URL Radar brings several focused threat-analysis engines together in one explainable report. Each engine looks at a different part of the website, then Radar correlates their signals to show what was observed, why it matters and how confidently it can be interpreted.
Multiple engines. One clearer threat picture.
The content engine looks for social-engineering language, fake verification and pressure tactics. Script and clipboard analysis examines inert code for command delivery, clipboard writes, concealment and encoded behavior. Document analysis reviews supported files for active actions, image-based lures and external-link handoffs.
Network and redirect analysis follows the safe request path and records destination changes. Connection analysis reviews HTTPS and available TLS details. URL and brand context highlights suspicious address patterns and possible impersonation. A website can be tagged by several engines when its behavior crosses more than one category.
From signals to an explainable report
Radar validates the submitted address, blocks private and system networks, retrieves a tightly limited public response and applies deterministic detection rules. Bounded encoded strings may be decoded in memory for classification, but commands and payloads are never executed, retained or reproduced.
The final score is not a black-box verdict. Every contributing rule includes its evidence category, interpretation, score contribution and possible limitations, alongside practical guidance for visitors and security teams.
What Radar cannot prove
A scan is a point-in-time automated assessment. Websites can change, hide content behind browser challenges or target particular visitors. A low score does not prove a website is safe, and a high score does not by itself prove malicious intent.