GoGoAnime has been one of the most-searched unofficial anime streaming names for years, but almost nobody watching it today is watching the "original." The name has rebranded across domains and operators repeatedly, following the same DMCA-driven pattern as AniWave and the KissAnime clones I've previously audited on this site. The domain I tested here — gogoanime.by — is the one currently ranking and actively serving traffic at the time of writing.
As with every audit on this site, I didn't just load the homepage and call it a day. I ran DNS and WHOIS analysis, a full TLS test, live network traffic capture across the homepage, schedule page, and multiple episode pages, and — critically — cross-referenced every third-party domain the site loads against VirusTotal's independent security-vendor database. I also ran a controlled, before-and-after measurement of the site's actual CPU impact with and without an ad blocker.
What is GoGoAnime, and which domain am I actually testing?
"GoGoAnime" isn't a single stable site — it's a brand name that's been reused across many domains and, almost certainly, multiple unrelated operators over the years, the same way "KissAnime" now refers to a cluster of unrelated impostor sites rather than one original. For this audit I tested the domain that is currently live and serving the GoGoAnime brand: gogoanime.by.
A WHOIS lookup shows the domain was registered in February 2024 — roughly two and a half years old at the time of this audit — through registrar Reliable Software, Ltd, with nameservers on Cloudflare. Unlike most sites in this space, the registration was not hidden behind WHOIS privacy protection: it resolves to an individual registrant based in Pakistan. That's unusual — operators in this space typically use privacy services specifically to avoid this kind of identification, so its absence here is itself a small data point, though not a safety finding on its own.
My testing methodology
I ran gogoanime.by through the same six categories of analysis I use for every site on this blog, with one addition specific to this audit:
- DNS and infrastructure check — who operates the servers, what CDN and tech stack are in use
- SSL/TLS implementation — quality of encryption on the connection
- Network traffic analysis — every domain contacted across the homepage, schedule page, and multiple episode pages
- Ad network audit, with independent verification — not just cataloguing third-party domains, but running each one through VirusTotal's aggregate of 90+ independent security vendors
- Cookie and tracker audit — persistent identifiers and their naming patterns
- Controlled performance testing — measuring actual CPU impact with and without ad-blocking, and searching all loaded scripts for known cryptomining signatures
Infrastructure — a legitimate-looking WordPress site
gogoanime.by runs on WordPress (theme name "dramastream"), with Yoast SEO, a LiteSpeed web server, and Jetpack's image CDN (wp.com) serving media. That's a fairly ordinary, even professional-looking content stack — not the kind of bare-bones infrastructure you might expect from a piracy-adjacent site.
The SSL/TLS implementation scored a B grade on Qualys SSL Labs' server test, consistent across both the IPv4 and IPv6 endpoints — solid, though not top marks. The site sits behind Cloudflare, which handles DNS, DDoS protection, and TLS termination, the same setup I found on AniWave.
None of this is where the risk is. It's what loads on top of this otherwise unremarkable WordPress site that matters.
The ad network: a rotating pool of malicious domains
This is the centerpiece of this audit. Capturing live network traffic across the homepage, the schedule page, and multiple episode pages, I repeatedly observed scripts and tracking pixels loading from a set of domains with the kind of generic, randomly-assembled names that are a well-known signature of disposable ad-fraud infrastructure: grop.net, spendsdetachment.com, portalfluently.com, flushpersist.com, and workdeadlinededicate.com.
These aren't five unrelated ad networks. Multiple of these domains served the exact same backend request pattern — an identical URL structure (purst?dl=0&th=0&sc=0&rs=...&rd=...&fd=...&bv=2026.7.1&tmpl=70) with a matching build-version signature, just from a different hostname each time. That's a textbook pattern for a single ad-fraud operation rotating through disposable domains specifically to stay ahead of domain-based ad blocklists — when one domain gets blocklisted, traffic simply shifts to the next.
I ran each of these five domains through VirusTotal, which aggregates results from more than 90 independent security vendors:
| Domain | VirusTotal detections | Notes |
|---|---|---|
grop.net | 0 / 91 (clean) | Fronts as "BPGame interactive engagement network"; sets a noindex,nofollow tag to stay out of search results |
spendsdetachment.com | 12 / 91 malicious | Flagged by Fortinet, Sophos, VIPRE, Webroot, and others as malware/malicious |
portalfluently.com | ~5-6 / 91 malicious | Registered only one month before this audit |
flushpersist.com | 5 / 91 malicious | Flagged malicious by CRDF, Webroot, Chong Lua Dao, VIPRE |
workdeadlinededicate.com | 15 / 91 malicious | Highest count of the group; flagged malicious/phishing by ADMINUSLabs, Kaspersky, Sophos, Fortinet, and 11 others |
Four of the five domains feeding this site's ad delivery are currently flagged as malicious or phishing infrastructure by multiple independent security vendors. The one clean result, grop.net, is worth including precisely because of the contrast: it presents itself as a legitimate-sounding "engagement network," while sitting in the same delivery chain and sharing the same request signature as domains that 15 different vendors call outright malicious.
Real-world impact: measuring the cost in CPU
Domain reputation alone doesn't tell you what a site actually costs you to visit. So I measured it directly, using Firefox's per-tab process monitor, comparing the same idle page — nothing being clicked, no video playing — with an ad blocker off versus on.
With no ad blocker running, the GoGoAnime tab climbed from a baseline of under 1% CPU to 48% while sitting completely idle on a normal content page. That's not a brief spike — it was a sustained climb over several readings, on a tab that visibly wasn't doing anything beyond a slow-rotating image carousel.
I ran the same test with uBlock Origin enabled. CPU usage on the same page dropped to roughly 5% — a nearly 90% reduction. I also searched every script loaded on the page for known cryptomining signatures (CoinHive, Cryptonight, WebMiner, CoinIMP, AuthedMine, CryptoLoot) and found no evidence of a dedicated in-browser miner. The CPU cost here isn't a miner — it's the ad/tracking infrastructure itself, and specifically the same domain family flagged as malicious above.
Privacy and cookies
The site sets a cookie named with a pp_main_ prefix — a naming pattern associated with PropellerAds, an ad network with a well-known reputation for aggressive monetization on piracy-adjacent sites (worth noting I can't confirm attribution with full certainty from the cookie name alone). More notably: gogoanime.by has no privacy policy at all. No footer link, no dedicated page — nothing describing what data is collected, how long it's kept, or who it's shared with. That's a meaningfully lower bar than even AniWave, which at least has a (weak) privacy policy to critique.
Playback reliability
The actual video player loads through megaplay.su using JW Player, a legitimate commercial video SDK — not inherently suspicious on its own. What is worth flagging: one episode I attempted to play failed outright with "Failed to load player," and across multiple episode attempts I observed repeated requests to gogoanime.by/player.php carrying an oddly-named Blogger= parameter containing what looks like an obfuscated token — these consistently returned a 403 Forbidden. Whether that's deliberate bot-detection or just a flaky embed rotation, it makes for an unreliable viewing experience even before you account for the ad network.
Risk assessment — separating real threats from hype
Low risk — the site's own code and infrastructure
The underlying WordPress install, TLS implementation, and Cloudflare hosting are unremarkable and don't themselves show signs of compromise. No dedicated cryptominer was found in any loaded script.
Medium risk — privacy and tracking
No privacy policy at all, plus third-party tracking cookies with a naming pattern associated with aggressive ad networks.
High risk — the ad network
Four of five ad-delivery domains identified in live testing are independently flagged as malicious or phishing infrastructure by multiple named security vendors, sharing a common backend signature that indicates a single rotating ad-fraud operation. This measurably taxes your device's CPU even when idle, dropping by roughly 90% with a good ad blocker in place.
How to use GoGoAnime more safely (if you choose to)
Step 1 — Install uBlock Origin, and treat it as non-negotiable
This isn't optional advice here — the CPU test above shows a measured, roughly 90% reduction in load with it enabled. uBlock Origin is free and open-source for Chrome, Firefox, and Edge. Avoid Adblock Plus, which operates an "Acceptable Ads" program that whitelists some advertisers.
Step 2 — Use a VPN
A VPN prevents your ISP from seeing that you're visiting gogoanime.by and adds a layer of protection against IP-based tracking. See our VPN guide for streaming fans for tested recommendations.
Step 3 — Never download anything the site prompts you to
Streaming does not require any software download. Any prompt to install a "player," "codec," or "update" is a social-engineering attempt — close the tab.
Step 4 — Use a separate browser profile
Given the confirmed-malicious ad infrastructure documented here, isolating this kind of browsing from your main profile (banking, email, accounts) is a reasonable precaution, not paranoia.
GoGoAnime versus alternatives
Crunchyroll (Licensed)
Free tier with ads from mainstream, vetted ad networks — a categorically different risk profile than what's documented above. Extensive library covering most mainstream anime.
Netflix (Licensed)
The most secure streaming environment I've tested across this whole series of audits — no third-party trackers, no pop-ups, and a legitimate anime library including exclusives.
AniWave (Unlicensed, previously audited)
Also carries real ad-network risk, but in that audit I wasn't able to get independent, vendor-confirmed detections on the specific ad domains involved — the risk there was circumstantial (behavior observed directly: pop-unders, fake alerts) rather than backed by third-party malware databases the way this GoGoAnime audit is. That makes GoGoAnime's ad-network finding the more concretely documented of the two.
GoGoAnime (Unlicensed)
Large library, free, professional-looking WordPress infrastructure underneath — but the ad-delivery chain is confirmed by multiple independent security vendors to include malicious infrastructure, and that infrastructure has a measurable, non-trivial performance cost on your device even when you do nothing at all.
Frequently asked questions
Will I get a virus from GoGoAnime?
Not from the site's own code, which is a fairly ordinary WordPress install. The real risk is the ad-network infrastructure it loads on every page — five different rotating ad domains were tested, and four of them are independently flagged as malicious or phishing infrastructure by multiple security vendors on VirusTotal. With a good ad blocker running, CPU load tied to those scripts dropped by roughly 90% in testing.
Does GoGoAnime have malware?
A source-code search of every script loaded on the site found no evidence of a dedicated in-browser cryptocurrency miner. The concern is different: the site loads scripts from a rotating pool of disposable ad domains, several of which VirusTotal vendors — including Fortinet, Sophos, Kaspersky, and Webroot — currently flag as malicious or phishing infrastructure.
Is GoGoAnime illegal to use?
In most countries, accessing unlicensed streams as a viewer exists in a legal grey area, and rights holders have historically pursued site operators rather than individual viewers. That doesn't offset the security risk documented in this audit — legality and safety are separate questions.
Why does gogoanime.by keep loading scripts from different random-sounding domains?
This audit caught the same backend request pattern — identical URL parameters, including a matching build-version signature — served from five different domains. Rotating through disposable, randomly-named domains is a known technique ad-fraud networks use specifically to evade domain-based ad blocklists. One of the domains caught in this testing was registered only a month before this audit.
Is GoGoAnime safe for kids?
No. Independent of the content itself, the confirmed-malicious ad infrastructure and complete lack of a privacy policy make it unsuitable for younger or unsupervised users. Use a licensed, moderated platform for children.
Final verdict
GoGoAnime's own infrastructure — the WordPress install, the TLS setup, the Cloudflare hosting — is unremarkable and not itself a red flag. But the ad-delivery chain sitting on top of it is the most concretely documented risk I've found across the site-safety audits on this blog: four of five ad-network domains independently confirmed as malicious or phishing infrastructure by multiple named security vendors, with a measured, non-trivial CPU cost even when you're doing nothing at all.
No dedicated cryptominer was found, which is a genuinely fair result to report. But "no miner" isn't the same as "safe" — this is a site where the ad infrastructure itself is the confirmed threat.
Use Crunchyroll's free tier first
For titles not available on any licensed platform, GoGoAnime is usable only with uBlock Origin treated as mandatory, not optional — the measured CPU difference alone (48% down to roughly 5%) makes that the single most important thing you can do. Go in knowing the ad infrastructure here has confirmed detections from real security vendors, not just a suspicious-looking domain name.