Scoring methodology
A transparent, weighted mix of eight public safety signals.
| Signal | Source | Weight |
|---|---|---|
Google Safe Browsing Live lookup for known malware, phishing, and unwanted software. | safebrowsing.googleapis.com | 25% |
Abuse blocklists Community-maintained lists of sites confirmed hosting malware or phishing. | URLhaus (abuse.ch), PhishTank | 20% |
Domain age (WHOIS) How long the domain has been registered. Very new domains are risky. | RDAP | 15% |
SSL / TLS certificate Whether HTTPS works and the certificate is valid. | Direct TLS probe | 10% |
DNS configuration SPF, DMARC, DNSSEC and basic MX/NS setup — signs of a legitimate operator. | Cloudflare DoH | 10% |
Community reviews Real-user reports of scams, poor service, or malware. | TrustDepth users | 10% |
Reachability & HTTPS Whether the site responds, redirects HTTP → HTTPS, and sets HSTS. | HTTP HEAD probe | 5% |
Naming heuristics Suspicious TLDs, digit-heavy names, homoglyph patterns. | Local rules | 5% |
Verdict bands
- 85–100 · Trusted — passes all core safety checks.
- 70–84 · Likely safe — no red flags; use normal caution.
- 45–69 · Unclear — mixed signals; verify independently.
- 25–44 · Suspicious — multiple warning signs; don't share personal info.
- 0–24 · Dangerous — flagged as unsafe; do not visit.
Freshness
Scores are recomputed on demand, with results cached for up to 7 days. You can force a rescan from any scorecard page.