Trusted but Verify
We found mixed reputation evidence. Supporting points include security-provider warnings and content related to software products and downloads, but third-party reputation remains weak.
Trust signal radarNormalized trust signals for worktop.devDomain Maturity: 221 daysDomain MaturityWarning Cleanliness: 7 detectionsWarningCleanlinessSafety Level: 1 negative tag, 1 warning signalSafetyLevelPositive Signals: 1 positive signalsPositiveSignalsPopularity: Estimated low traffic without Tranco or social profile dataPopularityTrust Zone: .devTrust ZoneOperational Signals: 1 detected servicesOperationalSignalsLocation Credibility: Hosting country USLocation Credibility
Figure 1. Trust signal radar for worktop.dev. Larger shaded area indicates stronger trust signals.
How we scored worktop.dev
On-page mentions:
Microsoft Software
Tech signals:
Cloudflare Browser Insights, Astro Framework
Positive signals:
a long-term domain history
an active SSL certificate (3 months)
Negative signals:
security-provider warnings
a relatively new domain (7 months)
Context signals:
content related to software products and downloads
Last checked September 3, 2026 at 5:40 PM by
Gridinsoft Trust Model v2.5.3
Share this report?
Independent Gridinsoft analysis
What Gridinsoft observed on Worktop.dev
A Gridinsoft threat analyst reviewed the site directly and documented the evidence behind this decision.
Current review
Review ID
GMA-20260903174001-657d8997
Reviewed
by Gridinsoft Threat Analyst
Analyst finding
Safe
Evidence basis
First-party site analysisExternal vendor intelligence: Contradictory context โ not used for this decision
The independent first-party review did not reproduce phishing, malware delivery, an unrelated redirect, or another malicious behavior in the reviewed current worktop.dev web and software-distribution scope. The exact reported legacy paths were blocked, and no current malicious URL, file, payload, or hash was identified. Retained external warnings were domain-level blacklist categories and were not used to determine this verdict.
Analyst findings
Info4
Info01
No current phishing flow was reproduced
The reviewed public site consisted of consistent product, documentation, support, and legal content. It did not present a credential-collection form, impersonated login, unrelated redirect, or automatic download in the enumerated public pages.
Info02
Reviewed download and update flows were versioned and internally consistent
The official download and update paths led to versioned artifacts. The installer contained an Authenticode certificate chain naming Comunit AB, and the update archive matched the SHA-256 value published by the site's update endpoint. Static inspection found components consistent with the documented desktop utility rather than an unrelated web payload.
Info03
Reported legacy paths were blocked and served no payload
The three exact paths associated with the historical claim returned HTTP 403 across the tested protocol and host variants. No current command response, redirect destination, file, or other malicious object was observed at those locations.
Info04
Historical domain state does not identify a current malicious object
Archived root-domain records demonstrate that the domain's public content changed over time, but the reviewed archive did not reproduce the reported legacy gateway paths or establish a prior malware payload. Historical context and domain-level blacklist labels are not substitutes for an exact current malicious URL or sample.
Review 6 documented observations
View evidence
01Navigation
The sitemap exposed 26 public pages. Every page returned HTTP 200 at its expected worktop.dev URL. The reviewed pages described a Windows desktop-management utility and its documentation, guides, support, privacy, terms, download, and uninstall flows. No form, password field, file-upload field, iframe, unrelated final redirect, or automatic download was present. Four desktop and mobile user-agent checks returned identical homepage content.
HTTP status200
Final URLhttps://worktop.dev/
Page elementThe public sitemap listed 26 same-site pages covering the product, documentation, guides, support, legal information, downloads, and uninstall instructions.
Analyst observationNo credential-collection form, password input, file-upload input, iframe, unrelated final redirect, or automatic download was observed across the sitemap-listed pages.
02Download
The public download page offered WorkTop 1.4.0 for Windows. The same-site download handler redirected to a versioned installer on artifacts.worktop.dev. The retrieved x64 package was a 10,875,256-byte NSIS Windows installer with SHA-256 24a217e4e5b663777ade4e21fc94bd0a2605ba484fb8ca682732529062bbf179. Its embedded Authenticode certificate data named Comunit AB, and its extracted components were consistent with the documented WorkTop desktop utility.
HTTP status200
Public artifact URLhttps://artifacts.worktop.dev/releases/1.4.0/worktop-1.4.0-x64-setup.exe
Certificate factThe installer contained an Authenticode PKCS#7 certificate chain whose leaf certificate subject organization and common name were Comunit AB.
Analyst observationStatic package inspection identified an NSIS installer containing the WorkTop application, installation helper, shell-extension library, uninstaller, and third-party license text; it did not expose a phishing page or an unrelated payload URL.
03Download
The public update endpoint returned structured metadata for WorkTop 1.4.0 and a versioned update archive on artifacts.worktop.dev. The SHA-256 published by the endpoint exactly matched the downloaded archive, which contained the same named application components as the installer package.
HTTP status200
Public artifact URLhttps://artifacts.worktop.dev/releases/1.4.0/worktop-1.4.0-x64-update.zip
Analyst observationThe endpoint-declared SHA-256 matched the downloaded 12,899,117-byte ZIP archive.
04HTTP response
The three specifically reported legacy paths /c5n9/, /7bay/, and /5fqe/ returned HTTP 403 in all twelve tested combinations of HTTP or HTTPS and the root or www host. No content, redirect destination, command response, or payload was served from those paths during the review.
HTTP status403
Analyst observationAll twelve protocol, host, and path combinations for /c5n9/, /7bay/, and /5fqe/ were blocked with HTTP 403 without a redirect.
Analyst observationNo current malicious response or payload was reproduced at the reported legacy paths.
05Historical content
The public archive index contained a December 2021 root-domain capture that rendered a generic parked-domain page, a November 2023 root capture recorded as HTTP 404, and April 2026 captures of the current WorkTop product site. The current RDAP record gave a registration event on January 25, 2026. No archived capture of the three specifically reported legacy paths was found. This supports a material change in domain content but does not independently establish that malware was previously operated on the domain.
HTTP status200
Page elementThe December 2021 archived root page was a generic domain-parking page.
Analyst observationThe archive index recorded the root as HTTP 404 in November 2023 and the current WorkTop product site in April 2026.
DNS factThe current RDAP record reported a registration event at 2026-01-25T20:57:14.051Z.
Analyst observationNo archived capture was returned for /c5n9/, /7bay/, or /5fqe/; the historical review therefore did not confirm a prior live malware gateway or payload.
06TLS
The root and www hosts served the same product site over HTTPS. Current DNS placed the root, www, and artifact hosts behind Cloudflare, while the checkout link used a Lemon Squeezy storefront on store.worktop.dev. Certificate Transparency showed the current root, wildcard, artifact, and store certificate history beginning after the January 2026 registration event.
Certificate factThe live certificate covered worktop.dev and *.worktop.dev and was valid during the recorded review.
DNS factThe root, www, and artifacts hosts resolved through Cloudflare during the review.
Final URLhttps://worktop.dev/
Scope and limitations
The Windows binaries were reviewed statically and were not executed in this investigation.
The result applies to the public pages, download and update flows, exact artifact hashes, and reported legacy paths observed at the recorded time; it does not certify future content or different file versions.
Public archive evidence confirmed changes in domain content but did not independently confirm the claimed historical malware gateway or any historical payload.
This domain was registered January 24, 2026 at 10:00 PM through the company ENOM, INC.
and ownership information is not publicly available.
Complaint contact not found.
About worktop.dev
We reviewed worktop.dev and found mostly positive signals. Current checks lean toward a legitimate, lower-risk profile, although a few caution points still keep it short of a fully verified standing. The current trust score is 66/100. Key signals include security-provider warnings and content related to software products and downloads. We also saw reputation caution signals from third-party review sources, so commercial claims should still be checked independently. Verify key details and recent independent feedback before relying on this site for important actions.
FAQ
Is worktop.dev safe?
Based on current analysis, worktop.dev appears to be generally safe. The final verdict also reflects manual expert review. Basic verification is still reasonable before relying on the site.
Why does worktop.dev look trustworthy?
Key factors include registrar information (ENOM, INC.), hosting in US, and a relatively new domain (7 months). The trust score blends security detections, domain and infrastructure signals, and on-page behavior patterns. The overall assessment remains mixed because third-party reputation sources do not point to a fully consistent trust profile.
Worktop Digital Footprints
A structured view of the site's detected themes, page signals, and related online footprint elements.
Microsoft Software
Cloudflare Browser Insights
This website is proxied through Cloudflare's CDN/network and has Cloudflare Browser Insights enabled.
Astro Framework
Long Term Domain
This site is registered for an extended period, which is generally a positive continuity signal.
Young Domain
worktop.dev was registered recently, which limits historical reputation data and long-term trust signals.
Low Scamadviser Score
Independent security assessment from Scamadviser indicates this site has received a low trust rating, suggesting potential security risks or operational concerns requiring user caution.
External provider warnings: 7/28
This section shows what independent external security sources say about this site.
A warning appears when one or more sources report malware, phishing, abuse, or other safety concerns. Each row shows the source and its verdict.
If no source reports a warning, the site is shown as clear in this section.
alphaMountain.ai
Phishing
Chong Lua Dao
Malicious
Forcepoint ThreatSeeker
Malicious
Lionic
Malicious
Sophos
Phishing
VIPRE
Malware
Scamadviser
Warned
External provider results for Worktop.dev, last checked September 3, 2026.
โ VirusTotal
Domain Information
CreatedJanuary 24, 2026 at 10:00 PMExpires: January 24, 2029 at 10:00 PM
Domain Age7 monthsRecently Registered
RegistrarENOM, INC.
Top Level Domain.devGeneric TLD
Technical Details
IP Address104.21.48.9
Hosting ProviderAS13335 Cloudflare, Inc.San Francisco, California, US
SSL CertificateWE1QUIC ยท Valid for: 3 months ยท from July 28, 2026 at 8:24 AM ยท to October 26, 2026 at 9:22 AM
Name Serversns1.dreamhost.com ns2.dreamhost.com ns3.dreamhost.com
Content Analysis
Website titleWorkTop - Multiple Real Desktops for Windows
Website descriptionWorkTop gives you multiple Windows desktops, each with its own files and icon layout. Switch contexts instantly.
Verified ServicesThis domain has been verified by the following legitimate services and organizations, confirming authentic ownership and proper email security configuration.
Google Verification
Domain ownership verified by Google.
Are You the Owner?
If you own Worktop.dev and want to challenge the trust score, please submit a review request via portal.gridinsoft.com. There you can claim your profile and add verified company/contact details. If you cannot access the portal, email legal(at)gridinsoft.com with proof of legitimacy and contact details. We never charge website owners for reviews or reconsideration requests. For more information, please review our Disclaimer.
Leave a review
66
points /100
The score is based on a 1-100 scale, with 100 being the most reputable.
A website report warns you. A PC scan protects you.
Unsafe sites can leave adware, unwanted apps, or hidden malware in downloads and browser settings. Run Gridinsoft Anti-Malware to check what may already be on this Windows PC.
Checks active threats, startup items, and suspicious downloads
Finds adware and unwanted apps linked to unsafe websites
Shows scan results before you decide what to remove
Your comment is currently undergoing moderation and will be published shortly.
Help protect others by sharing this page on social media! The more people who know about worktop.dev, the fewer chances they have to deceive someone else.Help others evaluate worktop.dev by sharing this page on social media!
Help protect others by sharing this page on social media! The more people who know about worktop.dev, the fewer chances they have to deceive someone else. Help others evaluate worktop.dev by sharing this page on social media!