URL Safety · Check

by URL Safety

GETBase

$0.003

per call · USD Coin on Base

Score a URL for phishing risk before an agent opens or trusts it. Keyless, deterministic heuristics - typosquat / homoglyph of a known brand, punycode / mixed-script hosts, credentials-in-URL, raw-IP hosts, suspicious TLDs, over-deep subdomains - plus a best-effort domain-age check (young domains are a top phishing signal). Returns a 0-100 risk score, a SAFE / SUSPICIOUS / DANGEROUS verdict, and labelled reasons. No API keys, no LLM.

Endpoint

GET https://safe.cyberwarex.com/check

6

Calls / 30d

1

Unique payers / 30d

Sep 10

Last called

exact

Payment scheme

Call this service

TypeScript · @x402/fetch
import { wrapFetchWithPayment } from "@x402/fetch";
import { privateKeyToAccount } from "viem/accounts";

const account = privateKeyToAccount(process.env.PRIVATE_KEY);
const fetchWithPay = wrapFetchWithPayment(fetch, account);

const res = await fetchWithPay("https://safe.cyberwarex.com/check", {
  method: "GET",
});
const data = await res.json();
cURL
curl -X GET \
  "https://safe.cyberwarex.com/check?url=https%3A%2F%2Fcoinbase.com.secure-login.xyz%2Fverify" \
  -H "X-PAYMENT: <signed x402 payment>"

Example response

{
  "domain_age_days": 4,
  "host": "coinbase.com.secure-login.xyz",
  "labels": [
    "brand_impersonation",
    "suspicious_tld"
  ],
  "reasons": [
    "'coinbase' appears in the host but the domain is secure-login.xyz, not coinbase.com"
  ],
  "registrable_domain": "secure-login.xyz",
  "risk_score": 80,
  "source": "heuristics + RDAP",
  "url": "https://coinbase.com.secure-login.xyz/verify",
  "verdict": "DANGEROUS"
}

Payment details

Pay to0x058d0cc5cc97e61e8a9f38d6d6365bce525921b2
AssetUSD Coin · 0x833589fcd6edb6e08f4c7c32d4f71b54bda02913
NetworksBase
Schemesexact

Is this your API?

Pin it to the top of Search & Web and the homepage with a featured placement.

Get featured →

More from URL Safety & similar services