Website Security Check

Core updates

The traces the crawl looks for are not fixed. When we see a new wave of attacks, the signature goes into the core and the next crawl looks for it too. This page is the record of what we added and when. Every entry here also moves the number of checks that run, because both come from the same place.

Signature version
v1
Checks that run
61
Entries
8
  1. Measurement

    The core was calibrated against real sites

    The thresholds were set by measurement rather than at a desk. A round of roughly 20,000 pages was crawled, the single alarm it raised was a real case, and no false alarm came out of it. The rule stays the same from here: no threshold changes without measurement.

  2. Notification

    Findings started going out by email

    A warning that sits in the panel is not a warning until someone opens the panel. If the verdict is not clean when a crawl ends, an email now goes out the same day and a dismissible banner appears on the site's landing screen. Even after it is dismissed, the banner comes back if the next crawl finds the same problem.

  3. Panel

    The cleanup curve and its trend reading arrived

    The only thing that shows whether a cleanup worked is time. Spam queries in your search data are now drawn as a daily curve, the last two weeks are compared, and the trace gets one of four readings: rising, holding, falling, cut off. Days with no measurement never enter the curve, and the footnote says so.

  4. Panel

    The crawl scorecard was added

    A clean verdict on its own did not build much trust, because the reader could not see what had been examined. The scorecard now lists every check, how many parameters ran inside it and what came out. It is drawn even when the verdict is clean, which is where it earns its place.

  5. Precision

    Genuine translated pages are now told apart

    The foreign-script check flagged the genuine translated pages of a client selling abroad. The criterion changed: if a page declares which language it is in, or carries a language prefix in its URL, that is a legitimate translation and does not count as evidence. Injected pages inherit the template's language and never declare themselves as foreign.

  6. Precision

    The signature weight gate was put in

    In the first pass, weak patterns were flagging pages on their own. Now every signature carries a weight: a strong one flags the page by itself, a weak one asks for a second hit on the same page. A weak hit that stands alone is no longer recorded. That is why a model name in a car article or a time expression in a scheduling article does not count as a finding.

  7. Core

    Four separate traces were merged into one verdict

    Most of the signals were already being collected, but they sat in separate tables and nobody put them side by side. Traces found on pages, content in a language the site does not use, suspicious outbound links and queries leaking into search data are now brought together into one verdict as the crawl ends: Clean, Watch, Alarm.

  8. Corev1

    The crawl started looking for attack traces

    The site crawl was already walking your pages one by one. A signature core was added at the crawl's shared write point, and every page started passing through that gate. Because the check runs on the server, both the server crawl and the browser extension crawl run the same signatures.

How an update reaches you

Nothing is asked of you. Because the check runs on our server, new signatures never require an update to the browser extension; your next crawl simply runs them. Verdicts on earlier crawls can also be rebuilt when needed, so an old crawl can be reassessed with what we know today.

Crawl your site today

Free · Inside the Website Crawler · An email if anything turns up

Start a crawl in the panel