Skip to main content
POST
Project URL Risk Analysis

Authorizations

x-api-key
string
header
required

Body

application/json

A JSON object containing a single URL string to be analyzed for potential risks.

url
string
required

The URL or domain to check, with or without a scheme, path or query (e.g. uniswap.org or https://app.uniswap.org/swap). The verdict is for its host; www. and any port are ignored.

Example:

"https://app.uniswap.org/swap"

Response

Success - Returns an assessment of the URL's safety score, including blacklist and maliciousness checks.

riskLevel
enum<string>
required

high: a known phishing or blocklisted site, from Webacy's database or a real-time phishing feed. A subdomain takes its registered domain's verdict when it has none of its own (login.<phishing domain> is high, app.aave.com is low). medium: not listed, but similar to a known project's domain, a possible impersonation. low: a known project's site. unknown: no verdict, including pages on shared hosting such as sites.google.com/view/…, where the platform's reputation says nothing about the page.

Available options:
low,
medium,
high,
unknown
description
string
required

Human-readable explanation of the verdict.

message
string
required

Where to report a wrong verdict.