← Back to Home

Is pentestgpt.ai/login Legit or a Scam? Warning Signs!

Website: pentestgpt.ai/login

Screenshot of pentestgpt.ai/login

Safety Score How we score →

55/100
Needs Review

This result needs manual review before you rely on it.

First analyzed Nov 5, 2025 · Updated Sep 19, 2026

Think this is wrong? Dispute this verdict — free.

Why this score

  • Canonical verdict: Needs Review with a 55/100 final score.
  • 6 guardrail adjustments influenced the published result.
  • Evidence state is Unknown and review status is Needs Review.
Final score
55/100
Canonical published score used on the public result page.
Final status
Warning
Published backend status from the canonical read model.
Raw AI score
55/100
Content-review score before canonical guardrails and publication checks.
Score source
openai guardrail
Recorded by the canonical guardrail pipeline.
Confidence
Low
Confidence attached to the published canonical outcome.
Caution signals
  • Redirect-only domain: pentestgpt.ai redirects to signin.hackerai.co; relationship to signin.hackerai.co unverified
  • Subdomain inheriting trust from parent domain pentestgpt.ai (score: 100/100, capped to 85/100) - infrastructure verified (85 points): 2+ shared nameservers (2), 3 shared IP(s), SSL certificate covers parent domain
  • Applied site-type-aware risk policy (general:phishing login payment surface) warning cap
  • Sensitive phishing login payment surface surface kept in warning because of limited deterministic evidence, material contradiction pressure, stale archive continuity evidence
  • Deterministic contradiction assessment found material conflicts (archive continuity contradictions)
  • Deterministic evidence sufficiency is limited and should temper the explanation (47% coverage)
Evidence summary
Confidence: Low
Evidence state: Unknown
Review status: Needs Review

AI Analysis Results

Category: Web Application
About this website:

Detailed Analysis Report: Is https://signin.hackerai.co/?client_id=client_01JXJMN004P40WZ3BSMDHX4XN8 redirect_uri=https%3A%2F%2Fhackerai.co%2Fcallback state=Fe26.2*1*3e960510b4ffe4b4a7713e7d12df94b2f3d101ec93f335d86155b056bb298761*giXu5rc643AFkKIXAUEpVQ*yqE_c7DjFp-H5K_idxsApg5S1iyA8BxQgyKjZ6-9tXo3SBcY_4OpoZxQtg7DcR5MGeTzBxYXtbdOjvwviAytArhFsfa6kjwc9qYvOoBJWaKx7_4a2IpqDtsr95OQxZzE3-gLttpfZ3agsXjM7Mb_qA*1789876199718*bdeb0b880a5846f814407f879c411746e75991bb15a0d2dce15c93762a318c89*N003MexT5056E3JcbXWcwUMtFLjMnsuzqlykYZ2LEiw%7E2 authorization_session_id=01M2YECGDS62DPN6X9263M5F81 Safe and Legit? Website Overview and Purpose The analyzed page was the /login path rather than the homepage, so this report is anchored to that specific page experience. The scraped title was Sign in . The visible page appears to serve the following purpose: Credential Management. Visible on-page text referenced Sign in Sign in Email Continue with email OR Continue with Google Continue with Microsoft Continue with Apple Don t have an account? Sign up Terms of Service and Privacy Policy. . The content appears aimed at Users seeking penetration testing services. In classification terms, the page aligns most closely with Web Application and Login Portal characteristics. Content Quality and User Experience Key Experience Highlights The requested page path /login was preserved during scraping, so this review reflects that specific page rather than a generic homepage substitute. The scraped title was Sign in , which gives a direct signal about what the page presents to visitors. The visible page appears to serve the following purpose: Credential Management. The page appears aimed at Users seeking penetration testing services. No additional internal page content was needed for a baseline view of the visible experience. Observed transparency on accessible pages: contact signals were limited and policy signals were present . Additional observed context from the analysis included: Domain is 767 days old, which is relatively new and may indicate a lack of established trust | SSL certificate is valid, providing a secure connection, but does not guarantee legitimacy | The login page redirects to hackerai.co, which raises concerns about potential phishing or credential harvesting. Claims Verification and Red Flags Red Flags Detected From a cybercrime and cybersecurity perspective, the visible page content appears commercially transactional and is trying to move the visitor toward a purchase or service-order flow; looks tied to an external account or platform profile, which raises the impact if credentials or access are mishandled. Those observed behaviors do not prove fraud by themselves, but they do increase the importance of validating operator identity, payment safety, and account-handling practices before trusting the service. Finding: High-risk redirect to hackerai.co | Evidence: login process Finding: Missing contact information | Evidence: no contact details provided Finding: Missing terms of service | Evidence: no terms available Finding: Privacy policy present but lacks detail | Evidence: privacy policy link available but no content Caution Points Treat the page as a commercial offer: verify pricing, refund rules, payment handling, and dispute options before paying. If the service touches a third-party account or profile, avoid sharing raw credentials unless the workflow is independently verified and clearly documented. Read the available privacy or policy pages to understand liability, support scope, and what data the operator says it collects. Contact transparency appears limited, so treat support and dispute recovery as uncertain until independently verified. Verify operator identity, ownership trail, and off-site reputation before escalating from browsing to payment, login, or installation. Security Note: SSL is valid (issuer: WE1 ), VirusTotal reports 0/unknown detections, WebRisk status is CLEAN , SPF is missing , and DMARC is configured . Legitimacy and Reputation Assessment Technical and reputation evidence is secondary to the page-content review above, but it still matters. Domain age evidence indicates 2 year(s) based on whois . Archive continuity suggests archive continuity could not be verified in this run . Threat-intelligence checks currently show no direct malicious-engine consensus, while WebRisk is CLEAN . Reputation telemetry shows no meaningful Tranco ranking , and visible transparency signals are limited for contact details and present for policy/legal pages. Final Verdict and Recommendations The current result is warning with a trust score of 55/100 . Primary classification from this run: warning with score 55/100 in Web Application (Login Portal). Conclusion: Overall risk remains in warning territory, so users should require additional proof before trusting critical interactions. Exercise caution when using this site. Verify its legitimacy before entering any personal information.

Risk Assessment: Needs Review
⚠️ Red Flags:
  • [REDIRECT] High-risk redirect to hackerai.co | Evidence: login process
  • [CONTACT] Limited Contact Accountability | Contact accountability signals were limited on captured pages.
  • [TERMS] Missing Terms & Conditions | Terms and conditions were not clearly detected on captured pages.
  • [PRIVACY] Privacy policy present but lacks detail | Evidence: privacy policy link available but no content
📊 Analysis Reasons:
  • [DOMAIN_AGE] Domain is 767 days old, which is relatively new and may indicate a lack of established trust.
  • [SPF_RECORD] The site lacks SPF records, which are important for email authentication and security.
  • [CONTACT_TRANSPARENCY] There is no contact information or legal documentation available, indicating poor transparency.
🛡️ Safety Actions Applied:
  • {"type":"redirect_scope_note","reason":"Redirect-only domain: pentestgpt.ai redirects to signin.hackerai.co; relationship to signin.hackerai.co unverified","scoreFloor":null,"scoreCeiling":null,"targetStatus":null}
  • {"type":"subdomain_inheritance","reason":"Subdomain inheriting trust from parent domain pentestgpt.ai (score: 100/100, capped to 85/100) - infrastructure verified (85 points): 2+ shared nameservers (2), 3 shared IP(s), SSL certificate covers parent domain","scoreFloor":75,"scoreCeiling":null,"targetStatus":"warning"}
  • {"type":"risk_policy_warning_cap","reason":"Applied site-type-aware risk policy (general:phishing_login_payment_surface) warning cap","scoreFloor":null,"scoreCeiling":62,"targetStatus":"warning"}
  • {"type":"uncertainty_sensitive_surface_warning","reason":"Sensitive phishing_login_payment_surface surface kept in warning because of limited deterministic evidence, material contradiction pressure, stale archive continuity evidence","scoreFloor":null,"scoreCeiling":55,"targetStatus":"warning"}
  • {"type":"contradiction_material","reason":"Deterministic contradiction assessment found material conflicts (archive_continuity_contradictions)","scoreFloor":null,"scoreCeiling":null,"targetStatus":"warning"}
Score Source: openai_guardrail
AI Confidence: low

Frequently asked questions about pentestgpt.ai/login

Is pentestgpt.ai/login a scam?

pentestgpt.ai/login shows warning signs and has a trust score of 55/100, indicating potential risks.

Is pentestgpt.ai/login safe to use?

Caution is advised when using pentestgpt.ai/login due to high-risk redirects and limited contact accountability.

What are the red flags for pentestgpt.ai/login?

Red flags include high-risk redirects to hackerai.co and missing terms and conditions.

What does the trust score of 55/100 mean for pentestgpt.ai/login?

A trust score of 55/100 suggests that pentestgpt.ai/login may not be entirely reliable.

Can I trust pentestgpt.ai/login with my information?

Due to warning signs, it's advisable to be cautious and consider alternative sites.

How can I report issues with pentestgpt.ai/login?

You can report issues by checking for contact information on the site, although it may be limited.

Verdict history

  • — Warning (automated reanalysis)

Technical Details

Registrar: NAMECHEAP INC
Domain Age: 2 years (767 days)
TLS Certificate: Valid · issued by WE1 (DV) · expires in 32 days
Hosting: AS13335 Cloudflare, Inc. (US)
Email authentication: SPF missing · DMARC present