No site is automatically entered but only after validation by a consultant who has verified the same analyses (even in the case of positive analyses).
The starting point is a three-level analysis that ShopSicuro performs for each verified site. The first concerns the domain's technical infrastructure: how long it has been registered, what type of SSL certificate it uses, how its DNS is configured, and where its hosting server is physically located. A domain that's only been around for a few days, with a free certificate, and hosted in a high-risk jurisdiction, already accumulates several negative signals before even looking at the page content.
The second level examines what the site actually displays to visitors . The system verifies the presence of the VAT number and the legal pages that every e-commerce site should have, such as a privacy policy, terms and conditions, and a verifiable contact page. It then checks the payment methods offered: PayPal and credit cards are considered indicators of normality, while a site that only accepts bank transfers, PostePay top-ups, or cryptocurrencies immediately raises alarm bells. This is complemented by an analysis of the page's text quality, to detect placeholder content or carelessly copied text, and a price check: systematic discounts of over 70% are a typical pattern of fake shops, much more than an occasional offer.
The third level, perhaps the most crucial, queries external security intelligence sources. Google Safe Browsing reports whether the domain has already been classified as phishing or malware-ridden. VirusTotal aggregates the verdicts of over ninety different antivirus and security engines. IPQualityScore analyzes the domain's reputation with its own algorithm, assigning a risk score from 0 to 100 and identifying suspicious patterns linked to spam, parked domains, or previous fraudulent activity. This is complemented by a comparison with ShopSicuro's internal database, which cross-references the results with reports already received from users and previously classified sites.
Finally, the fourth step before being blacklisted is validation by our consultants , who confirm the checks performed by the automated systems.
From the score to the red light
Each check produces a value that is weighted based on its statistical significance in fraud detection: a match on the internal blacklist and a Google Safe Browsing result carry more weight than, for example, the mere presence of a valid SSL certificate. The weighted sum of all these signals produces a final score from 0 to 100, which translates into a three-color traffic light: green above 60 points, yellow between 30 and 59, and red below 30.
However, there are conditions that override the standard calculation. If a domain is already blacklisted, if Google Safe Browsing flags it as dangerous, if VirusTotal collects more than five reports from different security engines, or if IPQS confirms phishing or malware, the traffic light automatically turns red, regardless of how the site performs on other parameters. This mechanism is designed to leave no room for ambiguity when the warning signs have already been confirmed by independent external sources.
The role of user reports
In addition to automated checks, the blacklist also relies on direct reports from consumers who have had a negative experience with a particular site.
When a domain receives three or more unfiled reports, its overall score drops significantly, and this alone can lead to its inclusion in the list of confirmed scam sites.
This is important because it combines technical analysis with real-world experience: a site can have a technically flawless infrastructure and still behave unfairly toward those who buy from it.
A system that admits its own limits
ShopSicuro explicitly states that this is an automated evaluation based on technical and algorithmic parameters, and is not a certification of reliability or a guarantee of the commercial operations of the site operator.
False positives can occur, when a legitimate site receives a low score because it is new or has not yet completed some technical configuration, as well as false negatives, which are fraudulent sites that have taken care of their appearance enough to pass most of the automatic checks.
For this reason, anyone who believes their site's rating is incorrect can request a manual review, and anyone who identifies a suspicious site not yet listed can report it directly to the team.
In short, the scam website blacklist isn't a static list compiled once and for all, but the result of a process that updates in real time, combining automated technical checks, external intelligence, direct input from those who surf and shop online every day, and final validation by our consultants.