Anti-Malware · head-to-head

Google Safe Browsing vs MalShare

Google Safe Browsing

Google Safe Browsing lets clients check URLs against Google's continuously updated lists of malware, phishing, and unwanted-software sites via the v4 threatMatches:find endpoint, the same data that powers warnings in Chrome and Search. A live POST with a syntactically valid but bogus key returned a 400 "API key not valid" error from safebrowsing.googleapis.com, reconfirming API-key auth and HTTPS, and both that call and its OPTIONS preflight echoed the request Origin in Access-Control-Allow-Origin. The API is free for any Google Cloud project under its published quota.

MalShare

MalShare is a community-run, free public malware sample repository: registered users pull hash lists, per-sample metadata, and the raw binaries themselves through a single api.php endpoint, or upload their own finds back to the pool. A live GET against that endpoint with an invalid key returned a plain-text "user specified in api_key GET variable does not exist" error rather than any CORS header, reconfirming API-key auth over HTTPS and reconfirming cors as no. Standard registered keys are free and capped around 2,000 calls a day, a limit MalShare says it will raise on request.

Google Safe BrowsingMalShare
AuthenticationAPI KeyAPI Key
Pricingfreefree
FormatsJSONJSON, Binary
CORSyesno
HTTPSYesYes

Google Safe Browsing supports CORS, while MalShare doesn't — pick Google Safe Browsing for direct browser calls.

More comparisons