious 0, suspicious 0, harmless 62, undetected 29 · reputation 120 |
|---|
| Google Safe Browsing | unavailable (safebrowsing status 403) |
|---|
Engine comparison
| Engine | OK | Status | Final URL | Body hash | Error |
|---|
| chrome | ✅ | 200 | https://github.com/ | 771bd023e39ac271… | — |
|---|
| curl_cffi | ✅ | 200 | https://github.com/ | 256f6fa8250f1206… | — |
|---|
| requests | ✅ | 200 | https://github.com/ | b716b2aaa2de3d8c… | — |
|---|
Page content
Plaintext HTML (571966 bytes)
View raw JSON
← Back home