RepoTrace

GitHub-first repository intelligence + public-ready OSINT radar
v2.0 RepoTraceChecking token…
Ready.

RepoTrace Radar

User/org scanner · identity graph

GitHub User / Org Scanner

Scan public repositories for a GitHub user or organization and rank them by risk. This stays RepoTrace-only: repo intelligence, not payload triage.

Product Mode

Multi-repo scanner · Bulk scanning · Saved investigations

Bulk / Multi-Repo Scan

Paste one GitHub repo URL per line. RepoTrace will scan them concurrently and show cross-repo links.

Saved Investigations

Save the currently analyzed repo and reload your investigation index later.

Watch Mode

baseline · delta · alerts

Advanced Watch Mode

Create a baseline snapshot, then run again later to detect new commits, new/deleted files, new domains/IPs, and risk changes. Optional email alert fires only when changes are found.

My Watchlist

Log in to view and manage your watched users/orgs.

Account & Billing

Login · org token routing · usage limits · payments · admin

Enterprise / Org Login

optional · server-side org token routing

Enterprise users can register/login with an organization email. If RepoTrace has a server-side token configured for that email domain, logged-in scans use that org token instead of the public RepoTrace token. Users do not need to paste GitHub secrets into the browser.

Login

Forgot password?

Create Account

Not logged in. Public RepoTrace token will be used.

Public Launch Controls

usage limits · verified payments · search counter · admin stats
Loading usage status…
Payment/UPI placeholder loads from .env.

Admin Panel

Protected by HTTP Basic auth. Supports ADMIN_USERNAME/PASSWORD plus optional TEST_ADMIN_* or ADMIN_USERS_JSON in .env.

Pay for Extra Search

Generating QR…

Report suspicious repository

RepoTrace prepares a GitHub-ready owner/user report template. GitHub does not provide a public API to submit abuse reports automatically, so submit the generated template manually through GitHub's official report flow.
Reports are enabled only when VirusTotal marks at least one file in the current scan as malicious. Evidence is limited to malicious file name/path and VirusTotal report link.