Investigation
Is Scam-Detector.com Legit or a Scam?
That is not my phrasing. It is Scam-Detector.com’s own wording, from its report on my business. Their heading reads “Is aiwebpageseo.com Legit?”, their opening line reads “Is aiwebpageseo.com legit or a scam?”, and the page is titled “aiwebpageseo.com Reviews: Is this site a scam or legit?” — indexed under my brand name, which I was never told about. So this article asks their question, in their words, about them — and answers it the way they did not: with the evidence, every check dated and reproducible.
It scored the NHS at 80.1 out of 100 and published the sentence “nhs.uk is an innocuous suspicious website” — then told readers to avoid my business. It calls itself the largest fraud prevention resource in the world. It is not, and it has never published a figure that would make it so. It told readers my domain was detected on blacklist engines. Seven blocklists said otherwise — and that claim has since been removed from the page without a word. Here is what Scam-Detector.com’s numbers are actually measuring — and what happened when I used its own correction process three times.
Since this article was published, three of the specific claims examined below have been removed from Scam-Detector.com’s report on aiwebpageseo.com. No notification was given, no correction was issued, and there has still been no reply to any of the three verification submissions described later in this piece.
The blacklist claim has gone. The company details panel asserted “Detected on blacklist engines” when this article was researched on 24 July 2026. It now reads “Not detected by any blacklist engine” — which is what the seven independent DNS checks reproduced below found on 24 July, and what they still find. The single most serious and most easily disproved statement on the page was deleted rather than corrected — five weeks after I wrote to them, on 17 June 2026, with ownership documentation and the words “you also say I am on banned databases yet I am not”. That email was never answered.
The score has changed. 15.5 out of 100, tagged “Controversial. High-Risk. Unsafe.”, became 28.1 out of 100, tagged “Risky. Dubious. Perilous.” No new evidence accompanies the new figure, and none accompanied the old one. A score that had stood since February moved overnight, which is the clearest available demonstration of the central point of this article: the number is not a measurement.
The verdict did not improve with it. At 15.5 the page tagged this business “Controversial. High-Risk. Unsafe.” At 28.1 it tags it “Risky. Dubious. Perilous.” The figure moved by nearly thirteen points and a reader is still told three condemnatory words. Nobody reads a decimal against a scale; they read the tags. Whatever those three words track, it is not the score they are printed beneath.
And consider what “Perilous” asserts. It tells a reader this site is dangerous to visit. The only three data points the report publishes about the domain are that it is not detected by any blacklist engine, that valid HTTPS was found, and the date it was registered. All three are clean. There is nothing in the published evidence that supports peril of any kind — and the metrics that might have, had any figure been given, are the five that appear nowhere on the page.
The success penalty has gone. The line flagging the site’s “seemingly suspicious success, even with a newly registered domain” no longer appears.
Everything below is left as originally published and dated 24 July 2026, so the two versions can be compared. The findings that do not depend on those three items — the unpublished metric values, the templated phishing language, the invitation to supply evidence after the verdict, the unnamed corroborating partners, the dead media badges and the correction terms — are unchanged on the live page.
Who wrote this, and why. I run AIWebPageSEO (aiwebpageseo.com), an SEO, AEO and schema audit platform. Scam-Detector.com published an automated report scoring my business 15.5 out of 100 and telling readers to stay away (28.1 as of 25 July 2026 — see the update above). I used their correction process three times and was ignored. So I did the thing I do for a living: I checked their working, using the same public tools anyone can run, and published every result — including the one that flatters them. Every check below is reproducible.
Scam-Detector.com describes itself as the largest fraud prevention resource in the world. It runs a "Website Validator" that assigns any domain a trust score out of 100, publishes that score on an indexed page carrying the target's own brand name, and tells readers whether to stay away.
The billing is confident. Its homepage calls it the largest fraud prevention resource in the world, run by a full team of professionals with world-class partners, and an official contributor to the Federal Trade Commission.
Two details sit oddly against that. The homepage puts its reach at over 169 countries; the company's own Trustpilot profile says 191. A twenty-two country discrepancy in your own marketing is trivial in isolation, but it is a strange lapse for an organisation whose entire proposition is the accuracy of numbers about other people.
The second is the origin story, which the site tells itself: Scam Detector grew out of a 2008 amateur short film about the Nigerian 419 scam, made for $180 with a volunteer crew, which went viral and prompted requests for an app. That is a likeable story. It is not the provenance of a global risk-scoring authority, and nothing on the site bridges the gap between the two.
That is an enormous amount of power to hold over other people's businesses. So the reasonable question is not whether scam detection is worth doing — it plainly is — but whether this particular scoring system is accurate enough to justify the damage it does when it is wrong.
On the evidence its own users have left in public, it is not.
What the algorithm actually is
Scam Detector's published methodology is thin. Its validator pages state that a score is produced from 53 aggregated factors relevant to the site's industry, and that it partners with other fraud-prevention companies.
Fifty-three factors. Not one of them named. There is no published weighting, no per-factor breakdown on the report, no way for a business owner to see which signal cost them sixty points. You are given a number, a set of tags — Suspicious, Dubious, Unsafe — and boilerplate.
That boilerplate matters more than the number. The validator's own template language tells readers the algorithm found high-risk activity connected to phishing and spamming, and advises them to stay away. One reviewer's objection to this is precise: the language is templated, it is applied to sites where it is "patently false", and no supporting proof is offered.
So a legitimate business does not merely get a low number. It gets a public page implying phishing and spam, with nothing behind the implication a reader can inspect.
Consider what that means in practice. A one-page brochure site for a plumber, a new domain with clean WHOIS privacy, a small shop on an unfashionable platform — these trip generic risk heuristics constantly. Domain age alone will sink any legitimate new business. The scoring cannot distinguish "new and small" from "fraudulent", because at the signal level those two things look nearly identical. So it labels both.
The reviews are evidence of the fault, not the cure
Scam-Detector.com has over 600 reviews on Trustpilot, and it does well out of them. Read them in sequence, though, and the rating turns out to be measuring something other than what it appears to measure.
Here is the shape of nearly every positive one. A business owner discovers their site has been scored somewhere between 20 and 40, and publicly described in terms implying phishing or spam. They contact Scam Detector. They supply documents. Within a day or two the score is corrected — frequently, and this is the part worth dwelling on, straight to 100.
Then they write a five-star review.
Reviewers describe exactly this arc over and over: a low algorithmic score, an email, supporting documents, an immediate correction to 100 out of 100. One describes a server's anti-bot protection blocking the scanner as the cause, corrected to "100/100 almost immediately" once a human looked. Another opens by saying they had originally rated the company one star after finding their own site labelled a scam — and then revised it upward once it was fixed.
Sit with the mechanics of that for a second.
Every review following that pattern began as a false accusation. The reviewer is not a satisfied customer. They are a wronged party, thanking the company for undoing damage that company inflicted on them, unprompted, without warning, in public, on a page carrying their own brand name. Gratitude for the removal of an injury is not evidence of a good product. It is evidence of an injury.
The more sites the algorithm wrongly flags, the higher Scam Detector's Trustpilot score climbs.
Each false positive manufactures one more relieved business owner with a reason to write in. A validator that never made a mistake would generate almost none of these reviews at all. The rating is not a measure of accuracy — it is a measure of how many people needed rescuing, and it rises when the tool gets worse.
And the corrections themselves give the game away. If a business moves from 26 to 100 by sending an email and two documents, the original 26 was never a measurement of anything. Twenty-six and one hundred are not adjacent numbers. There is no methodology on earth where a couple of PDFs legitimately swing a score by seventy-four points — unless the score was close to arbitrary to begin with. A real risk assessment does not collapse on contact with the first person who pushes back.
The company's defenders have this exactly backwards. The speed of the correction is not the reassurance. It is the confession.
Note also what has to happen before any of this works: you have to find out. There is no notification. The business owners writing these reviews are the ones who happened to discover the page. Nobody knows how many low scores are sitting live right now, uncorrected, on sites whose owners have never thought to search their own brand name. Those people leave no reviews at all — and so the one population that would drag the rating down is precisely the population that never shows up in it.
A wrong score does not expire
Here is the part that turns an inaccurate score into a lasting one.
Across hundreds of public reviews describing a corrected score, a single detail is conspicuous by its absence: not one describes the score fixing itself. Every correction on record follows the same trigger — the owner found the page, the owner made contact, the owner supplied documents. Nobody reports coming back weeks later to discover the algorithm had reconsidered on its own.
Whatever the re-evaluation schedule is, the company does not publish it, and its users cannot see it operating. There is no visible date on which a business that fixed the underlying issue — added HTTPS, published contact details, aged past the new-domain penalty, unblocked the scanner — gets that reflected without asking.
Which means the score is not a live assessment. It is a snapshot, taken once, published permanently, and revised only under pressure. A business that was six weeks old when the crawler arrived is still being described by that six-week-old snapshot years later, to every customer who searches its name.
Combine that with the absence of any notification and the position is stark: the error is published without telling you, it does not correct itself, and the clock on the damage only starts when you happen to stumble across it. Every day between those two moments is paid for by the business, not by the company that made the mistake.
The allegations, and what they are worth
Beyond the false-positive pattern, reviewers make sharper accusations. These are allegations by members of the public, not established fact, and should be read as such — but there are enough of them, saying the same thing, to be worth putting on the record.
Several describe the model as commercial rather than protective. One states flatly that the business model is "extortion": poor rating, customer alarm, invitation to pay. Another characterises the site as blackmail, alleging that removal from the blacklist requires the paid service. A third accuses it of scare tactics to drive subscriptions.
Others take issue with the surrounding commercial layer — that the site monetises through advertising, affiliate links and premium services, and that this sits awkwardly alongside a claim to impartial fraud assessment.
Against this, other reviewers state directly that using the site costs nothing and that unfair scores are raised for free on request. Scam Detector's own homepage is unambiguous on the point: it says the service is free and always will be. Both things are being said, and an honest account has to carry both — but the company's public position is that no payment is required to have a wrong score corrected, and that is the standard it should be held to.
Two further complaints stand out because they are checkable rather than subjective:
Domains with no website at all were scored. One business owner, holding defensive domain registrations with nothing published on them, reports that none scored above 40. A parked domain has no content to assess. Scoring it at all is scoring nothing.
The scores contradict other authorities. One commenter notes Scam Detector rating a company at 20.8 that Trustpilot rates at 100. Divergence from another rating system is not proof of error — but when the divergence is that wide, at least one of the two is badly broken, and only one of them shows its working.
The self-assessment
Scam-Detector.com's validator awards scam-detector.com a trust score of 100 — the maximum available. Its own reasoning notes no high-risk activity detected, tags of Safe and Secure, and confidence backed by partner fraud-prevention companies.
Six hundred public complaints about accuracy, and the algorithm scores itself perfect. Whatever those 53 factors measure, it evidently isn't reputation.
Why any of this matters beyond one company
The real harm is downstream, and it is getting worse.
A Scam Detector validator page ranks. It carries the target's brand name in the URL and the title, so it surfaces on brand searches — often on page one, sometimes above the business itself. A customer who searches your name to check you out before buying sees a page implying phishing, next to a number under 30.
You do not get told. There is no notification. Businesses in these reviews found out via a customer, or by accident, sometimes long after the score went live and the lost sales had already happened.
And it no longer stops at human readers. AI assistants ingest exactly this kind of structured, confidently-worded, well-indexed content when answering "is this company legitimate?" An unsupported score becomes a citation, the citation becomes an assertion, and the assertion is repeated to people who will never see the source or the caveat. A wrong number that once cost you a few clicks now propagates.
That is the case for holding automated reputation scoring to a far higher standard than this. If you are going to publish a number that can cost someone their business, you owe them three things: the evidence behind it, a notification before you publish it, and a free correction route that doesn't depend on them finding out by luck. The same principle drives how we build our own checks: every finding in an AIWebPageSEO technical audit names the element it came from, so it can be verified or disputed.
If your business has been scored
- Search your own brand name and see whether a validator page ranks for it. Our free SEO and schema tools will show you what else is ranking on it. Check it monthly. This is not paranoia — nobody is going to tell you.
- Screenshot the page with the date visible. If the score is later quietly corrected, that record is the only evidence the damage ever existed.
- Contact them with documentation. By the weight of the public reviews, this works, it is fast, and it appears to cost nothing. Do this before anything adversarial.
- Escalate formally if it fails. A published statement implying your business conducts phishing, with no evidence and no correction, is a matter for a solicitor. At least one reviewer reports a cease and desist letter producing an overnight correction to 100.
- Fix the signals you control — HTTPS, complete WHOIS or a proper registrant record, real contact details, a physical address, and no aggressive bot-blocking on your firewall. Several corrections in these reviews traced back to a scanner being blocked rather than anything real.
Who actually operates it, and what its own terms say
Click "Terms of Use" or "Privacy Policy" on Scam Detector and you leave the site. Both links land on guidingtechmedia.com, and neither document names scam-detector.com anywhere in its text.
What they name is the operator. The terms are entered into with Zeus, LLC dba Guiding Tech Media, of 151 Calle de San Francisco, Suite 200 – PMB 5072, San Juan, Puerto Rico, and they govern all websites and properties owned and operated by that company. Scam Detector is identified as one of those properties only in the site footer, listed under "Everyday Tech" alongside Guiding Tech, Alphr, Shotkit, AppleToolBox and Tech Junkie. A second group, "Pro Tech", holds KDnuggets, Machine Learning Mastery, Statology and ExcelDemy.
So the world's largest fraud prevention resource is one title in a portfolio of consumer tech content brands. Not a security firm, not an investigator, not a regulator — a publisher, sitting in the same stable as a photography blog and an Excel tutorial site.
That is not concealed, exactly. It is disclosed in the least visible place available: a footer on a corporate site the reader has to leave scam-detector.com to reach, in documents that never mention the brand that sent them there.
The terms disclaim everything the marketing asserts
Under "Reliance on Information Posted", the terms state that the information presented on the websites is made available solely for general informational purposes, that the company does not warrant its accuracy, completeness or usefulness, and that any reliance placed on it is strictly at the reader's own risk. All liability arising from such reliance is disclaimed.
Hold that against the product. The validator tells readers a business is high-risk, unsafe, associated with phishing, and that they should stay away. It publishes a number to one decimal place. It says the company is confident in the score.
In public, a finding. In the contract, an unwarranted opinion nobody should rely on.
Both cannot be true, and the gap between them is the whole problem. If the score is reliable enough to destroy a small business's brand search, it is reliable enough to stand behind. If it needs a blanket accuracy disclaimer, it is not reliable enough to publish as a verdict.
Paid placement, admitted
The Affiliate Disclosure is unambiguous. Links may be affiliate links earning commission. And, in the company's own words, it may feature sponsored content or work with third-party partners who compensate it for placements, recommendations, or promotions.
Now return to the block at the top of every validator report — "Scam Detectors Most Trusted Websites in Online Security" — awarding Guardio, ExpressVPN and Incogni a score of 100.
The operator's own terms concede that placements and recommendations may be paid for. The reports do not distinguish which recommendations those are. A reader is shown a business scored 15.5 and three security products scored 100, in the same visual language, with no indication that one category may be commercial.
The privacy policy has nothing for the people it scores
The privacy policy opens with a notice that the website may sell and/or use your personal data.
More importantly, read what it covers: information collected from users of the websites — what you type into forms, what your browser reveals as you read. The rights it offers follow that scope. You may request access to, correction of, or deletion of personal information that you have provided to them.
There is nothing — not one clause — about the data the company collects on the millions of third-party websites it scores. No route to object to being scanned. No route to demand removal of a published report. No stated retention period for it. No process for challenging accuracy beyond the informal email arrangement printed on the report itself, which is a courtesy, not a right.
The policy also carries no UK or EU data protection section at all. It addresses US state privacy rights and nothing else. For an operation claiming to have been accessed in 191 countries, publishing risk assessments of British and European businesses — many of them sole traders, whose business data is personal data — there is no named data protection officer, no EU or UK representative, no lawful basis stated, and no data subject rights procedure.
So where does the authority come from?
It doesn't. And that is the honest answer, not a rhetorical one.
The terms bind readers — people who visit the site. A business that has been scored never visited, never registered, never agreed to anything. There is no contract between Scam Detector and the subjects of its reports, which means there is no consent, no agreed standard of accuracy, no service level, and no contractual remedy. The company is not regulated, not accredited, and not appointed by anyone.
What it is doing is publishing. Anyone may publish an opinion about a business, and that freedom matters. But the corollary is the one Scam Detector's structure appears designed to avoid: a publisher answers for what it publishes. Not through its terms of use, which the subject never signed — through defamation, through malicious falsehood, through data protection law, and through the consumer protection regime governing how the material is presented and monetised.
There is a final irony in the terms. Users are prohibited from employing any robot, spider or automatic device to access or monitor the company's websites without written consent. The prohibition its operator applies to its own property is precisely the activity its product performs, unasked, on everybody else's.
A worked example: this site, scored 15.5 on 24 July 2026
Disclosure: Scam Detector's validator scored aiwebpageseo.com — the site you are reading — at 15.5 out of 100, tagged "Controversial. High-Risk. Unsafe." As of 25 July 2026 the same page reads 28.1, tagged "Risky. Dubious. Perilous." We publish that openly, because the report is the clearest available illustration of everything above, and because you should weigh what follows knowing we are a subject of it, not a bystander.
Read as a document, the report contradicts itself.
It asserts phishing, then admits it hasn't identified anything. The verdict paragraph states the algorithm detected high-risk activity related to phishing and spamming. Four paragraphs later, under the risk factors themselves, it says the investigation is still working to pinpoint the specific category — and invites readers to supply the answer in the comments. The conclusion is stated as established; the evidence section concedes it is not.
It penalises success. The report says the algorithm flagged the site's "seemingly suspicious success, even with a newly registered domain." Being new is a demerit. Performing well while new is a further demerit. There is no configuration a legitimate new business can adopt that scores well against that pair of rules. This line no longer appears on the live page as of 25 July 2026.
It cites a blacklist without naming one. "Detected on blacklist engines." No engine named, no listing reproduced, no date given. It is the most serious and most easily verifiable claim on the page, and it is the one carrying no evidence at all. It has since been deleted — see the update at the top.
It reads privacy compliance as concealment. The company details are largely "REDACTED FOR PRIVACY" — the default WHOIS behaviour for private registrants, and a data protection requirement, not a choice to hide. It is scored as opacity.
Eight metrics, not one number
The report opens its methodology with a list of what it assessed: Proximity to Suspicious Websites, Threat Profile, Phishing Profile, Malware Score, Spam Score, Domain Blacklist Status, HTTPS connection, Domain Creation Date.
It then explains, at length, how to interpret them. A proximity score above 80 strongly indicates a high-risk website, below 30 a less-threatening one. Malware and spam scores under 30 are reassuring; anything higher should raise concerns.
Not one value is published. Not a single number appears against any of the five scored metrics.
The reader is handed a detailed key to a chart that isn't there — told precisely where the danger threshold sits, and never told which side of it the business falls on. Then, having shown no figures, the page concludes that the site is suspicious given all the risk factors and data numbers analysed. There are no data numbers. They are not withheld or summarised; they are simply absent, while the prose insists they were decisive.
The same applies to the section headed Domain Blacklisting Status, which defines what a blacklist is and never states a result. The only place a result appears is the panel at the top, asserting detection, which the DNS checks above disprove.
Unnamed partners who "found the same issues"
The verdict is fortified with a claim of corroboration: the company says it is confident in the score because it partners with other high-tech, fraud-prevention companies that found the same issues.
No partner is named, on this report or anywhere else. No finding of theirs is quoted, dated or linked. And the one class of independent finding that can be checked from outside — blacklist status — came back clean on all seven engines tested.
So the sentence performs a specific job without carrying any information. It converts one company's unpublished opinion into an apparent industry consensus, using partners the reader cannot identify and corroboration the reader cannot inspect.
The evidence is crowdsourced after the verdict
The most revealing sentence in the whole report is the quiet one in the middle of the risk factors section: the investigation continues working to pinpoint the specific category, but insights are welcome in the comments below.
Read the sequence that implies. The score is calculated. The tags are applied. The phishing and spamming language is published. The page is indexed and begins ranking on the business's name. Then the public is invited to supply the substance.
That is the reverse of an investigation. A finding is what you publish after you establish something. Here the finding is the starting position and the evidence is an open request.
The invitation itself is not neutral either. Readers are asked how they found the page — online ads, suspicious Facebook advertisements, Instagram, email? The question presupposes suspicious advertising, from a company that has never established that any advertising exists, and asks members of the public to confirm a premise it supplied to them. Whatever is collected that way is not evidence. It is an echo.
One further detail sits oddly beside all of this. The report's own company panel records a valid HTTPS certificate — a pass, by its own criteria — and explains the check by noting whether the address bar shows an 's' and displays in green. The site meets every objective standard the report actually measured, and scores 15.5.
The blacklist claim, tested
The single most serious line in the report is in the company details panel: Domain Blacklist Status — Detected on blacklist engines. Plural. No engine named, no listing reference, no date.
It is also the only claim on the page that asserts an independent third party found something. Everything else is Scam Detector's own opinion of domain age and traffic. This one says somebody else caught you.
It is trivially testable, so we tested it — direct DNS lookups against the major blocklists, run on the server, on 24 July 2026:
- Spamhaus DBL (domain) — not listed
- SURBL multi (domain) — not listed
- URIBL multi (domain) — not listed
- Spamhaus ZEN (IP 87.106.96.71) — not listed
- SpamCop (IP) — not listed
- Barracuda (IP) — not listed
- SORBS (IP) — not listed
Seven engines, domain and IP, every one clean. Not a single listing anywhere.
So the claim is false, and it is false in the most damaging direction available. "Detected on blacklist engines" is the line that converts an opinion about a young domain into an apparent finding of fact corroborated by security infrastructure. It is what makes a reader believe the phishing language. And it is not true.
Note what the check cost: four lines of shell and about two seconds. This is not obscure data requiring a partnership or a licence — it is public DNS, queryable by anyone, and any system claiming to assess blacklist status must already be doing exactly this lookup. Which raises the question of what the report is reporting on. Either something ran and returned nothing and the page said the opposite, or nothing ran at all.
It stood, uncorrected, through three ignored attempts to have it reviewed — and was then removed, silently, after this article was published. No reply to any of the three submissions has ever arrived.
Three attempts, a dated notice, and no reply
The report invites the owner to challenge the score, sets out the documentation required, and gives an email address. We used it.
Over the past two to three months, aiwebpageseo.com submitted that verification process three times, supplying the business documentation the report asks for, and additionally contacted the company by email direct.
The blacklist statement was disputed in writing on 17 June 2026. That email identified myself by name as the owner, attached photographs and PDFs evidencing ownership, company records and company registration information, pointed to the About page on this domain carrying the company details, asked for the site to be re-evaluated, and said in terms: you also say I am on banned databases yet I am not.
That is the documentation the report itself specifies. It named the single most serious statement on the page and stated plainly that it was untrue. It received no reply.
The statement remained published for a further five weeks. It was not corrected, not qualified, and not acknowledged. It was removed at some point on or before 25 July 2026 — after this article was published — and no notification of that removal has ever been sent.
There has been no response to any of them. For five months the 15.5 score, the phishing language and the “Unsafe” tag stood published and unchanged, on a page that ranks for the business’s own name. Then, on the night of 24 July 2026, it changed — the score, the tags and three of the claims examined here — still without any reply, notification or acknowledgement that a correction had been made.
Weigh that against the review corpus. The five-star reviews are almost uniformly about responsiveness — replies within a day, documents reviewed promptly, scores corrected to 100. That responsiveness is the company's entire defence against the accuracy complaints, and it is the thing every satisfied reviewer is actually praising.
So the correction process is not a right, and on this evidence it is not even a reliable courtesy. It is discretionary. Some businesses are answered within hours and write glowing reviews about it; others use the same route three times and are ignored, and never appear in the review data at all — because there is nothing to thank anyone for.
That asymmetry deserves an explanation the company has not offered. Whatever determines who gets answered, it is not published anywhere, and it is not the process printed on the report.
What the report is actually selling
Above the verdict, before a reader reaches a single finding, sits a block headed "Scam Detectors Most Trusted Websites in Online Security", listing Guardio at 100, ExpressVPN at 100 and Incogni at 100.
Commercial partners hold the maximum score on the same page that assigns this site 15.5.
Below the findings, the page turns into sales copy: Incogni with plan tiers and prices, Guardio with an exclusive 20% reader discount, Surfshark with "86% off + up to 5 months free". The Surfshark link is an affiliate tracking URL carrying Scam Detector's own publisher ID — a commission, not a recommendation.
And the Surfshark pitch is introduced as a Black Friday promotion available "only this week", on a page served in July. Either that text has sat unchanged since November, or the deadline is permanent furniture. A countdown that never expires is not an oversight; under UK consumer law, falsely stating that a product is available only for a limited time, in order to elicit an immediate decision, is a prohibited practice in its own right.
Then, for anyone who has lost more than $1,000, the page offers to pass their case to partnered "asset recovery companies".
So the architecture of the page is: frighten the reader about the business, then sell the reader four security products, then capture the reader's loss. The trust score is the top of a funnel.
The badges that link nowhere
The validator page carries a "Featured On" row of eleven media logos — ABC, BBC, CNET, NBC, FOX, The Star, FOX Business, CTV, Global TV, Kiplinger, Breakfast TV.
Ten of the eleven are not links to anything. They resolve to "#." — an empty anchor pointing back at the same page. Only FOX Business carries a genuine outbound URL.
The company's homepage does link to real coverage, so the underlying claim is not invented wholesale. But on the validator page — the page that damages a business, the page a customer lands on after searching a company's name — the corroboration is decorative. Eleven trust signals doing persuasive work at the exact moment a reader is deciding whether to believe a low score, and ten of them cannot be checked from where they are displayed.
"The more proof, the higher your trust score"
The correction terms are printed on the report, and they are candid to the point of self-indictment. Owners are asked for incorporation documents, business registration, the owner's personal LinkedIn profile, company social accounts, screenshots of satisfied customers, evidence of inventory. And then, in the company's own words: the more proof you provide, the higher your trust score.
That sentence describes a document-collection exercise, not a risk assessment. The number does not measure the probability that a business is fraudulent. It measures how much paperwork that business has sent to Scam Detector — which is why a score can travel from 26 to 100 in a day, and why it never moves at all for the business that never noticed.
We ran their tool on the safest sites in Britain
If a trust score measures fraud risk, it should be trivially easy to validate: put unimpeachable sites through it and see what comes back. So we did, on 24 July 2026.
| Site | Score | Tags applied |
|---|---|---|
| gov.uk — UK government | 100 | Safe. Secure. |
| nhs.uk — National Health Service | 80.1 | Fair. Valid. Known. |
| aiwebpageseo.com — this site | 15.5 | Controversial. High-Risk. Unsafe. |
Start with the NHS. The national health service of the United Kingdom — a government body, decades old, one of the most visited and most scrutinised domains in the country — does not receive full marks. It is docked twenty points and tagged "Fair", with the report recording a low risk of phishing and spamming activity rather than none.
There is no coherent risk model in which nhs.uk carries residual phishing risk. What the score is actually reporting is that nhs.uk is not gov.uk: slightly different domain profile, slightly different signals, twenty points gone. The algorithm is not measuring fraud. It is measuring conformity to a template, and deducting for deviation.
Then read the sentence the system generated about it, reproduced exactly:
nhs.uk is an innocuous suspicious website, given all the risk factors and data numbers analyzed in this in-depth review.
Innocuous suspicious. Two contradictory words, side by side, published about the NHS. It is not a typo — it is a template with a variable slot, filled by a score band, with nobody reading the output. The phrase "given all the risk factors and data numbers analyzed" appears there too, on a page that publishes no numbers, exactly as it does on ours.
That is the mechanism laid bare. There is no in-depth review. There is a string of boilerplate with a number dropped into it, and whatever comes out is published under the business's name and indexed.
The same sentences, on a site they rate 80.6
If the phrasing on my report were a finding about my business, it would not appear on a business they approve of. So I pulled their report on archive.md, a site they score 80.6 out of 100 and tag “Fair. Valid. Known.” — fetched 25 July 2026, and reproducible by anyone.
Four of the sentences are identical to mine, word for word.
The unnamed corroboration. “We are confident about our score as we also partner with other high-tech, fraud-prevention companies that found the same issues.” The same claim, on a site with no issues. Whatever those partners are said to have found, they found it on a business scored 80.6 and on one scored 28.1, and it is printed either way.
The unfinished investigation. “Our investigation continues working to pinpoint the specific category, but we welcome your insights in the comments below.” Also on the 80.6 page. It is not a candid note about my case. It is fixed text.
The contradiction published about the NHS. “archive.md is an innocuous suspicious website, given all the risk factors and data numbers analyzed in this in-depth review.” The phrase this article’s headline was built on is not a one-off generated about the health service. It is a score band, and it prints for anyone who lands in it.
And the risk sentence itself is a slot. Where my report reads that the algorithm detected high-risk activity related to phishing and spamming, theirs reads that it detected a low risk for activity related to phishing and spamming. Same sentence, one variable, no evidence on either page. The phishing language is not an allegation the system arrived at about my business. It is the sentence it prints, with a word swapped by band.
Then the detail that settles the missing metrics.
So the number is not unobtainable, and the panel is capable of displaying it. On a page that scores well, the favourable reading is shown. On mine — where a proximity figure would have to be either low, and inconsistent with the verdict, or high, and finally an actual piece of evidence — the row is simply absent, and the section beneath it explains at length how to interpret a figure the reader is never given.
One last thing on that page, offered without comment. Under the heading asking what archive.md is, where my report carries a summary of my business, theirs carries three words: “Could not retrieve website content.” They could not read the site. They scored it 80.6 anyway.
The four factors they left blank, measured
Their report lists eight factors it says it assessed. It prints a value for three and leaves five blank: Proximity, Threat, Phishing, Malware and Spam. Four of those five can be measured directly, with public tools, by anyone — so on 25 July 2026 I measured them. Each test below gives what their report claims, what the test does, the command that produces the result, and the value it returned. Every one is reproducible: run the command yourself and you get the same answer. That is the whole point — their report shows no working, and this one is nothing but working.
Threat and Malware — Google Web Risk
Their claim: two factors, “Threat Profile” and “Malware Score”, printed with no value, under the sentence that the algorithm “detected high-risk activity related to phishing, spamming, and other factors”.
The test: Google Web Risk is the threat database Chrome and Firefox use to warn users away from dangerous sites. It answers public queries. A site hosting malware or used for social engineering returns the matching threat types; a clean site returns an empty object.
curl "https://webrisk.googleapis.com/v1/uris:search?threatTypes=MALWARE&threatTypes=SOCIAL_ENGINEERING&threatTypes=UNWANTED_SOFTWARE&uri=https://aiwebpageseo.com/&key=KEY"
Result: {}. Empty. No malware, no social engineering, no unwanted software. Not my tool grading my own site — Google’s threat database, answering anyone, on a dated query. Their two blank boxes, filled by Google, both read nothing.
Phishing — where the forms submit
Their claim: a factor named “Phishing Profile”, printed with no value.
The test: a phishing page captures what a visitor types and sends it to someone other than the site they believe they are on. That is mechanical and checkable: read every form on the site and see where it posts. A form submitting to a domain that is not mine would be the signature. Count the forms; count how many send data off-domain.
for each <form> in public/*.html : read its action= URL, flag any that is not on aiwebpageseo.com
Result: 14 forms found across the site; 0 post to any third-party domain. Every form submits to aiwebpageseo.com and nowhere else. The measured Phishing Profile is zero — the value their report declined to print.
Spam — the mail authentication records
Their claim: a factor named “Spam Score”, printed with no value.
The test: a spam-sending domain does not publish sender authentication, because authentication is what stops forged mail. A legitimate domain publishes three public DNS records: SPF (who may send for it), DMARC (what to do with mail that fails), and DKIM (a cryptographic signing key). These are readable by anyone in seconds.
host -t TXT aiwebpageseo.com host -t TXT _dmarc.aiwebpageseo.com host -t TXT default._domainkey.aiwebpageseo.com
Result: all three present. SPF published; DMARC published with policy p=quarantine, the enforcing setting that tells receivers to quarantine mail failing the check; DKIM signing key live on the default selector. Every record that would inform a Spam Score exists and passes. Their blank box, filled in, reads clean.
Blacklist — nine engines, queried directly
Their claim: when this article was researched, “Detected on blacklist engines.” It now reads “Not detected by any blacklist engine.” Neither version carries the list of engines checked or the date.
The test: a DNS blocklist answers a specially-formed lookup with a 127.0.0.x address if the domain or IP is listed, and with nothing if it is not. Query nine of them directly.
for zone in dbl.spamhaus.org zen.spamhaus.org multi.surbl.org multi.uribl.com bl.spamcop.net b.barracudacentral.org dnsbl.sorbs.net dnsbl-1.uceprotect.net combined.mail.abusix.zone : dig +short DOMAIN_OR_REVERSED_IP.$zone
Result: not one of the nine — Spamhaus DBL and ZEN, SURBL, URIBL, SpamCop, Barracuda, SORBS, UCEPROTECT, Abusix — returns a listing. One caveat stated honestly: URIBL replies with the block code 127.0.0.1 to any query arriving through a public DNS resolver. That is a “can’t serve you” response, not a listing — a real URIBL listing is in the 127.0.0.2–127.0.0.14 range — and a careless checker that treats any answer as a hit would misread it. It is not a hit. This is the same clean result seven engines gave in June, re-run across nine in July.
The three factors they did fill in — verified, and hardened
Their claim: the three factors they do print — Domain Blacklist Status, HTTPS Connection, Domain Creation Date — all favourable.
The test and result: HTTPS goes further than their tick. The certificate is valid, issued by Let’s Encrypt, covering the domain and its wildcard. The server negotiates TLS 1.3 and refuses the obsolete TLS 1.0 and 1.1 outright — the insecure protocols a hardened server is supposed to reject. The response headers add HSTS with preload, X-Content-Type-Options: nosniff, a same-origin frame policy, a locked-down permissions policy, and a content security policy defaulting to self. Every objective security control their factor list gestures at is not merely present but tightened past the baseline.
The one factor I cannot measure, and why
Their claim: “Proximity to Suspicious Websites”, printed with no value.
The test: there isn’t one I can run — this factor draws on their private link graph, so only they can produce it. I flag it rather than skip it, because honesty about what cannot be tested is the difference between this report and theirs. What can be said is this: the same factor is printed as a plain 1/100 on their report for archive.md, a site they score 80.6. The number exists and the panel can display it. It is shown when it flatters and blank when it would have to serve as the evidence for a low score.
One honest note, because this article’s standard is that a check proves only what it checks. These results establish the absence of specific, named indicators — no listing, no Google threat, no off-domain form, no missing mail authentication. They do not prove a universal negative, and I am not claiming one. But that is precisely the standard their report fails: it asserts the presence of risk, in categories it names, and prints not one figure behind any of them. I have printed a figure behind every one. The fifth blank factor, Proximity to Suspicious Websites, is the only one I cannot reproduce — it draws on their private link graph — and it is also the one they leave empty on my report while publishing it, as a clean 1 out of 100, on a site they happen to score well.
Their own site, measured by the tools they scored 15.5
Scam Detector rated AIWebPageSEO Controversial, High-Risk and Unsafe. So I pointed AIWebPageSEO at scam-detector.com. Same checks, same thresholds, same code that runs for every other user of the platform, on 24 July 2026.
AIWebPageSEO E-E-A-T Checker: 10 out of 100
Experience, Expertise, Authoritativeness and Trust — the framework Google's own Quality Raters use, and the one that matters most for exactly the kind of high-stakes financial-safety content Scam Detector publishes.
- Experience 0/5. No author information in schema, no visible byline, no publication date.
- Expertise 0/5. No Article or BlogPosting schema, no FAQ schema, no external citations or outbound links.
- Authoritativeness 1/4. No Organization schema, no structured data, incomplete Open Graph. HTTPS passed.
- Trust 1/6. No canonical URL, no meta description, no about or contact page linked on the domain itself. Security headers passed. (The privacy policy is linked, but off-domain to the parent company — see above.)
Two passes out of twenty checks. A site that tells the world which businesses to trust carries no author, no credentials, no publication date, no citations and no organisation identity — the precise absences its own reports treat as red flags in others.
AIWebPageSEO AEO Checker: 17 out of 100 — and the crawlers are refused
The answer-engine check returned 17. But the significant finding was not the score.
A live server check — not a reading of robots.txt, but an actual HTTP request presenting each crawler's user-agent string — found scam-detector.com returning HTTP 403 in every case: GPTBot, PerplexityBot, ClaudeBot, Googlebot and Bingbot. Refused at server or firewall level, despite robots.txt permitting them.
One caveat, stated plainly because this article is about unqualified claims. Requests presenting a crawler's user-agent from an address outside that crawler's published IP ranges are routinely blocked as spoofing, and that is correct behaviour. Scam Detector ranks in Google, so live Googlebot from Google's own addresses is evidently admitted; the Googlebot and Bingbot results above should be read as anti-spoofing, not as search-engine blocking. The AI crawlers are a different matter. Our separate trust audit confirms their robots.txt explicitly permits GPTBot and ClaudeBot — it scores points for doing so. The published policy invites them; the server refuses them at the door. Whether by deliberate rule or blanket firewall policy, the effect is a site that advertises openness it does not practise.
It also runs none of the eight AI discovery files — no llms.txt, no ai.txt, no identity.json, nothing.
Sit with the shape of that. This is a company that publishes automated assessments of websites that never asked to be assessed, whose reports are built by fetching other people's pages, and which flags anti-bot protection as suspicious behaviour when it meets it. Its own terms of use forbid anyone from running a robot or spider against its property without written consent. And its server enforces that by returning 403 to the major crawlers.
Recall the review quoted earlier in this piece: a business owner whose site was wrongly scored because their anti-bot protection blocked Scam Detector's scanner. They were penalised for doing, defensively, exactly what Scam Detector does absolutely.
There is a practical consequence too. A site that refuses the AI crawlers is a site that cannot be read, quoted or corrected at source by the systems now answering "is this company legitimate?" for millions of people. Scam Detector's verdicts still reach those answers, through search results and third-party quotation, while the source itself stays shut. It is broadcasting into a conversation it will not join.
None of the above is our opinion of them. It is their own site, run through the same tooling, at the same thresholds, that produced the number they published about us.
AIWebPageSEO Website Trust Audit: 81, Grade A
Fairness requires publishing the result that does not suit us. The AIWebPageSEO Website Trust Audit — the same passive audit any visitor to aiwebpageseo.com can run, checking domain age, Safe Browsing, backlinks, identity signals, crawler behaviour, technology and TLD risk — scored scam-detector.com at 81 out of 100. Grade A. Trustworthy.
- Domain 100% — registered January 2011, fifteen years old, WHOIS published, registrar identifiable
- Reputation 100% — Google Web Risk clean, backlink spam score 25
- Authority 100% — 11,372 referring domains, 277,294 backlinks, domain rank 436
- Behaviour 100% — robots.txt present, crawlers allowed, AI crawlers permitted
- Technology and TLD 100%
That is not a grudging concession. It is the point.
The AIWebPageSEO trust audit assessed the same company this article has spent seven thousand words dismantling, and returned a warm A. It did so because it measures what such tools can measure: domain age, backlink profile, blacklist status, configuration. It has no way to know that the site publishes unnumbered risk scores, cites unnamed partners, ignores three correction requests, or asserts blacklist detections that seven engines contradict.
Which is the whole argument in one line. An automated trust score measures infrastructure, not honesty. Their 15.5 about us and our 81 about them are the same species of number, and neither one tells a reader whether the site in question is telling the truth.
The difference is not the arithmetic. It is what gets done with it. We are publishing our score of them alongside every check that produced it, the points each check carried, and this paragraph explaining what it cannot see. They published a number about us with no values, no named sources, no notification and no reply to three attempts at correction — and told readers to stay away.
What our audit did find
Where the audit deducted points, it deducted them for things a fraud-prevention authority might be expected to have:
- Identity 1/4. No contact email visible on the homepage. No Organization schema. No social profiles linked.
- On-Page 0/4. No About page linked. No Contact page linked. No Privacy link. No Terms link.
Zero out of four on the pages that establish who you are. A company that will not name a partner, does not publish an About page, links no contact address and hosts its terms on a different domain under a different trading name is asking for a degree of trust it does not extend to anyone it scores.
And one finding matters more than the rest, because it settles a question raised earlier. The audit awarded points for allowing AI crawlers: robots.txt explicitly permits GPTBot and ClaudeBot. Yet a live request presenting those user agents is met with HTTP 403. The published policy says come in. The server says no.
Credentials, checked
Scam Detector's standard description of itself states it is "an official contributor to the Federal Trade Commission", linking to the FTC's Consumer Sentinel Network data contributors page.
Open that page. It carries two lists.
The first is the data contributors: the Consumer Sentinel Network gives law enforcement access to complaints made directly to the FTC together with complaints shared by these organisations. It includes the AARP Fraud Watch Network, the Consumer Financial Protection Bureau, the Internet Crime Complaint Center, Microsoft's Cyber Crime Center, numerous state Attorneys General, the US Postal Inspection Service and Western Union.
Scam Detector is not on it.
It appears in the second list, under a separate heading for entities that refer complaints to the FTC. The other names in that list include Craigslist, eBay, LinkedIn, Indeed, Zillow, Costco, PepsiCo, several toll road authorities — and Scam Advisor, its direct competitor.
Referring a complaint to the FTC is something any organisation, or any member of the public, can do. Appearing on that list is not accreditation, endorsement, partnership or oversight, and the presence of supermarkets and toll operators on it makes that unmistakable. The page cited as proof of the claim is the page that disproves the version of it being made.
A company whose product is catching other businesses overstating their credentials, overstating its own on a document anyone can open.
Three near-identical domains, three different verdicts
The validator's own output is the neatest demonstration that it is not measuring what it says it measures.
- scam-detector.com — 100. "Safe. Secure."
- scamdetector.com — 55.9. "Questionable. Minimal Doubts. Controversial."
- scam-detecter.com — 3.6. "Young. Unsafe. Warning."
Three domains within a character or two of each other, in the same sector, scored across almost the entire range. If the algorithm were assessing fraud risk, that spread would demand an explanation, and none is offered on any of the three pages.
The explanation is visible in their own factor list: domain age, traffic rank, blacklists, WHOIS completeness. New and quiet scores low. Old and busy scores high. The tool is not detecting fraud. It is detecting establishment — and publishing the unestablished as suspicious.
It is not the largest. Here is the proof.
The claim leads the homepage and every profile the company maintains: the largest fraud prevention resource in the world. It is stated without a unit. Largest by visitors, by sites assessed, by staff, by database, by countries reached? None is specified, which is the first problem — an unquantified superlative cannot be verified, and under UK advertising rules a superlative claim is supposed to be substantiated on request.
Test it against the nearest comparable operator anyway. ScamAdviser does substantially the same job — an automated trust score for any domain — and, unlike Scam Detector, publishes its numbers:
- More than 4.5 million consumers using it every month
- Over 1 million new sites analysed monthly
- Trust-score APIs and data feeds supplied to law enforcement, cybersecurity firms, consumer authorities and brand protection agencies
- An estimated 1.5 billion consumers reached monthly through data partners
- Over 1,500 Trustpilot reviews, against Scam Detector's 600-odd
Scam Detector publishes no equivalent figure for any of those categories. Not one. In fairness, the two sites are comparable on raw web traffic — third-party estimates put Scam Detector around 2 million visits a month, and by some monthly measures it is ahead of ScamAdviser. But traffic to a website is not the same as the reach of a fraud prevention resource, and on distribution, data partnerships and institutional integration the published figures run one way only.
Then widen the frame, because "in the world" invites it. Trustpilot, whose ratings sit in the same decision a consumer is making, operates at a scale neither site approaches. So does the Better Business Bureau. And the actual fraud infrastructure is public: the US Federal Trade Commission's Consumer Sentinel Network, the FBI's Internet Crime Complaint Center, Action Fraud in the UK — national systems processing complaint volumes measured against populations, not page views. Scam Detector appears on the FTC's own page not as a peer but as one of well over a hundred entities that refer complaints inward, listed between a theatre company and a relationship-scam charity.
And finally, look at what it is. Not a security firm. Not an investigator. One brand among ten in the content portfolio of Zeus, LLC dba Guiding Tech Media, filed under "Everyday Tech" between a photography blog and an Apple tips site.
So here is the position on the evidence anyone can check. A website of roughly two million monthly visits, run by a small consumer-tech publisher in Puerto Rico, which publishes no data on users, sites assessed, staff or institutional partners, and which is outranked in its own field by a competitor's distribution, by two commercial review platforms, and by the national fraud agencies of several countries. That is not the largest fraud prevention resource in the world. It is not close, and no reading of the phrase makes it close.
Scam Detector could settle this in one line by publishing what it counts. It never has. A superlative that has gone unsubstantiated for years, on a site whose product is demanding substantiation from everybody else, is not a rounding error in the marketing copy — it is the same standard of evidence the validator applies to your business, turned on its author.
There are only two explanations, and the company is welcome to pick either.
The first is that it checked, and knows. The comparison is not difficult: the competitor's figures are on the competitor's own website, the FTC list is public, the traffic estimates are free to view. Anyone at the company could establish the position in an afternoon. If they did, the claim has been published in the knowledge that it is false.
The second is that they never checked at all — that the largest-in-the-world line has sat at the top of every page for years because somebody wrote it once and nobody ever tested it.
That is not the softer option. This is a business that sells verification. It publishes numbers to one decimal place about companies it has never contacted, tags them Unsafe and High-Risk, and instructs its readers that unverified claims are precisely what a scam looks like. An organisation whose sole product is checking other people's assertions, which never checked its own headline assertion, has disqualified itself by its own criteria.
Knowingly false, or never verified. On the evidence, one of those is true — and a company in the fraud-detection business does not get to shelter behind the second.
The law this runs into
"The algorithm did it" is not a defence, and it never has been. A publisher is responsible for what it publishes. Automating the writing does not change the authorship — a human built the system, a human chose to publish its output unreviewed, a human chose not to notify the subjects, and a human chose not to re-run it. Every one of those is a decision, and decisions carry liability.
Three regimes are engaged, and it is worth being precise about which protects whom.
Consumer protection: the DMCC Act 2024
On 6 April 2025 the consumer provisions of the Digital Markets, Competition and Consumers Act 2024 came into force in the UK, replacing the Consumer Protection from Unfair Trading Regulations 2008 and handing the Competition and Markets Authority direct enforcement powers — including the ability to impose fines without going to court.
The relevant prohibition is the misleading action: a commercial practice that gives consumers false information, or presents information in a way likely to deceive, causing a transactional decision they would not otherwise have made.
Apply that to a trust score. It is presented as an objective assessment. It sits on a page carrying advertising and affiliate links for security products. Its operator will revise it to 100 when the subject asks. A reader deciding whether to buy from a business is making a transactional decision, and they are making it on the strength of a number whose basis is not disclosed.
The CMA has said its early enforcement focus includes information given to consumers that is objectively false, and it published guidance in October 2025 actively encouraging well-reasoned consumer complaints. That route is open to anyone who relied on a score and found it wrong.
Defamation and malicious falsehood
This is the regime that protects the scored business rather than the reader. A published statement implying that a company conducts phishing or fraud, causing serious harm to its reputation, is the textbook shape of a defamation claim. Malicious falsehood covers a false statement about a business causing it financial loss.
At least one reviewer reports that a cease and desist letter produced a correction to 100 overnight. That tells you how robustly these scores are defended when someone with legal advice pushes back.
Data protection
Where the subject is a sole trader or an identifiable individual rather than a limited company, an automated score is personal data. UK GDPR carries a right to rectification of inaccurate data, and rights concerning solely automated processing that produces legal or similarly significant effects. A published risk score attached to someone's livelihood is a serious candidate for the latter.
What none of this is: a breach of fiduciary duty. Directors' duties under the Companies Act 2006 are owed to their own company and enforceable only by it. Nothing in company law gives a business you have wrongly labelled any claim against your directors. The argument that reaches them is the one above — publisher responsibility — not the one that sounds most severe.
This section is general information about the applicable regimes, not legal advice. Anyone considering action should take advice on their own facts.
The bottom line
Scam Detector may well do genuine good in its editorial work on fraud. That is a separate question from whether the Validator should exist in its present form.
An automated score becomes defensible at the point where the operator publishes its methodology, notifies the business before going live, shows the specific evidence behind a negative rating, and corrects errors without the target having to discover the damage themselves.
Until then, the most useful thing anyone can do with a Scam Detector trust score is treat it the way its own users have learned to: as an opening bid, not a finding.
Sources: Scam-Detector.com homepage and validator pages; Trustpilot review pages for scam-detector.com (600+ reviews); ScamAdviser published company figures; Similarweb and Semrush traffic estimates; the FTC Consumer Sentinel Network data contributors page; the Scam Detector validator report for aiwebpageseo.com; and the Terms of Use and Privacy Policy of Zeus, LLC dba Guiding Tech Media at guidingtechmedia.com. Blacklist status independently verified by direct DNS queries to Spamhaus DBL and ZEN, SURBL, URIBL, SpamCop, Barracuda and SORBS on 24 July 2026. Comparative validator scores for gov.uk, nhs.uk and aiwebpageseo.com recorded 24 July 2026. The Scam Detector report scoring aiwebpageseo.com 28.1/100 was archived to the Internet Archive on 25 July 2026 at web.archive.org, preserving the version described here. Server-side evidence — blacklist status across nine engines, Google Web Risk, TLS protocol support, security headers, SPF/DKIM/DMARC, a phishing-form test and a malware scan of 914 served files — produced by a read-only script on the aiwebpageseo.com server on 25 July 2026, Google Web Risk returning an empty (clean) result. The Scam Detector validator report for archive.md, showing 80.6/100, the identical corroboration, investigation and “innocuous suspicious” sentences, and a published Proximity score of 1/100, retrieved 25 July 2026. E-E-A-T and AEO results for scam-detector.com produced by the AIWebPageSEO platform, 24 July 2026, including live user-agent requests, and a Website Trust Audit of scam-detector.com returning 81/100 on the same date. All sources accessed July 2026. Statements attributed to reviewers are the opinions of those individuals as published on Trustpilot and are reproduced here as allegations, not as findings of fact. An email disputing the blacklist statement, attaching ownership and company registration evidence, was sent to Scam Detector on 17 June 2026 and received no reply; the statement remained published for a further five weeks. The owner of aiwebpageseo.com submitted Scam Detector's own verification process three times over the past two to three months, providing the business documentation it asks for, and also contacted the company directly by email. No response has been received to any of them. The report then changed on the night of 24 July 2026, still without reply or acknowledgement.
Check any of this yourself
Every result in this article came from tools that are free to run and produce the same output for anyone. If an automated score has been published about your business, these will show you what it was actually looking at.
- Site Audit & technical checks — what a crawler sees on your page
- E-E-A-T Checker — the trust signals Google's Quality Raters look for
- AEO Checker — whether AI crawlers can reach you, plus a live server test per bot
- All AIWebPageSEO tools — 14 free to run, no account needed
Share this page
Find us on
Comments
Been scored by an automated trust tool? Share what happened. Comments are reviewed before appearing, and nothing posted here feeds into any score.
Loading comments…