How we review websites

Every SiteScano report says something about someone's business, so the process behind it should be open to inspection. This page describes what we measure, who checks it, when a report gets published, and what to do if we got something wrong.

Last reviewed Owner SiteScano editorial team

The two tracks

A SiteScano report is built in one or two passes. The first is machine-run and covers what can be measured reliably. The second is a person reading the site, and it only happens where it changes the answer.

Track 1

Automated check

Runs in real time against security engines, registration records, the page itself and link data. Produces the raw signals and a provisional score. Every report has one.

Track 2

Expert manual review

An analyst opens the site and reads it. Judges authorship, originality, transparency and intent — the things a scanner reads as an empty field rather than a problem.

The two tracks answer different questions. The automated check asks is this domain dangerous or unusual. The manual review asks would a careful person trust this site with something that matters. A site can pass the first comfortably and still fail the second, which is why a clean malware scan is never presented as the whole answer.

When a report exists at all

We do not hold a pre-built page for every domain on the internet. A report is created when a real person asks about a specific domain, and it is published only once it holds enough of our own findings to be worth reading. Each report covers a website as a whole rather than an individual page on it.

What creates a report

Visitor demand

Someone checks the domain

A visitor enters a domain in the checker. The automated pass runs live and the result is shown to that person immediately.

Repeat demand

The same domain keeps coming up

When a domain crosses a rolling threshold of independent checks, it enters the manual queue. Sustained interest usually means people are unsure about something specific.

Direct request

Someone asks for a manual review

Visitors can request an expert review of any domain, and site owners can request a re-review of their own. Both go into the same queue on the same terms.

Editorial trigger

The automated result is unconvincing

Contradictory signals, a disputed report, or a domain in a category where a mistake would be expensive. The queue is fed by low confidence, not by traffic potential.

The automated check

This pass runs on demand, in real time, and takes a few seconds. It queries independent providers rather than relying on a single source, because any one blacklist has both false positives and blind spots.

What we queryWhat it tells usRefreshed
Security & blacklist engines90+ independent providers Whether the domain currently appears in malware, phishing, spam or command-and-control listings, and how many providers agree. Every check
Certificate & transportLive TLS handshake Whether HTTPS is served, whether the certificate is valid and current, and who issued it. Every check
Registration recordsWHOIS / RDAP Creation date, registrar, status flags, DNSSEC, expiry and abuse contact. Domain age is the single most useful number here. Every 7 days
Hosting & infrastructureDNS, ASN, IP geolocation Where the site is hosted, on whose network, and whether it shares infrastructure with previously flagged domains. Every 7 days
On-page analysisFirst-party crawl Detected technology, site category, presence of contact, ownership and policy pages, and whether content is age-restricted or otherwise sensitive. Every 30 days
Link reputationAhrefs data How many separate websites link in, the authority of those sources, and whether the anchor text pattern looks organic or bought. Every 30 days
Reviews and public discussionReview platforms, forums, complaint threads Whether reviews of the site exist elsewhere, how many, how old they are, and whether the pattern looks accumulated or manufactured. Public complaint threads are read for recurring themes. Every 30 days
Visitor reviewsFirst-party, moderated Submitted experiences from readers. Held for moderation, never counted toward the score, always shown separately. Continuous

Where the automated pass is weak

Stating this is part of the method. Automated checks are reliable at catching domains that are already known to be bad and domains that are conspicuously new. They are poor at judging a site that is technically clean but written by nobody, hosted properly, and quietly useless — or worse, a site set up carefully enough to look ordinary. A young domain belonging to a legitimate new business and a young domain set up last week for a fake shop produce very similar automated signals. Separating those two is what the second track is for.

The expert manual review

A manual review is an analyst spending real time on the site: opening pages, reading them, following the trail of who published them, and writing down what they found. It follows a fixed sequence so that two analysts reviewing the same site arrive at comparable findings.

  1. Intake and context

    The analyst starts from the automated output, not from a blank page, and notes what triggered the review — repeat searches, a direct request, a dispute or a low-confidence score. Requests from a site's own owner are marked as such in the internal record.

    Recorded: trigger, date, analyst, automated score at intake
  2. Identity and ownership

    Who runs this site, and can that be confirmed from the site itself? The analyst looks for a named operator, a physical or registered address, a working contact route, company or registration numbers, and whether any of it matches the registration records. Hidden ownership is not automatically a problem, but hidden ownership combined with money changing hands is.

    Recorded: ownership disclosure, contact routes tested, mismatches with WHOIS
  3. Authorship and accountability

    Are articles attributed to real, identifiable people with relevant background? Is there an editorial or corrections policy? Are author pages substantive or decorative? Sites that publish advice on money, health or safety without anyone's name attached are treated more sceptically than sites that do the same on cooking.

    Recorded: named authors, bios, editorial policy, review dates
  4. Content reading

    The analyst reads a sample of pages, weighted toward the ones that earn the site money or ask something of the reader. They judge originality, depth, whether claims are supported, and whether the writing shows first-hand knowledge or only rearranges what is already published elsewhere. Sample size scales with the size of the site.

    Recorded: pages sampled, originality and depth assessment, notable findings
  5. Commercial behaviour

    How does the site make money, and is that disclosed? Checkout, pricing, refund, shipping and cancellation terms are examined where they exist. Undisclosed affiliate relationships, fake urgency, invented review counts and pressure tactics are all noted explicitly.

    Recorded: monetisation model, disclosure quality, dark-pattern findings
  6. Reviews, discussion and external reputation

    Does anyone actually use this site, and what do they say afterwards? The analyst reads reviews on the platforms where customers leave them, weighs whether praise looks earned or manufactured, and follows complaint threads and forum discussion for recurring themes. How the operator responds publicly when something goes wrong is often more informative than the complaint itself. Social presence and independent mentions are checked at the same time — a brand with genuine customers leaves traces that are difficult to manufacture cheaply.

    Recorded: review credibility, complaint themes, operator responses, social footprint, link source quality
  7. Write-up, adjustment and sign-off

    Findings are written in plain language with the evidence attached. The analyst may adjust the automated score within a capped range, and every adjustment carries a stated reason. A second reviewer signs off on any review that moves a site across a band boundary or that was requested by the site's owner.

    Published: analyst findings, adjusted score, reason for adjustment, review date

What an analyst may not do

Analysts do not contact site owners to offer services, do not accept anything of value from a reviewed site, and do not review a domain they have any personal or commercial connection to. A review is reassigned if a conflict surfaces at any stage.

How the score is built

Five signal groups produce a score from 1 to 100. The weights below are fixed and applied to every domain. A manual review can move the result within a capped range, and the cap exists so that a single analyst's judgement cannot override the measured evidence entirely.

SecurityBlacklists, malware, phishing, transport
35%
Content & authorshipOriginality, attribution, transparency
25%
Domain & infrastructureAge, registrar, hosting, records
20%
Link reputationWho links in, and how good they are
15%
Reviews and discussionWhat the rest of the web already says
15%

Overrides and caps

Two rules sit above the weighting. A confirmed active threat — live malware, a credential-harvesting page, a listing agreed on by multiple independent engines — caps the score in the Danger band regardless of every other signal. In the other direction, a manual review may adjust a score by no more than 15 points, and never past a security cap.

The five bands

1–39 Danger Active threats, confirmed blacklisting or deliberate concealment.
40–54 Risky Several weak signals at once, often a very new domain with hidden ownership.
55–69 Caution Nothing alarming, but little to confirm the site either.
70–84 Trusted · Verify Mostly clean signals with one or two open questions.
85–100 Safe & Secure Long history, clean security record and a strong link reputation.

Confidence

Every score carries an internal confidence value based on how much of the evidence we actually obtained. A domain that returned complete registration records, a full crawl and usable link data scores with high confidence. A domain that blocked our crawler and returned partial records scores with low confidence, and low confidence is what keeps a report out of the index. Confidence affects publication, never the score itself.

Publishing standards

These are the rules a report has to satisfy before it goes on the site, and they apply to every domain regardless of who asked about it.

Evidence before conclusions

A report is published when we hold enough of our own findings to say something useful. Where a check could not be completed — a registrar withholding records, a site blocking our crawler, a domain too new to have any link history — the report says the data was unavailable. It does not fill the gap with an assumption, and a missing signal is never presented as a negative finding.

Dated and sourced

Every report carries the date of its last check, because a reputation assessment has a shelf life. Where a finding comes from a third party, that provider is named on the report itself rather than buried here. If we cannot attribute a claim to either a named source or an analyst who saw it, it does not go in.

Careful language

We describe what we measured and let the reader draw the conclusion. A report says that a domain appears in a phishing listing, or that no named author could be found — not that a site is a scam. The stronger word is reserved for confirmed active threats, where multiple independent engines agree and the evidence is on the report for anyone to check.

Reviews from readers

Visitor reviews are moderated before publication and are never counted toward the score. They appear in their own section, clearly separated from our findings, so nobody has to guess which is which. We remove reviews that are abusive, obviously fabricated or submitted in bulk, and we do not remove reviews because a site owner objects to them.

On the use of automation

Data collection is automated, because querying ninety security engines by hand would be absurd. Judgement is not. Automated results are presented as measurements with their sources named, and anything presented as an assessment of quality, authorship or intent comes from a named analyst who read the site. We do not publish machine-written prose in the voice of a reviewer.

Independence

A reputation report is only worth reading if its subject cannot influence it. Ours cannot. Revenue comes from Pro subscriptions bought by readers — the only arrangement where the person paying and the person the report serves are the same person.

No commercial path to a score

  • ×No charge for reviews, re-reviews, reconsideration or faster handling
  • ×No paid removal, placement, badges or ranking in any listing
  • ×No commercial relationship with a reviewed site, at any point

Named, independent data

  • ✓Third-party providers are named on the report itself
  • ✓Link metrics from Ahrefs; security results from independent engines
  • ✓No financial interest in the outcome those providers return

Corrections and appeals

We publish assessments that can affect a business, so being correctable is not optional. Anyone can challenge a report — readers, owners, or people with no connection to either.

  1. Report the error

    Use the report-an-error link on the report itself and name the specific fact you believe is wrong. Claims we can check — a registration date, a security listing, a category, a statement about authorship — move fastest. "The score is unfair" without a factual point takes longer, because there is nothing to verify.

    Acknowledged: within 2 working days
  2. Re-run and verify

    We re-run the automated checks and compare them against what is published. Where the disagreement is about judgement rather than fact, the domain goes into the manual queue for a fresh review by an analyst who did not write the original.

    Resolved: factual errors within 5 working days; full re-reviews within 15
  3. Correct and log

    Confirmed errors are corrected and the report shows that it was updated. Where a correction changes the score materially, the reason is stated on the report. If we decline to change something, we say why rather than leaving the request unanswered.

    Published: correction date and reason on the report

Site owners: the fastest route is usually not an appeal

Most low scores on otherwise legitimate sites come from the same three gaps: no named authors, no real contact or ownership page, and no independent sites linking in. Fixing those changes the underlying signals, which changes the score at the next check without anyone needing to argue about it.

What a score is not

The most common misreading is treating a number as a verdict. It is a summary of what we could measure on a particular date.

A low score is not an accusation

It means the signals available to us are weak, contradictory or missing. A new, honest business will often score low. Read the findings, not only the number.

A high score is not a guarantee

Established domains get compromised, sold or repurposed. A score reflects the state of a site at the last check date shown on the report, and nothing after it.

Not a quality or service rating

We assess whether a site is what it appears to be and whether the people behind it can be identified. Delivery times, product quality and customer service are outside our signals.

Informational, not advice

Reports are not legal, financial or professional advice, and they are not a substitute for your own checks before sending money or personal information to anyone.

Who does this work

Manual reviews are carried out by a named team, not an anonymous pool. Every published review records which analyst wrote it and who signed it off.

Ishika Verma

Ishika Verma

Head of editorial standards

Owns this methodology, the scoring weights and the corrections process. Signs off band-changing reviews.

Michael Jackson

Michael Jackson

Senior analyst, e-commerce

Reviews shops and payment flows. Focus on checkout behaviour, disclosure and refund terms.

Vivek Gupta

Vivek Gupta

Senior analyst, publishing

Reviews content sites and directories. Focus on authorship, originality and editorial accountability.

Sarah Chen

Sarah Chen

Security engineering

Maintains the scanning pipeline and the provider set. Investigates disputed security listings.

Something here look wrong?

If a report contains a factual error, or this document does not match what you saw on the site, tell us. Both go to the editorial team, not to a sales inbox.

Report an error Report a site for review