Model history
WebTrustScore model revision history
Every completed scan is stamped with the scoring-model and evidence-collection version that produced it — shown on each report as “Model X · collection Y”. This page records what each version changed. The model version moves when the scoring math, bands, or overrides change; the collection version moves when evidence gathering changes. Historical scores keep the version they were computed under and are never re-scored.
Model 5.4.0 · collection 3.3.3 — 2026-08-15
Domains offered for sale on a modern marketplace page are recognized again. A for-sale landing page used to be a thin placeholder; today the large marketplaces serve a full, working web page — navigation, written copy, payment options — and the scanner, which had been taught in July to treat a page with real content as a genuine site, was reading those pages as ordinary active websites and scoring them. Two things now identify a sale page regardless of how substantial it looks: the marketplace software the page is built from, and a page title offering that exact domain for sale — which is how a sale page describes itself and how an ordinary business does not, since a business names its brand rather than its web address. A site that merely mentions “for sale”, including property, vehicle and marketplace sites whose titles say exactly that, is unaffected, because the domain’s own name has to appear immediately before the phrase. A domain now recognized as for sale is reported as “For sale” instead of “Active site” and, as with any domain that has no operating site, receives no trust score. This changes only how a site’s live state is detected, not how the score is calculated.
Model 5.4.0 · collection 3.3.2 — 2026-08-05
Scans finish faster, and a check that cannot answer no longer holds up the rest. Each outside lookup now has its own time limit instead of every one of them sharing a single ten-second allowance: quick background checks such as DNS, registration records, and archive history are given only as long as a healthy service needs, while the checks that decide whether a site is actually reachable — and every malware and phishing feed — keep the full allowance, because cutting those short would mean checking a site less thoroughly. A lookup that fails is also remembered for two minutes, so one unreachable service is not waited on again and again within the same scan or a run of scans; two minutes is short enough that a brief outage clears on its own. Almost every site is unaffected. A site is only scored differently when one of the shortened checks was answering slower than a healthy service would: that check is now reported as unverified, which lowers the confidence in that part of the report and can therefore lower the score. Nothing about how the score is calculated has changed.
Model 5.4.0 · collection 3.3.1 — 2026-07-21
A site that is genuinely in use is no longer mistaken for its own “for sale” or parking page. Some real sites — most often domain-industry forums and marketplaces — fill their pages with other people’s sale listings and marketplace names, and the scanner was reading that as the site itself being for sale, then declining to publish a score. Now a page with real content and navigation is scored as the live site it is, while genuine parking and for-sale landing pages — including a domain that simply forwards to a marketplace such as Afternic or HugeDomains — are still recognized and still receive no trust score. This changes only how a site’s live state is detected, not how the score is calculated.
Model 5.4.0 · collection 3.3.0 — 2026-07-16
Fairer, more accurate reading of a site’s consumer documents and identity. A return or refund policy is now only expected of a site that actually sells online: a business, portfolio, or informational site is no longer marked down for lacking one — it is reported as “not applicable” instead of “missing.” A cookie disclosure that lives inside the privacy policy (the common arrangement) now counts as present rather than being reported missing when there is no separate cookie page. Ownership-identity checks now read the site’s footer contact and legal-entity details even on very long pages where that content previously fell outside the portion of the page the scanner examined, so large, well-run sites are no longer wrongly seen as lacking a contact channel or a named company. And a company’s own product names shown on its own site — for example “iPhone” on apple.com — are no longer flagged as a brand/domain mismatch, since a first-party product is not impersonation. Because these change how the evidence is read and, for non-store sites, how the transparency score is computed, every domain re-scores under model 5.4.0 / collection 3.3.0.
Model 5.3.0 · collection 3.2.0 — 2026-07-13
Refund recourse now grades the drip-pricing penalty. On a subscription-funnel site that hides its price behind a quiz (model 5.2.1), how a buyer can get their money back now sets the severity: a clear, discoverable refund or cancellation policy keeps the score at the least-severe level, a refund buried only in the fine print is treated as worse, and no refund policy at all — where the price is hidden and there is no way to recover money — is the most severe. Hiding both the price and the refund path is what marks questionable intent. This never applies to business, custom-quote, or consulting services: they do not run consumer subscription funnels (an app-store listing, quiz-style entry pages, and an auto-renewing subscription), and their pricing and refund terms live in a signed contract rather than online, so a refund that isn’t posted publicly is never mistaken for a missing one. The refund read is a checked absence — the terms page is already fetched for this pattern — and it withholds whenever the terms can’t be read. Model 5.3.0; evidence collection unchanged (3.2.0).
Model 5.2.1 · collection 3.2.0 — 2026-07-13
Drip pricing caps the trust score. A site that reveals its price only after a quiz or sign-up step — building commitment before disclosing the true cost — while showing no price upfront, on a confirmed subscription funnel (app-store plus quiz-style entry pages and an auto-renewing terms page), is now capped at 599 (the “Concerning” band) no matter how clean its other signals are. Hiding costs until after commitment is a deliberate manipulation pattern that research consistently shows inflates spend and completed purchases, and WebTrustScore measures honest dealing rather than whether the tactic works — so strong security, identity, or transparency signals can no longer buy it back. A price shown anywhere on the page clears the finding; a pricing link that still hides the number does not (that was the loophole a heavily-manipulative site used to slip through). The check fires only on the strong, positively-confirmed pattern and withholds whenever the page can’t be fully read or its terms can’t be fetched, so it cannot misfire on a transparent business. Model 5.2.0; evidence collection unchanged (3.2.0).
Model 5.1.0 · collection 3.2.0 — 2026-07-13
Recourse and citation-gap signals for subscription funnels. On a site that funnels visitors from an app-store listing through a quiz-style signup, the model now records two deterministic content findings drawn only from what the page itself shows: a “fabricated authority” finding when a “science-backed”-class claim appears with no verifiable outside research citation (a site’s own “research” link never counts), and a “hidden costs” finding when the page states its price is revealed only after a quiz while showing no price and no pricing link anywhere. A subscription-gated transparency check separately looks for a plain, discoverable way to cancel. Every absence-based conclusion withholds when the page can’t be fully read, so a site that cites its research or links its pricing is never flagged — the findings are matter-of-fact and each falls away the moment the page adds the missing citation, price, or cancel link. Both are medium-severity and can never cap a score. The report also now states the registrant’s country when it is confidently attributable, and says plainly when a privacy service withholds it. Collection 3.2.0 adds one or two same-site policy-page reads (the contact page, and on funnel sites the terms page) used only as evidence — never rendered, never sent to the semantic analyzer, and with no links followed. The homepage HTML link and text parsers were also rebuilt to run in linear time, removing a per-scan denial-of-service risk. Because new findings can lower a score, every domain re-scores under model 5.1.0.
Model 5.0.0 · collection 3.1.0 — 2026-07-13
Off-page reputation becomes its own category. A seventh category, External reputation, now measures how a site is regarded from OUTSIDE its own pages — authoritative threat and blocklist intelligence (Google Web Risk, abuse.ch URLhaus). It is negative-only by design: an adverse listing floors the category and caps the overall score, while the absence of a listing is reported honestly as “no adverse listing found,” never as an endorsement, so a site cannot buy standing and a rival cannot review-bomb a score down. The threat-feed verdict moved out of Reputation history (now the site’s own age and scan track record) into this new category, and the seven category weights were rebalanced (security 24, content 20, identity 16, reputation 12, external 10, transparency 10, resilience 8). Because the weights changed, every domain re-scores under model 5.0.0. A provenance context panel (site age, link authority, certificate history) is reported alongside the score but never folded into it.
Model 4.0.0 · collection 3.0.3 — 2026-07-13
Semantic content analysis now completes on long pages. The 3.0.2 retry proved insufficient: the structured-output decoder can fail on content-rich pages at any temperature, so those pages still fell back to deterministic checks only. When structured decoding cannot complete, the analysis now moves the exact output contract into the prompt and parses the reply — every finding is still validated field-by-field against the page text, so nothing is trusted on format alone. Scan diagnostics logging is also enabled, so a skipped semantic pass is now visible instead of silent. Collection only (3.0.3); scoring math unchanged.
Model 4.0.0 · collection 3.0.2 — 2026-07-13
Semantic content analysis no longer silently skips long pages. The structured AI review could deterministically fail on content-rich pages — precisely the pages the content signal exists for — leaving the category at its neutral rules-only baseline without saying why. The analysis now retries once with slightly relaxed decoding when the structured output cannot be completed, and failures are logged. Pages whose semantic review previously failed are re-analyzed on their next scan. Collection only (3.0.2); scoring math unchanged.
Model 4.0.0 · collection 3.0.1 — 2026-07-12
Content-detection hardening after release review. Three fixes to how content-trustworthiness evidence is collected: sign-in and checkout forms that post to recognized single-sign-on and payment providers (Okta, Cognito, Authorize.net, Adyen, Klarna, and similar) are treated as normal integration rather than data exfiltration; a sensitive form posting to an unrecognized external destination is still penalized heavily but no longer reads as confirmed phishing by itself — the Critical-Threat cap now also requires a mismatched brand claim, harvest-pattern language, or a high-confidence semantic finding, which real phishing pages exhibit and legitimate integrations do not; and a semantic finding now needs at least 12 characters of exactly-quoted page text, so degenerate quotes cannot validate a finding. Collection only (3.0.1); weights, curves, caps, and band thresholds unchanged.
Model 4.0.0 · collection 3.0.0 — 2026-07-12
Content trustworthiness. The score now measures six categories, adding a 20% content signal that reads what a site asks visitors to believe or submit — deceptive claims, brand impersonation, credential/payment harvesting, fabricated authority, coercive urgency, hidden costs, and obstructed choice. Page structure is checked deterministically and a schema-constrained Workers AI pass adds semantic findings only when it can quote the exact visible page text. Sensitive forms sent to an unrelated destination or used under a mismatched brand can cap the score at 299; high-confidence fraudulent or miracle claims cap at 399; multiple severe dark patterns cap at 499. The other five category weights were rebalanced. Model 4.0.0 / collection 3.0.0.
Model 3.3.0 · collection 2.3.1 — 2026-07-11
Browser-verified reachability. Some parking and CDN edges block non-browser clients outright, so the raw scan fetch failed and a domain every visitor could see was reported as having no live site. When a name resolves in DNS but the direct fetch fails, the scan now loads the page once in a headless browser — the same fallback used for lander classification — and reports what it renders: a for-sale lander reads as for sale, a real page as a live site. Collection only (2.3.1); scoring math unchanged.
Model 3.3.0 · collection 2.3.0 — 2026-07-11
Better detection of parked and for-sale domains. A common current parked-name format (GoDaddy) serves a bare page that redirects in the browser to a same-site lander whose “for sale” content renders only in JavaScript — so a raw scan saw no for-sale cue and treated the name as an active site. The scan now recognizes that lander from its parking bundle, so a parked or listed-for-sale domain is reported as such and, like other domains with no operating site, receives no trust score instead of a misleading one. When a suspected lander matches no known marker at all, the scan now renders it in a headless browser and reads the “for sale” text a raw fetch cannot see — so future lander formats are classified from what they render, without waiting for a new marker. Collection only (2.3.0); no signal weights, curves, or band thresholds changed.
Model 3.3.0 · collection 2.2.0 — 2026-07-08
Malware and phishing checks on every scan. The URLhaus threat feed (abuse.ch) — previously an off-by-default option — is now part of standard evidence collection on all tiers, free scans included, once its free API key is configured. A URL listed as actively distributing malware or phishing now counts against security and reputation on every scan, and a free scan’s malware/phishing check can read “checked” instead of “not checked”. Premium scans additionally keep Google Web Risk. Scoring math is unchanged: the threat components and caps that consume this evidence were already in the model.
Model 3.3.0 · collection 2.1.0 — 2026-07-06
Fairer scores when evidence sources are dark, and better registration lookups. Scoring (3.3.0): a signal whose evidence could not be collected at all — for example, a registry that publishes no usable registration data — is now excluded from the weighted score and the remaining signals are renormalized; previously it stayed in the math as a zero and could cost a legitimate site up to a fifth of its score. When less than half of the model’s evidence weight is collectable, no score is published at all; the report explains what could and could not be checked. Collection (2.1.0): registration (RDAP) lookups now query the registrable domain, so scanning a www address no longer loses registration identity and domain age; WHOIS-privacy placeholders such as “DATA REDACTED” no longer count as an organization name; and when a registry does not publish a registration date, domain age falls back to the site’s first Internet Archive capture, which cannot be backdated. Signal weights, curves, and band thresholds are unchanged.
Model 3.2.0 · collection 2.0.1 — 2026-07-01
No score for a domain with no site. A domain that has no operating site to trust — it redirects to a different domain, shows a parking placeholder, is listed for sale, or has no reachable site — no longer receives a number at all; the report and badge state the situation (and, for a redirect, name the destination) instead of publishing a score that would misrepresent a vacant name. This replaces the previous approach of capping such domains at 599. A redirect that stays on the same registrable domain (www → apex, a subdomain, http → https) is not a redirect for this purpose and scores normally. No signal weights, curves, or band thresholds changed — the five-signal math is unchanged for real sites.
Model 3.1.0 · collection 2.0.1 — 2026-07-01
Live-site-state caps. The scan now reads what a visitor actually lands on and, when there is no operating site to evaluate — a parking placeholder, a domain listed for sale, or no reachable site at all — caps the trust score at the top of the “Concerning” band (599) and says why, so a vacant domain with clean transport and DNS can no longer read as trustworthy. A cross-domain redirect to another brand is disclosed on the report but does not change the score yet. The state (Active site / Parked / For sale / Redirects to … / No live site) is shown as an overlay beside the score. No signal weights, curves, or band thresholds changed; the five-signal math is otherwise identical.
Model 3.0.0 · collection 2.0.1 — 2026-06-12
Collection fix: an origin that cannot be contacted (the edge returns a 520–530 “origin unreachable” response instead of failing outright) is no longer counted as a reachable site with valid TLS, so unreachable or non-existent domains stop earning transport credit.
Model 3.0.0 · collection 2.0.0 — 2026-06-12
Major upgrade. Added an explicit confidence score (per signal and overall) reported separately from the trust score and shown on free scans, with a band cap when confidence is low. Added invalid-TLS (cap 699) and brand-impersonation (cap 499) overrides, multi-URL malware/phishing checks on premium, optional opt-in reputation sources (off by default), and deeper identity, email-authentication (DKIM), and consumer-transparency checks.
Model 2.1.0 · collection 1.1.0 — 2026-06-10
Collection reliability. A registry fallback for ownership lookups and a more honest handling of blocked page crawls fixed two bugs that had been understating scores. Scoring math unchanged.
Model 2.0.0 · collection 1.0.0 — 2026-05-29
First public scoring model: five weighted signals — security, ownership identity, reputation, consumer transparency, and operational resilience — combined into a 0–1000 trust score across seven bands, with critical-risk caps for confirmed malware and phishing.