tor sites github

Tor Sites Listed on GitHub: How to Find and Verify Onion Directories

GitHub hosts public repositories that catalog onion addresses and Tor sites, maintained by security researchers and community contributors. These repositories serve as reference points for finding legitimate Tor services, but they also attract phishing clones and outdated mirrors. Understanding how to spot a genuine GitHub directory and cross-verify onion addresses is essential before you visit any link.

Tor Sites on GitHub: Verified Onion Directories

What GitHub Repositories for Tor Sites Actually Are

GitHub repositories dedicated to Tor sites function as crowdsourced indexes of working onion addresses. They typically list categories such as search engines, forums, marketplaces, libraries and communication services. Most are maintained by individual researchers or small teams who test links periodically and remove dead ones. The repositories are public, versioned and searchable, which makes them useful for people trying to understand the onion ecosystem without relying on a single source.

These repositories are not official Tor Project resources. They exist because the Tor Project itself does not maintain a central directory of onion services. Instead, community members create and update lists based on their own testing and user reports. Some repositories include metadata such as the last-verified date, the service's purpose and whether it requires authentication. This transparency helps you assess whether a link is current or abandoned.

Why People Search for Tor Sites on GitHub

Users turn to GitHub for Tor site lists for several practical reasons. First, GitHub's version control system creates a public audit trail, so you can see when a link was added, modified or removed and by whom. Second, repositories often include descriptions and categorization that search engines alone do not provide. Third, GitHub's interface allows users to report issues, suggest corrections and discuss the accuracy of entries in the comments.

For security researchers and journalists, GitHub repositories serve as a way to document the onion ecosystem without endorsing any particular service. The platform's transparency also means that if a repository becomes inactive or is taken over, the history remains visible. This contrasts with a private list or a dark web forum, where changes are opaque and accountability is minimal.

How to Identify Legitimate GitHub Repositories for Onion Links

Verifying a GitHub repository requires checking several markers before you trust its contents. Start by examining the repository's creation date, commit history and contributor profile. Repositories that have been maintained consistently over months or years, with regular updates and multiple contributors, are more likely to be genuine efforts. A repository with a single commit from a brand-new account is a red flag.

Read the repository's README file carefully. Legitimate repositories explain their purpose, how they verify links and what categories they cover. They often include disclaimers stating that they are informational only and that the maintainer is not responsible for the content of linked services. Check whether the repository has a license (MIT, GPL or similar) and whether the maintainer has other public projects or a verifiable GitHub history.

Look for repositories that cite their sources or link to official Tor Project documentation. Some repositories include PGP fingerprints or links to the maintainer's security profile. If a repository claims to be a mirror or backup of another list, verify that claim by checking the original source. Phishing clones often copy the structure of a legitimate repository but change the onion addresses to point to scam sites.

Common Risks: Phishing Clones and Outdated Mirrors

GitHub repositories for Tor sites are frequently cloned, forked and impersonated. An attacker may create a repository with a nearly identical name (for example, replacing a zero with the letter O) and populate it with phishing links. These fake repositories can rank highly in search results and appear legitimate at first glance. The key difference is that the phishing clone will have no commit history, no community engagement and no clear maintenance schedule.

Outdated mirrors present a different problem. A repository that has not been updated in months or years may contain links to services that have been seized, exit-scammed or replaced by clones. When you visit an old onion address, you may land on a phishing site that was registered after the original service closed. Always check the last commit date and the timestamps of individual link entries. If a repository has not been updated in more than a few months, treat its contents as potentially stale.

Reality Check: How the Ecosystem Actually Works

GitHub repositories for Tor sites operate in a gray zone between transparency and risk. According to Tor Project documentation, onion services are designed to be self-authenticating through their cryptographic addresses, which means no central directory is necessary or recommended. However, this design also means that when an onion address changes or a service moves, users have no official notification mechanism. GitHub repositories fill this gap by allowing community members to document and discuss these changes.

Law enforcement agencies have used GitHub repositories as a source of intelligence about active onion services. This is public information, but it means that maintaining or contributing to a Tor site directory can attract scrutiny. Security vendor incident reports have documented cases where phishing actors registered GitHub accounts specifically to create fake repositories and distribute malware links. The lesson for readers is that GitHub is a useful reference tool, but it is not a substitute for verifying addresses through official channels, PGP-signed announcements or direct communication with service operators.

How to Verify Onion Addresses After Finding Them on GitHub

Once you have found a Tor site link on GitHub, do not visit it immediately. Instead, cross-reference the address with multiple independent sources. Check whether the service has an official website, a PGP-signed announcement or a presence on established forums. Many legitimate onion services publish their addresses on their own clearnet sites or in official documentation.

Use the following verification steps:

  1. Copy the onion address from the GitHub repository.
  2. Search for that address on other Tor site directories and forums to see if it appears consistently.
  3. Check whether the service has published a PGP key or fingerprint that you can use to verify announcements.
  4. Visit the onion site only after you have confirmed it in at least two independent sources.
  5. On your first visit, check the site's security certificate and look for any warnings from your browser or Tor Browser.

If an onion address appears on GitHub but nowhere else, or if it has changed recently, treat it as unverified until you can confirm it through the service's official channels.

Finding Tor Sites for Books and Other Specific Categories

GitHub repositories often organize onion services by category, making it easier to find specific types of sites. Repositories focused on libraries and archives typically list sites dedicated to books, academic papers and historical documents. These are usually the safest category to explore because they are non-commercial and maintained by volunteers. When searching for best tor sites for books, look for repositories that include descriptions of each site's collection, language support and access requirements.

Other common categories include Tor search engines, communication platforms, news sites and security tools. Repositories that cover tor sites reddit discussions or tor sites links often include user reviews and community feedback. This metadata helps you understand whether a site is active, trustworthy and relevant to your needs. Always read the repository's notes on each category to understand what you should expect before visiting.

Taking the Next Step: Building Your Own Verification Workflow

Rather than relying on a single GitHub repository, develop a personal workflow for finding and verifying Tor sites. Start by identifying two or three well-maintained repositories that cover the categories you are interested in. Check their commit history and contributor profiles to ensure they are active. Then, create a simple checklist of verification steps you will follow before visiting any new onion address.

Your workflow might include bookmarking the official Tor Project documentation, subscribing to security mailing lists that announce onion service changes and learning how to verify PGP signatures. These habits will serve you better than memorizing a list of links. When you encounter a new Tor site on GitHub or elsewhere, apply your verification steps consistently. This approach transforms GitHub from a passive reference into part of an active security practice that protects you from phishing and scams.

Frequently asked questions

Are GitHub repositories for Tor sites safe to use?

GitHub repositories are useful reference tools, but they carry risks. Phishing clones and outdated mirrors are common. Always verify onion addresses through multiple independent sources before visiting them. Check the repository's commit history and contributor profile to assess its legitimacy.

How do I know if a GitHub repository for Tor sites is fake?

Fake repositories typically have no commit history, a brand-new account, no community engagement and no clear maintenance schedule. Compare the repository name carefully with the original to spot subtle misspellings. Legitimate repositories include disclaimers, cite sources and have consistent updates over months or years.

Can I trust onion addresses listed on GitHub?

Not without verification. Onion addresses on GitHub should be treated as starting points for research, not as confirmed working links. Cross-reference addresses with official service announcements, PGP-signed statements or other independent directories before visiting them.

What should I do if an onion address on GitHub is no longer working?

A dead link usually means the service has closed, moved or been seized. Do not assume a new address is legitimate without verification. Check the service's official channels or PGP-signed announcements for updates. Report the dead link to the repository maintainer if the platform allows it.

Where can I find verified Tor site directories besides GitHub?

The Tor Project's official documentation and the Useful Resources page of this site provide curated links. Security-focused forums and mailing lists also discuss verified onion services. Always prioritize official sources and PGP-signed announcements over third-party lists.