DARKORA WEBSITE INTELLIGENCE

github.com

https://github.com/

Last scan: July 26, 2026 30 evidence signals High confidence 1,948 ms evidence time Independent sources checked
DARKORA RISK SCORE
90/100
Strong trust signals

This report meets the evidence and publication threshold.

ASSESSMENT SUMMARY

What the collected evidence means

The scan found a broad set of mature technical, behavioural and transparency signals. Its TLS certificate was valid at scan time. Registration records show the domain has existed for more than two years. The accessible homepage exposed a contact route and linked policy or company information. Confidence is high based on 7 distinct evidence groups collected during the latest scan. The result is a risk assessment, not proof that github.com is legitimate or fraudulent.

28positive factors2caution factors30signals collected
LIVE SITE PREVIEW

Homepage screenshot

https://github.com/
Screenshot of github.com captured during the latest DarkOra scan
POSITIVE FACTORS

Signals that support trust

28

Valid TLS certificate

The certificate is trusted, matches the hostname and is currently valid.

TLS · transport · +7 points

HTTPS is active

The final page is delivered through an encrypted HTTPS connection.

Transport · transport · +4 points

Long-established domain registration

Registration records indicate an age of about 18 years.

RDAP · domain · +4 points

Website responded successfully

The scanned destination returned HTTP 200.

HTTP · transport · +3 points

Domain email controls are published

The domain exposes multiple mail-routing or anti-spoofing controls.

DNS · domain · +2 points

HSTS is present

The response includes the strict-transport-security header.

Security headers · security · +2 points

Content Security Policy is present

The response includes the content-security-policy header.

Security headers · security · +2 points

Strong MDN Observatory grade

MDN HTTP Observatory assigned grade A+.

MDN HTTP Observatory · security · +2 points

Contact route found

The page exposes a contact or support page.

Content · transparency · +2 points

security.txt is available

A security contact file was found under .well-known.

Public files · transparency · +2 points

Normal homepage content was accessible

The scanner received a usable HTML homepage rather than an interstitial or access-control page.

Content · behavior · +2 points

No monitored high-risk wording detected

The accessible homepage did not contain the monitored high-pressure or credential-request phrases.

Content · behavior · +2 points

Responsive origin server

The initial request completed in about 97 ms.

Performance · transport · +1 points

Public DNS resolution

The domain resolves to 1 validated public network address.

DNS · domain · +1 points

Nameserver redundancy

At least two authoritative nameservers were found.

DNS · domain · +1 points

Certificate authority policy

CAA records restrict which authorities may issue certificates.

DNS · domain · +1 points

Public routing identity found

RIPEstat mapped the address to AS36459 and prefix 140.82.121.0/24.

RIPEstat · domain · +1 points

MIME sniffing protection is present

The response includes the x-content-type-options header.

Security headers · security · +1 points

Referrer policy is present

The response includes the referrer-policy header.

Security headers · security · +1 points

Clickjacking protection

Framing is restricted through X-Frame-Options or CSP.

Security headers · security · +1 points

HSTS preload list entry

The hostname is included in Chromium’s HSTS preload status data.

Chromium HSTS Preload · security · +1 points

Descriptive page title

The homepage provides a usable browser title.

Content · transparency · +1 points

Page description is provided

The homepage includes a descriptive meta summary.

Content · transparency · +1 points

Some policy information is linked

At least one policy or company-information page was found.

Content · transparency · +1 points

robots.txt is available

The website publishes a non-empty robots.txt file.

Public files · transparency · +1 points

Substantive homepage content

The scanned page contains enough readable text to explain its purpose.

Content · transparency · +1 points

No hidden frames or external form targets

The accessible homepage did not expose hidden iframes or forms posting to another hostname.

Content · behavior · +1 points

Canonical URL declared

The page declares a canonical destination.

Content · transparency · +0 points
CAUTION FACTORS

Signals worth reviewing

2

Some cookies lack protection

1 response cookie lacked Secure or HttpOnly attributes.

HTTP cookies · security · -1 points

Missing permissions-policy

The response did not include this browser security header. Missing headers affect hardening, but do not by themselves prove fraud.

Security headers · security · 0 points
REPORT EVIDENCE

A deeper view of the latest scan

These values were observed at scan time and may change when the website, DNS or certificate configuration changes.

NETWORK & DNS

Infrastructure footprint

Resolved IP addresses
140.82.121.3
Authoritative nameservers
8
Mail / MX records
1
CAA policy
Published
SPF policy
Published
DMARC policy
Published
HTTPS & TLS

Connection security

HTTP status
200
Final protocol
HTTPS
Certificate validation
Trusted and valid
Certificate issuer
TLS protocol / cipher
TLSv1.3 TLS_AES_128_GCM_SHA256
Certificate expires
September 30, 2026
DOMAIN RECORD

Registration context

Approximate age
6,864 days
Registered
October 9, 2007
Expires
October 9, 2026
Registrar
MarkMonitor Inc.
RDAP status entries
3
RDAP available
Yes
PAGE & IDENTITY

Homepage transparency

Page title
GitHub · Change is constant. GitHub keeps you ahead. · GitHub
Canonical URL
https://github.com
Readable words
825
Contact signals
1
Policy / company links
1
Social profiles
None detected
BROWSER SECURITY

5/6 monitored headers present

83%
HSTSmax-age=31536000; includeSubdomains; preload
Content Security Policydefault-src 'none'; base-uri 'self'; child-src github.githubassets.com github.com/assets-…
X-Frame-Optionsdeny
X-Content-Type-Optionsnosniff
Referrer-Policyorigin-when-cross-origin, strict-origin-when-cross-origin
Permissions-PolicyNot detected
INDEPENDENT SIGNALS

External security and reputation context

These results are requested from named public providers by the background enrichment worker. Provider failures remain separate from the DarkOra base scan and never create a fabricated result.

GOOGLE PUBLIC DNSNot validated

DNSSEC authenticated data

The provider answered, but authenticated DNSSEC data was not confirmed.

Response code 0 · 1 answers
MDN HTTP OBSERVATORYA+

Independent header grade

MDN evaluated the live HTTP security configuration independently from DarkOra.

115 points · 9/10 tests passed
CHROMIUM HSTS PRELOADPreloaded

Preload-list status

Browsers can enforce HTTPS for this hostname before the first network request.

Independent transport-hardening context
RIPESTAT NETWORKAS36459

Routing and origin identity

The scanned address maps to prefix 140.82.121.0/24.

BGP present · registry present
GOOGLE WEB RISK

Official threat-list context

The optional official Web Risk integration is not configured.

Checked Jul 26, 2026
TRUSTPILOT

Official profile lookup

Trustpilot requires an official API key. DarkOra does not scrape profile pages; administrators can enable the supported integration from the dashboard.

Open Trustpilot profile
HTTP DELIVERY

Response and redirect details

Origin address used
140.82.121.4
Server header
github.com
Content type
text/html; charset=utf-8
Downloaded response
524,288 bytes (limited)
Redirect hops
0
Initial response time
97 ms
CONTENT FOOTPRINT

What the homepage exposes

Internal links
81
External links
13
External-link ratio
14%
Forms detected
4
Suspicious phrase groups
0
Scanner methodology
Version 4.0.0
REPORT GUIDANCE

Questions readers commonly ask

The answers below describe this report’s scope and limitations in plain language.

Is github.com safe to use?+

The scan found a broad set of mature technical, behavioural and transparency signals. Its TLS certificate was valid at scan time. Registration records show the domain has existed for more than two years. The accessible homepage exposed a contact route and linked policy or company information. Confidence is high based on 7 distinct evidence groups collected during the latest scan. The result is a risk assessment, not proof that github.com is legitimate or fraudulent.

How is the DarkOra score calculated?+

The score combines six independently capped areas: connection and TLS, domain maturity and DNS, browser security, identity and transparency, page behaviour, and external reputation. Anti-bot pages are not treated as the website’s real content.

Does a high score guarantee legitimacy?+

No. Automated evidence can reduce uncertainty, but it cannot prove ownership, product quality or honest intent. Verify payment details, company identity and independent reputation before sharing sensitive information.

COMMUNITY EXPERIENCE

Reviews from DarkOra members

Every review is tied to an account, checked for spam and published only after manual moderation. Reviews do not replace technical evidence.

No approved community review yet

Be the first member to describe a direct experience with this website.

SHARE A DIRECT EXPERIENCE

Write a review

Use this report as one part of your decision. Automated checks can miss newly created threats and may flag legitimate configurations. Verify the organization, payment recipient, refund terms and independent reputation before sharing money, credentials or sensitive data.