Criticalscore 77 · flagged Saturday, September 26, 2026

jp-chatgpt-app-test.blog

Appeared in the .blog zone on Saturday, September 26, 2026; by the end of that day the census found active website about blogs & personal. Full domain report

Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.

Own one of these names and think the listing is wrong? Tell us and a person will look.

What matched

brand in the name
matched: chatgpt
+30
many hyphens
matched: 3
+6
brand name at a retail registrar
matched: Automattic Inc.
+8
brand name and brand-styled page
matched: chatgpt
+15
form on a brand-styled page
matched: has_form
+18
Registrar
Automattic Inc.
Nameserver provider
Nameservers
ns1.wordpress.com, ns2.wordpress.com
First-day state
active website
HTTP status
200
Page title
Site – Powered by ChatGPT
Has a form
yes
Brand echoed
chatgpt

Model opinions

Second opinionlooks like abusetarget: OpenAI (ChatGPT)confidence 55%· claude-opus-5-5

The name is built on the distinctive 'chatgpt' product name, which the site does not belong to. The page itself is only an empty default WordPress Twenty Twenty-Five install whose only forms are a search box and a comment box, so there is no credential or payment capture and it is a brand-squat rather than phishing. The 'app-test' wording and 'Powered by ChatGPT' tagline could be a harmless hobbyist test blog, which keeps confidence moderate.

First passsuspiciousconfidence 72%· claude-haiku-4-5

The domain contains 'chatgpt' with multiple hyphens and hosts a form, triggering phishing indicators. However, the page is a generic WordPress template with 'Powered by ChatGPT' footer text (likely a plugin attribution), a 404 error message, and standard blog infrastructure—no actual impersonation of OpenAI's login, branding, or service. The form appears to be a standard WordPress comment form, not a credential-capture page. This could be a hastily set up phishing infrastructure awaiting content

A model looked at the screenshot and page text and wrote what it thought. It can be wrong, and it is not a finding.

What the page looked like on Saturday, September 26, 2026

Screenshot of jp-chatgpt-app-test.blog taken by the zone census on 2026-09-26

Same data as JSON: /api/zone/domain/jp-chatgpt-app-test.blog. This page is not indexed by search engines and does not link to the site it describes.