Changelog.
Shipped this week.
New features, improvements and data-source additions to the Alertoscan scanner, in reverse chronological order.
- v2.2.0
Performance & polish
Faster pages, friendlier mobile, and more reliable sign-in deep links.
- Faster pages: tool pages and scan results load noticeably quicker.
- Better on mobile: bigger tap targets in forms and filters; the cookie banner no longer covers the hero.
- Sign-in deep links: sharing a scan URL or report link brings you back to the exact page after sign-up or password reset.
- v2.1.0
Review pages redesigned, with sharing
A rebuilt review experience with a live network graph, shareable snapshots, embeds and exports.
Review pages have been completely rebuilt around three focused tabs and a live view of the scam network behind every domain.
- New layout: review pages are now split into Overview, Network and Forensics tabs, each loading on demand for a faster page. Widgets were stripped back to a clean icon-and-title style, and a redesigned hero surfaces the trust score, live status and key signals at a glance.
- Live network graph: the Network tab maps the full scam operation in an interactive bubble graph: domains coloured by trust score, outlined by uptime, clustered together and filterable by detection signal. The graph is computed live, so it always reflects the latest data.
- Forensics: timing, resources, redirects, cookies and a full scan history timeline are now grouped into clear, paired widgets.
- Share an analysis: capture a PNG snapshot of any network graph, embed an interactive version on your own site, or export the network as STIX 2.1, CSV or JSON.
- Threat Intelligence on every review: review pages now cross-link into the Threat Intelligence registry, surfacing the brand, infrastructure correlations and detection signals connected to each domain.
Tabs with nothing to show are hidden automatically, and count badges make it obvious where the interesting data is before you click.
- v2.0.0
Threat Intelligence registry
Browse scam networks, broker brands, detection signals and the infrastructure behind them.
The biggest addition to Alertoscan yet: a public Threat Intelligence registry that maps how scam operations are connected.
- Networks: clusters of domains forensically linked through shared infrastructure and code.
- Brands: fake broker identities rotated across fresh domains.
- Signals: genome signatures (build, favicon and DOM fingerprints) that link cloned sites.
- Infrastructure: pivot across IPs, ASNs, registrars, nameservers, mail servers, SSL issuers and favicon hashes.
Every entity cross-links to the full scan review pages, so you can move from a single suspicious domain to the entire operation behind it.
- v1.2.0
Fresher scan data
Scan results now refresh on a 10-day cycle with an automatic rescan.
Scan data is now considered fresh for 10 days instead of 7.
- Domains with data older than 10 days trigger an automatic full rescan when visited.
- Published review pages are held to the same freshness rule, stale reviews automatically refresh their underlying scan when visited.
- Fixed a caching issue where a manual rescan could still show old data.
- v1.1.0
Community blocklists
Four open-source crypto and phishing blocklists added to every scan.
Scans now cross-check four community-maintained threat feeds alongside Google Safe Browsing and Cloudflare:
- MetaMask: 205k+ Web3 phishing domains
- ScamSniffer: crypto wallet drainers
- Phishing.Database: ~1M phishing domains
- Crypto Scam Intel: drainers, romance and pig-butchering scams
Feeds refresh every 6 hours. Hits feed directly into the blacklist badge of the Trust Score, and multi-source hits escalate the severity.
- v1.0.0
CMVM added to the regulator list
CMVM (Portugal) investor warnings are now part of the regulatory check.
Alertoscan now matches domains against the CMVM: the Comissão do Mercado de Valores Mobiliários, Portugal's securities market regulator.
Any domain named in a CMVM investor warning is flagged automatically in its review page and contributes to the Trust Score.
- v0.6.0
Regulator co-listing links
Domains named together in the same warning are now one click apart on every scan.
When a regulator names several domains in one warning, those operations are usually connected. Scans now link them directly. If a domain you scan was co-listed with others, each one is reachable in a single click.
- v0.5.1
Score Evolution chart
A timeline of how a domain's Trust Score changed across every scan.
Scan pages now include a Score Evolution chart. Each rescan adds a new point, so you can see whether a site is getting cleaner, getting worse, or has been flat for months.
- v0.5.0
Scoring badges on every scan
See exactly which checks drove the Trust Score, and how serious each one is.
The Trust Score now comes with a breakdown. Every scan result shows the scoring badges that contributed to the score, one per check triggered, with its severity tier and any positive signals that offset it.
- v0.4.0
Scam farm detection
Scans now surface the other domains connected to the same scam operation.
Every scan now reveals the scam farm behind a domain, the cluster of other sites linked to it through shared infrastructure and code fingerprints. A wide farm pulls the Trust Score down; a long clean history adds a small bonus.
- v0.3.0
Password Generator
Strong passwords, passphrases and PINs, generated in your browser, never sent to a server.
A new tool: a Password Generator with three modes (password, passphrase, PIN). Everything is generated in your browser; no secret ever leaves the device.
- v0.2.0
BreachRadar
A free email breach checker, see every public data leak that exposed your address.
A new tool: BreachRadar. Enter an email and see every public data breach it appeared in, what was leaked, and when. We don't store the address you check.
- v0.1.0
Alertoscan goes live
A free scam URL checker backed by antivirus engines and financial regulators.
Alertoscan is live. Scan any domain in under a minute, no account required, and get a Trust Score, a clear verdict, and a permanent result page you can share.