Web Catalog · established 2011 Full Information About Any website
Straight to the entry
Reference

Site Safety and Reputation Checks: What SiteAdvisor and Web of Trust Rated, and What Replaced Them

Two services defined site reputation for a decade. Both are gone, and the badges they issued are still on thousands of pages.

Measurement layer6 sectionsReviewed 2026-08-26
A shield-shaped geometric plate scanned by a horizontal band of light, with small tick and cross marks arranged in a column beside it.

What "safe" was supposed to mean

Site reputation services conflated several different questions under one word, and untangling them is most of the work. "Is this site distributing malware" is a technical question with a mostly factual answer. "Will this shop send me the thing I paid for" is a commercial question no scanner can answer. "Does this site hold opinions I dislike" is neither, and it repeatedly leaked into crowd-sourced ratings.

The services that mattered most sat at two ends of this range. SiteAdvisor scanned automatically and answered the technical question reasonably well. Web of Trust asked users and answered the commercial and reputational questions at the cost of being gameable. Both were free, both were cited constantly, and neither survives in its original form.

SiteAdvisor: automated scanning

SiteAdvisor launched in 2005 out of a research project and was acquired by McAfee the following year. Its method was mechanical rather than social: crawl sites, download what they offered, execute it in instrumented environments, submit forms to test-mail addresses and record what arrived. A site that served malware, or whose downloads bundled unwanted software, or whose signup form produced spam, was marked accordingly.

That approach had real merits. It was reproducible, it was hard to argue with, and it caught the specific behaviours it tested for. Its weaknesses were also structural: it could only judge what it had crawled, coverage of smaller sites was thin, and a clean rating meant "we found nothing" rather than "this is trustworthy". The ratings were eventually folded into McAfee's consumer product and rebranded, and the standalone public lookup page, the one that every badge and citation pointed at, was withdrawn.

Web of Trust: crowd rating

WOT took the opposite approach from 2007: let users rate sites on trustworthiness, vendor reliability, privacy and child safety, then aggregate the ratings weighted by rater reputation. At its peak it had a large participating population and a genuinely useful signal on exactly the questions automation cannot reach: whether a shop ships, whether a subscription can be cancelled.

It had the failure modes crowd systems always have. Coordinated rating campaigns worked. Sites could be damaged by disagreement rather than by conduct. And in 2016 an investigation reported that browsing data collected by the extension was being resold in a form from which individuals could be re-identified. The extension was pulled from the major browser stores. A product under the name returned afterwards, but the participation that had made the database meaningful did not.

The pattern, once again

Both services were free at the point of use and funded by something else: a security suite in one case, data collection in the other. When the funding mechanism changed, the free citable surface disappeared. That is the same shape as Alexa Rank and it is the recurring theme of the closed measurement tools.

What is worth checking now

Three checks, three different questions

CheckAnswersLimits
CertificateWhether the connection is encrypted, who issued the certificate, and to what name.Says nothing about the operator's honesty. Free automated issuance made this a very low bar.
Safe Browsing statusWhether major browsers will actively warn users away from the site.Binary and reactive. A newly built fraudulent site will be clean until it is reported.
Multi-engine reputationWhat a range of security vendors currently say, in one view.Vendors copy each other, so agreement is weaker evidence than it looks. False positives persist for months.

Two habits are worth more than any of the three. Read the domain's own registration record: a name created three weeks ago, behind full redaction, promising a decade of trading history, has told you something no scanner will. And read the TXT records, which frequently list every service the operator has ever verified against the domain, and are unusually candid about how real an operation is.

What a certificate does and does not prove

A domain-validated certificate proves one thing: at issuance, the applicant could demonstrate control of the domain, usually by publishing a token in DNS or serving a file. It says nothing about identity, legitimacy or intent. Since automated issuance became free and universal, every site of any kind has one, including every fraudulent one, and the browser padlock has correspondingly stopped carrying the reassurance users still attach to it.

The parts of a certificate that do carry information are the issuer, the validity window and the subject alternative names. A certificate covering a long list of unrelated names points at shared infrastructure. A certificate issued minutes before you looked, on a domain registered days earlier, is consistent with a site that did not exist last week. Neither is proof of anything, and both are more informative than the padlock.

Reading a safety badge

A great many sites still display trust badges from services that no longer operate, and the badges are usually static images rather than live verifications. The test is simple: click it. A live badge resolves to a verification page naming the domain. A dead one resolves to a redirect, a generic marketing page, or nothing at all: and a badge that was never live in the first place is just an image somebody saved.

That is worth doing before treating a badge as evidence, and it is the same discipline this whole section rests on. Prefer sources that a system is obliged to publish over figures a company chose to sell, because the first kind is still there when you go back to check.

Many small directional marks converging around a single central gauge, standing for an aggregated crowd verdict.
Crowd rating answered the questions automation could not reach, and could be moved by anyone willing to organise a few hundred accounts.

Frequently asked questions

What happened to McAfee SiteAdvisor?

It was folded into the wider McAfee product line, rebranded as WebAdvisor, and its standalone public lookup, the part everybody actually linked to, was withdrawn. The rating survives inside the consumer security product; the citable public page does not, which is why a large number of "verified safe by SiteAdvisor" badges now point nowhere.

Is Web of Trust still usable?

Not as it was. WOT was removed from the major browser extension stores in 2016 after an investigation found that browsing data it collected was being resold in insufficiently anonymised form. A product under the name returned later, but the crowd-rating database that gave the original its authority never recovered its participation.

Which safety checks are worth running now?

Three, in this order. Certificate validity and issuer, which is free and immediate. Google Safe Browsing status, which is what browsers actually enforce and therefore the one that has practical consequences. And a multi-engine reputation aggregator for a second opinion. All three answer different questions, and none of them tells you whether a site is honest.

Does a valid certificate mean a site is safe?

No. A certificate proves that whoever controls the domain was able to prove that control to an issuer. Since free automated issuance became universal, that is a very low bar, and a fraudulent site will have a perfectly valid certificate. A padlock means the connection is encrypted, not that the other end is trustworthy.