How a scan becomes a verdict.
Eight signals resolve independently and stream into one score. High-confidence reputation checks carry the most weight; local context keeps the result useful when a provider is degraded.
Scoring
Safe Browsing matches, community feed hits, and multi-engine detections move the verdict most. TLS quality, WHOIS age, DNS posture, and redirect behavior are supporting evidence rather than the primary driver.
- Risk-moving
- Google Safe Browsing, threat feeds (URLhaus, OpenPhish), VirusTotal detections, ML ensemble consensus.
- Supporting
- TLS validation, WHOIS age and registrar, DNS anomalies, redirect-chain hops.
Score bands
- 0–24
- Safe
- 25–54
- Suspicious
- 55–79
- Malicious
- 80–100
- Critical
Confidence
Confidence is coverage-aware, not just score bands. A safe verdict loses confidence when primary reputation sources time out; a risky verdict gains confidence when independent categories agree. Partial coverage is always stated next to the verdict.
Using the scanner
- Each signal row expands to its full evidence — engines, certificate fields, redirect hops.
- Batch rows resolve independently; open any finished row in the scanner for the full result.
- Saved scans stay on this device unless you export or share them — see privacy for what the server still processes.
- URLhaus and OpenPhish treat exact listed URLs as high-confidence evidence and hostname-only fallbacks as medium confidence. Browse pages like urlhaus.abuse.ch/browse/ are not matches.