Security Review

Is ghost.io legit or a scam?

Our verdict:Safe· 78/100

Legitimate publishing platform by Ghost Foundation (UK non-profit, 2013) with 100M+ installs and $10.8M ARR; clean security scan but low Trustpilot rating reflects customer service complaints, not fraud.

ghost.ioScanned 1h ago
0
Trust score
SAFE
Heuristics 75·MT 80
View density

Analysis Summary

Threat Intelligence
0/92
All engines report clean
Domain Age
Registration date unknown
MT Intelligence
Safe
Low likelihood · 92% confidence
SAFE

No threats detected

All checks passed. This site appears legitimate — but always stay alert for phishing even on trusted domains.

Website Preview

Screenshot of ghost.io
LIVE RENDER
ghost.io

Automated page render — captured in a safe sandbox. What an ordinary visitor would see when loading the site.

MT Intelligence

Advanced threat intelligence
MT Security Analyst
Low scam likelihoodengineMT · Guardiantrust80/100
MT AgentLive web researchVisual inspection
0%
Confidence
Ghost.io is the official managed-hosting domain for Ghost, a well-established open-source publishing platform operated by Ghost Foundation, a UK-registered non-profit (company 08540663) founded in 2013. Our antivirus network and browser blocklists show no malicious flags, and the domain ranks in the global top-100k by traffic. The push-notification spam detection reflects the open nature of the platform — individual user-created subdomains on *.ghost.io can be abused for spam, but the core operator does not distribute malware or engage in credential harvesting. Business registration confirms the foundation is active and self-funded via Ghost(Pro) hosting with transparent financials ($10.8M ARR, 100M+ installs). an independent review aggregator ratings are low (2.7/5 from 6 reviews) and spam.org records 102 complaints, but these centre on customer service delays, billing disputes, and newsletter spam signups by individual users — not outright fraud by the operator. Positive reviews from independent publishers and the foundation's public financials support legitimacy.
Full dossier
Analysis complete

Page Content

The page accurately describes Ghost as an open-source publishing platform with email newsletters and paid subscriptions. Title and meta description match the legitimate service offering. No phishing forms, countdown timers, or credential-harvest patterns detected. The page requests browser push-notification permission, a common vector for malvertising on open platforms, but not indicative of fraud by the operator.

Infrastructure

Hosting IP 151.101.131.7 has an abuse score of 0/100 with only 1 historical abuse report. SSL certificate is valid (Let's Encrypt, 40 days to expiry). The domain redirects cross-domain but shows no homoglyph or IDN abuse. External domains loaded include legitimate Ghost subdomains (ghost.org, docs.ghost.io, account.ghost.io) and analytics partners (Ahrefs, FirstPromoter).

Domain History

WHOIS data is unavailable, but business registration confirms Ghost Foundation is a UK-registered non-profit (company 08540663) established in 2013. The foundation operates transparently with published financials, a remote international team, and 100M+ reported installs. No evidence of recent registration, domain hijacking, or operator change.

Web Reputation

Antivirus engines: 0/92 flagged as malicious. Browser blocklists: clean. an independent review aggregator shows 2.7/5 rating from 6 reviews; spam.org records 102 complaints, primarily for unsolicited newsletter signups and customer service issues rather than fraud. Positive reviews from independent publishers and the foundation's transparent operations support legitimacy. No evidence of brand impersonation, malware distribution, or exit-scam activity.

Risk Factors
4
  • Push-notification spam detection flag — common on open platforms where user-created subdomains can be abused for spam campaigns.
  • 102 complaints recorded on spam.org, mostly for unsolicited emails and newsletter signups by individual users rather than operator fraud.
  • Low an independent review aggregator rating (2.7/5) reflects customer service and billing complaints, not security or fraud concerns.
  • No direct contact email, phone, or postal address on the homepage — typical for a SaaS platform directing users to help centre and account portal.
Positive Signals
5
  • Antivirus network: 0/92 engines flagged as malicious; browser blocklists clean.
  • UK-registered non-profit foundation (Ghost Foundation, company 08540663) established in 2013 with transparent financials ($10.8M ARR, 100M+ installs).
  • Valid SSL certificate and top-100k global traffic ranking.
  • Positive independent reviews praising Ghost as a legitimate professional publishing tool used by established publishers (Platformer, 404Media, Lever News, Tangle, The Browser).
  • No evidence of malware distribution, credential harvesting, brand impersonation, or exit-scam activity.
AI Recommendation
Ghost.io is a legitimate publishing platform safe to use for creating blogs, newsletters, and membership sites. If you encounter spam or phishing from a ghost.io subdomain (e.g. startledgeer.ghost.io), report it to Ghost's abuse team — individual users can misuse the platform, but the core operator is trustworthy.
Next-gen fraud intelligence
Evidence-backedCross-checked

Web Research Findings

Our live research agent queries scam-report databases, consumer-review sites, news coverage, and general web search for ghost.io, then cross-checks business-registration records and look-alike domain patterns. Everything below is pulled from what it actually found.

Business registration
Active · UK
Site traces back to an actively registered business.
Clone check
Not a clone
No well-known site's layout or branding detected here.
Typosquat check
No look-alike match
The domain doesn't resemble any well-known brand's spelling.
Web mentions
2 scam reports · 102 complaints · 2 positive
Key findings
7 headline facts from open-web research
  • ghost.io is the official managed hosting domain (Ghost(Pro)) for the open source Ghost blogging/newsletter platform operated by the Ghost Foundation, a UK-registered non-profit (company 08540663) founded in 2013.
  • The foundation is self-funded with ~$10.8M ARR from hosting, publishes transparent financials, has a remote international team, and reports 100M+ installs and significant publisher revenue.
  • Trustpilot shows low rating (2.7/5 from 6 reviews for ghost.io; similar for ghost.org), primarily reflecting customer service or billing complaints rather than outright fraud.
  • spam.org records 102 complaints against the domain, mostly for unsolicited emails ('Not Subscribed'); one specific registrar complaint was auto-resolved; Ghost maintains a strict anti-spam policy and terminates violating accounts.
  • Common user issues include spam signups to newsletters (hurting sender reputation), pricing concerns for larger sites, and technical limitations, but numerous positive reviews praise it as a legitimate professional publishing tool used by e
  • Subdomains on *.ghost.io are sometimes abused for phishing or spam by individual users (e.g. startledgeer.ghost.io flagged), consistent with the 'Push-Notification Spam' detection and open platform nature.
  • No evidence of malware distribution, brand impersonation, or exit-scam activity by the core operator; page title and description accurately reflect the legitimate service.
Scam reports (2)
Direct quotes from public scam databases, forums, and news.
  • spam.orgopen

    "We have received 102 complaints about this domain. ... Report Reason: Not Subscribed"

  • Trustpilotopen

    "ghost.io 2.7 Poor TrustScore 2.5 out of 5 6 reviews"

Positive reviews (2)
Quotes indicating the site is legitimate.
  • ghost.org/aboutopen

    "Ghost Foundation is a non-profit organisation ... self-sufficient, and is able to employ a wonderful team. ... 100M+ installs, $10.77M ARR"

  • norberthires.blogopen

    "I am happy that one year ago I decided to try Ghost. ... I am confident that Ghost as a platform is on a good track"

Business registration
Status: active · UK

Ghost Foundation, company number 08540663 (Companies House), registered as non-profit organisation / company limited by guarantee; remote team, self-funded via Ghost(Pro) hosting

Research summary
Narrative write-up from our AI analyst, grounded on the facts above

Spam.org records 102 complaints against ghost.io, mostly for unsolicited newsletter signups and 'Not Subscribed' issues — typical of an open platform where individual users can abuse subdomains for spam. an independent review aggregator shows a low rating (2.7/5 from 6 reviews), but complaints focus on customer service delays and billing concerns rather than fraud or security breaches. Independent reviews and the Ghost Foundation's public business registration (UK non-profit, company 08540663, established 2013, $10.8M ARR, 100M+ installs) confirm the platform is legitimate and widely used by professional publishers including Platformer, 404Media, Lever News, Tangle, and The Browser. No evidence of malware, credential harvesting, or exit-scam activity by the core operator.

Antivirus Engines

Clean pass · verified
Clean across 92 engines

We cross-check every URL against our antivirus network of 92 malware and blacklist engines. None of them flagged this URL in the last scan.

0Malicious0Suspicious62Harmless92Engines
Clean
Kaspersky
Clean
Bitdefender
Clean
Microsoft
Not in pass
ESET-NOD32
Not in pass
Avira
Not in pass
Sophos
Clean
Fortinet
Clean
Google Safebrowsing
Clean
Emsisoft
Clean

No engine detections. The URL passed every antivirus and blacklist engine we queried in this scan. Stay vigilant — AV coverage is only one signal among many.

Security Scans

Blacklist Check
Not flagged on major threat lists

Checked against the major public blocklists used by browsers and security tools — no hits.

Contact Verification

We fetched the page and looked for real-world contact details. Legitimate businesses almost always publish an email on their own domain, a phone number, and a postal address. Scam shops usually don't.

What We Found
No clear contact details on the page
Emails on site's domainNone
Phone numbersNone
Postal addressNot listed
Linked social profiles2
Signal Summary
Several contact red flags
  • No contact email found anywhere on the page.
  • No phone number listed on the page.
  • No postal address visible on the page.
  • Page requests browser push-notification permission — common malvertising vector.
  • Scam family match: Push-Notification Spam.
  • Links to 2 social profiles.

Domain & Encryption

Encryption Certificate
StatusValid
ProtocolTLSv1.3
IssuerLet's Encrypt · R13
ExpiresJul 20, 2026 (40d)
Self-signedNo
Hosting & Technology
HostingFastly, Inc.
Server locationUS
Web serverNetlify
Platform / CMSHugo 0.119.0
PopularityTop 100k worldwide

Redirect Chain

Hops
1
Cross-domain
Yes
Lookalike
No
Punycode
No
  • 1308http://ghost.io/
  • 2200https://ghost.org/cross-domain

Server Reputation

Abuse Intelligence
Confidence score0%
Reports on file1
ISPFastly, Inc.
Usage typeContent Delivery Network

Still, stay alert

No major threat indicators — but a clean scan does not guarantee every page is safe, and phishing emails routinely spoof real domains.

  • Double-check the exact URL in your address bar

    Confirm you are actually on ghost.io and not a lookalike like g-host.io.com or an IDN homoglyph.

  • Use a password manager

    Password managers only auto-fill on the exact domain they were saved for — they refuse to fill lookalike domains, which is the single best phishing defence.

  • Discuss this site on the forum

    If you have first-hand experience with this site — good or bad — share it with the MalwareTips community.

    Open

Reputation Sources

How this domain rates across independent threat-intelligence and blocklist providers.

Google Safe Browsing
Not listedCheck ↗
VirusTotal
Not listedCheck ↗
AbuseIPDB
Not listedCheck ↗

Referenced Domains

Outbound domains this page links to or loads resources from. Each links to its own security scan.

Safety FAQ

Common questions about this site, answered directly from the scan data above — so the answers always reflect the latest verdict on this page.

  • Our automated security review found no threat indicators on ghost.io. The site appears legitimate based on the signals we checked, but always stay alert for phishing emails that spoof real domains.
  • ghost.io passed our automated security checks with a trust score of 78/100. No antivirus engines or major blacklists flagged the site at the time of the last scan.
  • Yes. ghost.io presents a valid TLSv1.3 certificate issued by Let's Encrypt · R13, expiring in 40 days. Note that SSL only encrypts the connection — it does not guarantee that the site itself is trustworthy.
  • No. All 92 antivirus engines in our malware network report ghost.io as clean.
  • No. ghost.io is not currently listed on the major browser blocklist feeds that modern browsers use.
  • ghost.io resolves to an IP operated by Fastly, Inc. in US (usage type: Content Delivery Network). Hosting location alone doesn't make a site good or bad, but unusual geography for a brand's claimed country is one of many signals we weigh.
  • Yes. ghost.io sits in the global top-100k on Cloudflare Radar, which means it has substantial real-world traffic. That does not automatically make it safe, but established brands almost always rank here and throwaway scam domains almost never do.
  • This is a permanent record of the scan run on June 10, 2026. The verdict and evidence above reflect that scan and do not change on their own. If circumstances around ghost.io have changed, MalwareTips staff can run a fresh scan, which re-runs every check from scratch and publishes an updated report.

Final Verdict

0
Trust / 100
Final Verdict·ghost.io
SAFE

Ghost.io is the official managed hosting platform for Ghost, a legitimate open-source publishing and newsletter tool operated by a UK-registered non-profit foundation since 2013. The domain is clean across antivirus and browser blocklists, though it triggers a push-notification spam detection flag common to open platforms where user-created subdomains can be abused.

Ghost.io is a legitimate publishing platform safe to use for creating blogs, newsletters, and membership sites. If you encounter spam or phishing from a ghost.io subdomain (e.g. startledgeer.ghost.io), report it to Ghost's abuse team — individual users can misuse the platform, but the core operator is trustworthy.

AV engines
92
MT passes
2
Net signals
0
Scan another URL
Security review completemalwaretips.com/url-scan
Recently scanned

Other Safe reports

Browse all reports
Community review

User reviews & comments(0)

Share your experience — "Lost $200 on a fake checkout" is more useful than "Scam". Your review helps others avoid traps.

Loading…
Loading comments…
This report is generated automatically by combining threat intelligence, domain signals, and an AI security analyst. It is informational, not legal advice. Always use your own judgement before sharing personal information or money online.