How CheckURL scores websites
Every site is assessed the same way, by the same automated pipeline, and nobody can pay to change a score. This page explains what we do at a high level. The exact signals, weightings and thresholds are proprietary and kept private — publishing the full recipe would only help malicious operators reverse-engineer and evade detection.
We load the submitted URL in a real headless browser and assess what an actual visitor would experience — the redirect path, the rendered page, its network behaviour, its certificate and its hosting. The scanner only reads what the site serves: it never submits forms, fuzzes, exploits, or bypasses access controls.
That evidence is combined with independent, industry-standard threat-intelligence and domain-reputation sources, and with registry checks of any company identity the page claims (verified against official registries rather than taken on trust). Dozens of such signals feed a single 0–100 safety score — higher is safer — shown on every report, with plain-language reasons for the result. Confirmed-malicious evidence caps a site in the high-risk range no matter what else is present.
Automated scoring is occasionally wrong. If a report about your site looks inaccurate, fix the flagged issue and rescan — the score updates automatically from fresh evidence. We never charge to review, correct, or remove a score, and nobody can buy a better rating. Site owners can request a correction or removal via the address in our privacy policy.