Terms of use
Last updated: 10 October 2026
By using GiTRay you agree to these terms. They are short because the service is simple: it is free, it has no accounts, and it only reads public GitHub repositories.
The service
GiTRay is a free, non-commercial project, provided as it is and as long as it is available. It can change, slow down or stop at any time, without notice.
The site, its code and its design belong to its maintainer. All rights reserved.
How to read the results
Results are produced automatically by rules that look for known malware tricks. They are not a security audit and not a guarantee. A Clean verdict does not prove that a repository is safe, and GiTRay does not run the code it scans.
A Dangerous verdict or a place on the Scammer list is an automated assessment of the files in one commit. It is not a statement about the people behind a repository, and it can be wrong: security tools and malware research often contain the very patterns GiTRay looks for. Read the findings before you decide.
You decide what you clone, install or run, and you are responsible for that decision.
Repositories and their content
Only public GitHub repositories can be scanned. Their content belongs to their owners. Reports show short excerpts of files, made harmless and linked to the original on GitHub, only to explain a finding.
Fair use
GiTRay shares a limited GitHub and VirusTotal quota between all visitors, so scans are limited per visitor and per hour. Do not scan in bulk with scripts, try to get around the limits, or attack, overload or probe the service. The JSON API at /api/scan can be used for personal, non-commercial use within the same limits.
Liability
To the extent the law allows, GiTRay and its maintainer accept no liability for any damage that results from using the site or relying on its results, including a repository that turns out to be malicious after a Clean verdict.
Changes
These terms can change; the date at the top shows the latest version.