Early access · v2.1.1 For publishers · agencies · ad-tech · SaaS owners

Ad safety, phishing & tracker scanning,
transparently priced.

SevinShield drives a real Chromium browser through every URL you submit, records every network call, cross-checks every domain against 254,810 live threat-intel rows, scores trust signals (domain age, MX/SPF/DMARC, look-alike domains, scam-language, crypto-wallet blacklists), and tells you exactly what fired and why. No black box, no inflated numbers — and the public blocklist only contains hosts we confirmed ourselves.

Early-access pricing locks in for the first year. The product still has rough edges — we're documenting every fix in /docs.

Scans completed
Total since v1.0 launched
Scans today
Resets at 00:00 UTC
Malicious findings
High + critical severity
Intel database
Reference feeds we scan against
Active tenants
All plans
Confirmed blocklist
Real-browser verdicts only
Numbers above are queried live from our database. Until we have something real to count, we show "—" instead of inventing figures. As scans run, the counters update on the homepage in real time.

See it in action

Three real scans we ran. Click any card to open the full report — including the screenshot Chromium captured, every finding with evidence, and the new scam & trust signals panel.

clean #30
bbc.co.uk
Clean publisher scan
Scan screenshot

A real publisher with proper IAB TCF v2 consent detected, low-severity ad-trackers correctly classified as compliance signals (not malware). The kind of site you DON'T want flagged as malicious — and SevinShield agrees.

TCF v2 ✓No malware9 findings
Open full report
suspicious #22
jmc.edu.ph
Tracker + compliance issues
Scan screenshot

Looks legitimate at first glance, but missing the consent banner expected on an EU persona. 3 third-party trackers (Google Analytics, Meta Pixel, Cloudflare Insights) detected. Suspicious for compliance, not for fraud.

Missing CMP3 trackers3 findings
Open full report
malicious #29
binance-zh.com
Crypto phishing scam
Scan screenshot

A real PhishTank-listed Binance impersonator. Caught by our intel feed AND by the new lookalike detector (brand-in-stem) AND by scam-language heuristics. Trust deficit 6+/10 → low_trust_aggregate finding fired.

Lookalike: binance.com6 findingsPhishTank hit
Open full report

How a scan works

Submit a URL, we drive a real Chromium browser through it with one of eight device personas (iPhone, Pixel, desktop Chrome / Safari / Edge — in EN-US, PL, DE, RO locales). Every network call, cookie, redirect and script execution is recorded.

1. Submit a URL

From the dashboard, our API, or scheduled rescans on the domains you've registered.

2. Real browser run

Playwright + Chromium opens the page with a real device persona. Full DOM, real JS execution, full cookie storage — nothing emulated.

3. Detect & cross-check

Every loaded domain is checked against URLhaus, OpenPhish, MalwareBazaar, Google Safe Browsing and our heuristic detectors.

4. Verdict & report

Per-finding evidence, screenshots, full request chain, downloadable JSON / PDF. Aggregated into your tenant blocklist feed.

What we look for

Each detection is a rule with a fingerprint, so you can read why we flagged something — not just a score.

Known malicious domain

Loaded host matches URLhaus / OpenPhish / PhishTank / Safe Browsing.

Forced redirect

location.replace() to off-host within 3 seconds of load.

Cryptojacker

Known miner scripts (CoinHive forks, JSEcoin and friends) executed.

Popunder / popup abuse

window.open with negative coords, hidden focus, or auto-fire.

Permission abuse

Auto-requests for notifications / geolocation without user gesture.

Obfuscated JS

Heuristic: 95% non-printable in <script> + eval pattern.

Mis-leading destination

Display URL differs significantly from click-through final URL.

Excessive trackers

>10 distinct tracking pixels on one page.

Compliance: no CMP

No IAB TCF / OneTrust / Cookiebot / GPP signal detected on EU persona.

Content moderation

NSFW / gambling / weapons content detected in screenshots.

IP / domain reputation

Cross-referenced against StevenBlack hosts, EasyList, AdGuard DNS filter.

Fresh suspicious cert

New CT-log certificate on a look-alike of a known brand.

Honest pricing

No "contact sales" theatre. Everything is published — pick the tier, pay, get scans.

Free
€0/mo
  • 100 scans / month
  • Confirmed blocklist (JSON)
  • Full per-scan report
  • Dashboard access
  • Data export with 24h delay
Sign up
Agency
€299/mo
  • 100,000 scans / month
  • Multi-domain dashboard
  • White-label PDF reports
  • Priority queue
  • Webhook alerts
  • Dedicated support channel
Start Agency
Enterprise
Talk to us
  • Unlimited scans
  • Dedicated worker capacity
  • Custom detection rules
  • SOC 2 / DPA paperwork
  • On-prem worker option
Contact us

Who it's for

Same four verticals every grown-up ad-quality vendor serves. We start with the SMB end of each — fair price, real product.

Publishers

Block malvertising and offensive ads in real time. Subscribe to your blocklist feed from your ad server.

AdTech platforms

QA every creative before it ships. Categorise and identify regulated content.

Mobile apps

Verify monetisation partners aren't sneaking misleading offers, popunders or geo-fenced bad creatives.

Advertisers

Defend your landing pages and supply chain against impersonation domains and data leaks.