Loading the current evidence view. Navigation and account controls remain available.
GitHub scan
Loading the current evidence view. Navigation and account controls remain available.
supply-chain scan
Paste a repo, gist, raw script or release link. We check threat feeds, account and repo signals, and, with the deep scan, the code itself. Reads only; never executes repository code.
how it works
Works on a repo (github.com/owner/name), a gist, a raw.githubusercontent.com script, or a release download. Each returns a malicious / likely / suspicious / no-signal verdict with its evidence.
Reputation
Threat feeds + corpus for this exact URL, and any flagged infrastructure it references.
Account & repo
Age, ownership and traction: what separates a fresh throwaway from an established project.
Deep scan
Sandboxed clone → ClamAV signatures + Trivy + full-tree code analysis. Reads only.
coming in pro
Scan your dependency tree
Point Forensia at a manifest and get this verdict for every transitive dependency, on every push.