Domain Due Diligence
Report for Immich.app
Why we think so
Immich.app is a self-hosted photo and video management platform with a strong focus on user privacy and open-source development. It handles around 620,000 monthly visits, mostly from the US, Germany, and China. The website uses recognized technologies such as Cloudflare CDN and HTTPS for security. Reviews praise its fast performance, AI features like face recognition, and privacy controls, but note challenges with mobile app reliability for large backups and some restoration bugs. There are no credible scam reports or lawsuits identified. Despite some rapid development issues, Immich.app is generally seen as a trustworthy service suitable for users comfortable with self-hosting.
Risk Insights
Strong User Engagement
Clean Security Record
Trusted Brand With Trademark
Contradictory Signals
Google flagged some test or preview URLs as dangerous due to misclassification, but main domain is clean and issue resolved.
Signal A: No scam reports or phishing blacklists
Signal B: Past Google Safe Browsing flags on preview sites
Category Scores
Red Flags & Warnings
-
Google Safe Browsing previously flagged some Immich preview sites likely due to mistaken phishing detection, though resolved on main domains.
-
Some user reports describe bugs with mobile app backups and photo restoration issues for large libraries impacting reliability.
๐ Detailed Checks & Analysis
Traffic and Engagement Check
Traffic and Engagement Check
"Monthly visits around 620K with leading traffic from US, Germany, and China confirm genuine usage."
Reason: Site shows healthy, consistent monthly visits with a good mix of direct and search traffic.
Technical Security Check
Technical Security Check
"Infrastructure employs recognized tech such as Cloudflare and standard security protocols."
Reason: Uses Cloudflare CDN, HTTPS, and has a valid SSL certificate not expiring soon.
Blacklist and Phishing Check
Blacklist and Phishing Check
"Google Safe Browsing and crypto scam scanners report no risk."
Reason: Domain is not on any current phishing or scam blacklists.
Reputation and Community Feedback
Reputation and Community Feedback
"Feedback includes praise for AI features but warns about mobile app backup and restoration issues."
Reason: No credible scam reports; positive reviews emphasize privacy and open-source benefits though noting some bugs.
Legal and Trademark Standing
Legal and Trademark Standing
"No active litigation identified; licensing and trademark status stable."
Reason: No lawsuits reported; trademark 'IMMICH' registered by a legal entity.
Contact and Ownership Transparency
Contact and Ownership Transparency
"Direct communication channels and developer presence support legitimacy."
Reason: Contact email, GitHub repository, and social media links publicly available.
Your Next Steps
-
1Use the official Immich app and website links to avoid unofficial or phishing versions.
-
2Keep the app updated to benefit from patched vulnerabilities, especially OAuth2 fixes.
-
3For self-hosting, follow recommended security best practices like deploying reverse proxies.
-
4Monitor community forums and GitHub issues for ongoing developments or reported concerns.
Evidence & Citations
-
Immich.app Review Summary and User Feedback
Contains detailed user reviews and performance feedback highlighting strengths and known issues.
-
Security Vulnerability (CVE-2025-43856) Details
Describes a patched OAuth2 security vulnerability affecting immich.app.
-
Trademark Registration for IMMICH
Shows live trademark registration owned by FUTO Holdings Inc.
-
Google Safe Browsing and Blacklist Status
No current blacklisting or phishing flags for immich.app domain.
๐ต๐ป Keep investigating
Run another instant due diligence scan on any domain. Verify before you subscribe or shop!
Scammers clone legitimate ticket exchanges or invent resale hubs that require wire transfers and Zelle deposits. ScamAI...
Read playbook โWebinars promise secret trading signals but quietly upsell unregistered brokers or payment wallets. ScamAI inspects regi...
Read playbook โ