URL THREAT INTELLIGENCE · v0.5.0 · OPERATIONAL

The full anatomy of a phishing site,
one URL at a time.

ZeroPhish renders the page, runs twelve detection signals against the DOM, certificate chain, brand fingerprint and threat feeds, and returns a typed verdict. Built for security teams and product engineers.

scan
100 scans / day · free · typical scan 2–4 s ·
try
Scan another →
CACHED Showing previous scan from 17 d ago. Click Reanalyze to run a fresh scan.
SAFE · HIGH CONFIDENCE

No phishing signals detected

brand GitHub scan id 63c7f11d duration 10.32s signals 1 failing / 12
Risk score 0.04
4 / 100 · Low risk
Tags
https :// github . com /nemonicon/zerophishEx/
flagged registered domain path protocol / query
URL hxxps://GitHub[.]com/nemonicon/zerophishEx/
Host github[.]com
Brand GitHub
Screenshot https://cdn.zerophish.ai/bc4d80c4-2c8d-4418-8f47-c41c2f681095.jpg
Scan ID 63c7f11d-9be0-4ff3-92fa-26bac30d193c
17 d ago
SAFE github.com safe
17 d ago
SAFE github.com safe
17 d ago
SAFE github.com safe
17 d ago
SAFE github.com safe
419 d ago
REVIEW github.com safe
515 d ago
REVIEW github.com safe
516 d ago
REVIEW github.com safe
520 d ago
REVIEW github.com safe
Brand typo-squat detected
Registered brand domain
critical
Domain age
Awaiting analysis
high
Threat intel blocklists
Awaiting analysis
critical
Credential collection form
No credential collection form on visible content
high
×
Visual similarity to known brand
100% structural similarity to GitHub
high
Favicon impersonation
Favicon matches the registered owner
medium
SSL certificate
Served over HTTPS · certificate validated by ApiFlash
low
DNS reputation
Awaiting analysis
medium
showing 8 of 12 ·
Captured page
screenshot · captured at scan live page render
G
GitHub
github.com
100%
Host github.com
Registered domain github.com
Scheme https
Content length 318915 B
HTTP 200 · text/html
Initial scan heuristic + LLM

The website appears to be legitimate and belongs to GitHub as indicated by the URL. There’s no credential collection form on the page. The brand the page presents itself as matches with the URL and there’s no favicon impersonation.