# Phishing-Database/Phishing.Database

Phishing Domains, urls websites and threats database. We use the PyFunceble testing tool to validate the status of all known Phishing domains and provide stats to reveal how many unique domains used for Phishing are still active.

Repository: https://github.com/Phishing-Database/Phishing.Database
Canonical: https://ross.abutalabs.com/products/phishingdatabase
License: MIT
License Family: permissive
Topics: phishing, phishing-sites, phishing-reports, phishing-servers, domains, validity, stats, statistics, malware, malware-research, phishing-attacks, phishing-domains
Last push: 2026-08-23T07:30:38+00:00

## Health v2 (maintenance only)
Score: 77/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 99, release rhythm 35, longevity 100
- inputs: {"age_days": 3057, "days_push": 10, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1602, forks 53 (observed 2026-08-28T04:05:09.778969+00:00)

## What it is
A continuously updated open-source database of phishing domains, URLs, and threats, validated with the PyFunceble testing tool and published with activity statistics. It provides downloadable lists of hundreds of thousands of phishing domains and links for community threat intelligence.

## Use cases
- block phishing domains in a DNS firewall
- feed phishing URLs into a SIEM or threat intelligence platform
- check whether a domain is a known phishing site
- research trends in active phishing campaigns
- build a browser extension that warns users of phishing links
- enrich email filtering with known phishing domains

## When to choose
- you need a free, regularly refreshed phishing blocklist
- you want open-source threat data without licensing fees
- you need raw domain and URL lists for security research or filtering

## When to avoid
- you need curated, vendor-supported threat intelligence with SLAs
- you need real-time zero-day phishing detection rather than known-domain lists
- you need per-URL reputation scoring rather than raw lists

## Facets
- artifact type: dataset
- maturity: active
- function: security, monitoring, search-engine
- domain: security, osint, privacy
- platform: cross-platform
- tags: phishing, blocklist, threat-intelligence, malware-research, domain-validation, open-data, security-feed, web-server

## Member repositories
- Phishing-Database/Phishing.Database (main) score 77

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:05:09.778969+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T03:52:34.515078+00:00, confidence not recorded.
  - readme: https://github.com/Phishing-Database/Phishing.Database (fetched 2026-08-28T04:05:09.778969+00:00, sha 81521178b5de)
- Data as of 2026-08-30T08:39:29.467469+00:00.
