What Gridinsoft observed on Typebot.co
A Gridinsoft threat analyst reviewed the site directly and documented the evidence behind this decision.
- Reviewed
- by Gridinsoft Threat Analyst
- Analyst finding
- User-Generated Content Platform โ Object-Specific Review Required
- Evidence basis
- First-party site analysis External vendor intelligence: Context only โ not used for this decision
The official Typebot root and the sampled public objects did not reveal a specific active phishing page, malware payload, automatic download, or malicious hash during this review, and one previously recorded public object now returns HTTP 404. However, typebot.co delegates interactive public pages and client-side presentation to users, while the full set of published identifiers cannot be enumerated. The safety of the entire domain is therefore inconclusive; suspected public objects require exact-URL review, and a clean root does not certify all user-generated content.
Analyst findings
Official service root showed no observed active threat
The reviewed root was a coherent official Typebot service page, and no phishing imitation, malware payload, suspicious automatic download, or unrelated redirect was identified there.
Active user-controlled public namespace
Different public identifiers served independently published interactive content capable of collecting visitor input and using publisher-configured client-side presentation. A clean operator root therefore does not establish the safety of all public objects.
Abuse reporting and publication controls are present
The service provides an abuse-reporting route and source-visible publication risk, suspension, and removal controls. The previously recorded object tested during this review was unavailable.
Object-specific evidence is required
The public identifier namespace could not be enumerated sufficiently. The review found no active malicious payload in the sampled scope, but it cannot certify every existing or future user-created object and cannot independently verify remediation for unspecified URLs.
Review 6 documented observations View evidence
The root domain returned the official Typebot landing page for an open-source conversational-form and chatbot service. No phishing imitation, automatic download, or unrelated redirect was observed on the reviewed root page.
-
HTTP status
200 -
Final URL
https://typebot.co/ -
Page element
The page title was Welcome to Typebot and its product links led to the Typebot application. -
Analyst observation
No specific malware file, payload, credential-harvesting imitation, automatic download, or malicious hash was identified on the reviewed root page.
The domain operates an active user-controlled public-page namespace in which a path can resolve to a published conversational form rather than an operator page.
-
HTTP status
200 -
Analyst observation
The public paths /login, /dashboard, and /register each resolved to different published conversational content during the review. -
Analyst observation
A randomly generated non-existent public identifier returned HTTP 404, confirming that published identifiers are resolved as individual objects rather than a single static fallback page.
Reviewed public objects could present interactive prompts, accept visitor input, and include publisher-configured presentation and client-side code. These capabilities are legitimate platform functions but are security-relevant when content is user controlled.
-
Page element
The reviewed public bots presented distinct interactive workflows and text-input controls. -
Analyst observation
The reviewed public viewer implementation supports publisher-configured custom head code and client-side scripts. -
Analyst observation
The reviewed active objects were not established as phishing or malware by this observation; the finding concerns the capability and scope of the delegated namespace.
The service exposed a public abuse-reporting workflow, and the reviewed source code contained pre-publication risk checks plus workspace and public-object suspension mechanisms.
-
HTTP status
200 -
Page element
The /report-abuse public bot requested the URL of content that violates the service rules. -
Analyst observation
The reviewed publication flow calls a risk computation before publishing and can block publication at a high risk level or route intermediate results for review. -
Analyst observation
The reviewed source handles suspended workspaces and removed public objects as not found in the public viewer.
A previously publicly recorded user-created path was no longer available at review time and returned HTTP 404.
-
HTTP status
404 -
Final URL
https://typebot.co/funil-tiktok-wh5kmk5 -
Analyst observation
The current 404 response confirms that this specific object is unavailable; it does not establish the status of every other published identifier.
No public inventory of all published identifiers was available, so the material user-controlled namespace could not be enumerated or reviewed to a depth sufficient for a whole-domain safety conclusion.
-
Analyst observation
The root robots resource did not provide a complete inventory of published objects and the reviewed sitemap location returned HTTP 404. -
Analyst observation
Without the exact set of previously reported abusive URLs or an enumerable current object list, remediation can be verified only for individually known paths.
Scope and limitations
- The review covered the root domain, selected public objects, the public abuse-reporting route, public HTTP behavior, and relevant open-source publication and suspension logic.
- No account was created, no credentials or personal data were submitted, and private workspaces, administrative systems, and unpublished objects were not accessed.
- The exact complete list of previously reported abusive public identifiers was not available, so remediation could be verified only for the individually known path tested during this review.
- The user-controlled public namespace could not be enumerated sufficiently for a domain-wide Safe conclusion. Each suspected public object requires exact-URL review.
- The result describes the observed scope at the recorded time and does not predict future user-created content or later changes.
Help protect others by sharing this page on social media! The more people who know about typebot.co, the fewer chances they have to deceive someone else. Help others evaluate typebot.co by sharing this page on social media!