{"api":"url-screen","description":"Phishing / malicious-URL screening: a bundled URLhaus blocklist snapshot plus deterministic live heuristics. Verdicts are signals, never a safety guarantee.","checks":[{"id":"urlhaus_match","description":"Exact URL or host match against the bundled URLhaus blocklist snapshot."},{"id":"punycode_homograph","description":"Punycode (xn--) labels and mixed-script hosts that can impersonate a Latin brand."},{"id":"brand_lookalike","description":"Typosquat/lookalike of ~150 high-value brands (embedded domain, hyphenation, character substitution, edit-distance)."},{"id":"url_shape","description":"Structural red flags: IP-literal host, embedded credentials, @-obfuscation, deep subdomains, abused TLDs, URL shorteners."},{"id":"redirect_chain","description":"Optional (?follow=1): follows up to 5 SSRF-guarded redirects, re-screening each hop."}],"verdicts":["MALICIOUS_LISTED","SUSPICIOUS_PATTERNS","NO_KNOWN_SIGNALS"],"urlhaus_snapshot":{"source":"abuse.ch URLhaus (online URLs), CC0","generated_at":"2026-08-06T04:50:10.455Z","count":16061,"age_days":0},"heuristics":["punycode/homograph","brand lookalike / typosquat","url shape","redirect chain (opt-in)"],"limitations":["The URLhaus snapshot is NOT realtime — freshly-registered phishing may be absent.","Google Safe Browsing and OpenPhish are intentionally NOT consulted (their ToS forbid this kind of resale).","Domain age / WHOIS is not checked here — see the /domain-intel API.","No live page-content or malware analysis; nothing is rendered or downloaded (except opt-in redirect HEADs).","NO_KNOWN_SIGNALS is NOT a statement that a URL is safe."],"price":"0.005"}