Looking at the actual payment process it seems you get an iframe embedded within the github page that asks for your credentials. It's not possible for users to verify that the iframe actually belongs to paypal without looking at the source (it doesn't, it actually belongs to <a href="https://assets.braintreegateway.com/" rel="nofollow">https://assets.braintreegateway.com/</a> and it POSTs there too). If this was any less reputable website implementing this it would look really, really shady.<p>It also doesn't help with that we've been training users to check the URL bar before filling in their credentials, which won't help at all now.