Inspiration

Every day, we visit websites, create accounts, download files, and sometimes enter sensitive information without really knowing whether a website can be trusted.

I wanted to build something that could give users more information before they make that decision. Instead of simply labeling a website as "safe" or "scam," I wanted to show the actual signals behind the assessment.

That idea became VERISCAN — Know Before You Trust.

What It Does

VERISCAN is a website trust-analysis tool where a user enters a URL and receives an overall risk score based on multiple available signals.

It analyzes things such as:

  • Website connectivity and HTTP responses
  • Redirect behavior
  • Domain registration information
  • Domain age
  • Threat intelligence
  • Security and reputation signals

The results are presented as individual factors so users can understand what affected the score instead of receiving a result with no explanation.

How We Built It

VERISCAN uses a server-side analysis system to collect and process the information.

For domain registration data, I used RDAP (Registration Data Access Protocol).

For threat intelligence, I integrated the VirusTotal API, allowing VERISCAN to use real security-vendor observations instead of relying entirely on assumptions.

I also implemented server-side protections against potentially dangerous requests, including requests targeting private or internal network addresses.

The final risk score is calculated using a deterministic scoring system where individual signals can increase or decrease the score.

What Makes It Different

I wanted to avoid the typical "SAFE / SCAM" approach.

Website security isn't always that simple, and an automated system shouldn't pretend to know something when the required information isn't available.

VERISCAN therefore shows the factors behind its score and clearly indicates when certain information is unavailable.

This makes the result more transparent and gives users the information they need to make their own decision.

Challenges

One of the biggest challenges was making the analysis actually use real data instead of creating a simulated demonstration.

Handling redirects, domain registration data, external threat intelligence, and server-side security also required careful consideration.

Another challenge was making the technical information understandable to someone who isn't a cybersecurity expert.

What I Learned

While building VERISCAN, I learned more about how domain registration systems, threat-intelligence services, HTTP requests, server-side security, and risk-scoring systems work together.

I also learned that building a useful security tool isn't just about collecting data. The information has to be presented clearly, and the system needs to be transparent about what it knows and what it doesn't.

Future Improvements

There are several things I would like to add in the future, including more threat-intelligence sources, deeper website analysis, additional security checks, historical domain changes, and more detailed explanations of individual risk factors.

The goal would be to continue expanding VERISCAN while keeping its results understandable and transparent.

Final Thoughts

VERISCAN started with a simple question:

"Can we know more about a website before we trust it?"

Instead of giving users a blind yes-or-no answer, VERISCAN brings together multiple signals and explains them.

VERISCAN — Know Before You Trust.

Built With

Share this project:

Updates

Submission history