12 Best URL Scanners to Check for Security Risks
Compare 12 URL scanners by reputation checks, page behavior, privacy, access, and limits so you can choose the right way to inspect a link.
Short answer: choose a scanner based on the question you need answered. Multi-engine services such as VirusTotal aggregate reputation and detections. Browser-like services such as urlscan.io and Kaspersky’s web-address sandbox visit a page and show its behavior. Site-owner tools such as Sucuri SiteCheck look for malware and blacklisting. A clean result is only one signal, not proof that a URL is safe.
This guide compares 12 practical URL-checking options, explains what each one can and cannot tell you, and shows how to check links without exposing sensitive information unnecessarily. The services are grouped by use case rather than presented as a scientifically validated accuracy ranking; the reviewed official sources do not provide a common benchmark.
How to choose a URL scanner
| Your question | Start with | Why |
|---|---|---|
| Has this URL or domain appeared on known threat lists? | Google Safe Browsing, Cisco Talos, URLVoid | These provide reputation or blocklist signals. |
| What happens when the page loads? | urlscan.io or Kaspersky web-address sandbox | They visit the page and expose requests, contacted domains, resources, or other activity. |
| Can several security engines check it? | VirusTotal | It accepts a URL for analysis and returns an analysis record. |
| Is my own website infected or blacklisted? | Sucuri SiteCheck | It checks for known malware, blacklisting, errors, outdated software, and malicious code. |
| Is a shortened consumer link suspicious? | Bitdefender Link Checker | It expands shortened URLs before checking for malware, phishing, and counterfeit sites. |
| Do I need a visual record of what loaded? | ScreenshotNeo | It captures a clean screenshot or PDF through an API, with optional page controls and verdict headers. |
12 URL scanners and checking approaches
1. VirusTotal
VirusTotal’s URL API accepts a URL for scanning and returns an analysis ID. It is useful when you want a multi-engine view rather than a single provider’s verdict.
- Best for: aggregating detections and reputation signals.
- What it checks: submitted or queried indicators are scanned and added to the VirusTotal dataset.
- Privacy warning: VirusTotal says indicators become accessible to its community. Do not submit password-reset links, private invitations, authenticated URLs, confidential links, or personal data without considering that policy.
- Interpretation: a clean result means the selected engines did not identify a problem at that time.
2. Google Safe Browsing
Google Safe Browsing describes checks against lists of unsafe web resources, including phishing, social engineering, and malware resources.
- Best for: a straightforward unsafe-resource lookup.
- Access details: the documented Safe Browsing v4 API overview is marked deprecated and says the API is for non-commercial use. Google directs commercial use to Web Risk.
- Design distinction: Google contrasts simple URL lookup with a local-list approach intended to avoid sending the full URL on every check.
- Limit: list-based protection may not yet contain a new, targeted, or recently changed URL.
3. urlscan.io
urlscan.io automatically visits a submitted page like a regular user. Its scan records network activity, contacted domains and IP addresses, requested resources, and page information. Result views include a screenshot and DOM snapshot, and the documentation describes phishing and brand-impersonation verdicts.
- Best for: understanding page behavior, redirects, third-party requests, and visual impersonation.
- Privacy: review the visibility and submission settings before sending a sensitive URL.
- Commercial option: the documentation describes urlscan Pro for threat hunting; it is a business option, not a requirement for a one-off consumer check.
4. URLVoid
URLVoid says it checks websites against “30+ blocklist engines and online website reputation services” and returns sources plus other website details.
- Best for: a quick reputation cross-check.
- Privacy: URLVoid says submitted data is shared with security companies.
- Limit: blocklist aggregation does not prove that a page is harmless or that its current content is safe.
5. Kaspersky Threat Intelligence Portal lookup
The Kaspersky Threat Intelligence Portal accepts web addresses for lookup.
- Best for: an additional indicator or reputation lookup.
- Access: use the portal’s stated terms and privacy information when submitting URLs.
- Limit: a lookup result is not the same as a complete interactive visit.
6. Kaspersky web-address sandbox
Kaspersky’s documentation also describes registered-user web-address analysis that emulates opening a page in an isolated environment and reports activity.
- Best for: observing behavior that a reputation lookup alone cannot show.
- Requirement: web-address sandbox analysis requires registration.
- Privacy: submissions are subject to the portal’s terms and privacy statement.
7. Sucuri SiteCheck
Sucuri SiteCheck is aimed at remote checks of websites. It checks for known malware, blacklisting, errors, outdated software, and malicious code.
- Best for: checking a site you own or administer.
- Important limitation: Sucuri states, “Remote scanners have limited access and results are not guaranteed.” A clean report cannot rule out server-side or authenticated threats.
- Follow-up: if the site is yours, inspect server files, logs, CMS accounts, dependencies, and hosting controls as well.
8. Bitdefender Link Checker
Bitdefender Link Checker is a free consumer URL checker. It expands shortened URLs before checking for potential malware, phishing, and counterfeit sites.
- Best for: links received in email, messaging, or social platforms, including shortened links.
- Limit: Bitdefender says no scanner is foolproof.
- Safe handling: still avoid opening a suspicious destination simply because one check is clean.
9. Cisco Talos reputation center
The Cisco Talos Intelligence Center accepts URLs and domains as well as IP addresses and file hashes.
- Best for: an additional reputation signal when you want to compare providers.
- Limit: reputation data is only one view and may lag behind a newly created or targeted campaign.
10. Browser-integrated Safe Browsing checks
Many browsers use Safe Browsing-style unsafe-resource lists while you browse. This is a useful first warning layer for everyday navigation, but it is not an unrestricted public scanning API. Google’s official documentation distinguishes browser protection and list-based approaches from API access and notes the deprecated, non-commercial status of its Safe Browsing v4 API overview.
- Best for: blocking or warning during normal browsing.
- Limit: you may not receive a detailed report about redirects, scripts, network calls, or page content.
11. Google Web Risk for commercial checking
Google’s Safe Browsing documentation directs commercial use to Web Risk. Treat Web Risk as the commercial path to investigate when you are building a product or business workflow that needs Google’s unsafe-resource intelligence.
- Best for: teams evaluating a commercial Google threat-list integration.
- Before implementation: check current Web Risk documentation, quotas, pricing, authentication, and terms directly because those details are outside the reviewed Safe Browsing overview.
12. ScreenshotNeo visual capture and page verdicts
ScreenshotNeo is a website screenshot API and MCP server, rather than a blocklist database. It is useful when you need a visual record of what a URL rendered, a PDF, or an automated page capture that can be combined with your own security workflow. Its API response reports page verdict and billing headers, so failed or unusable captures can be handled separately from successful images.
- Clean captures: before capture, it accepts cookie or consent banners like a visitor and removes more than 60 known consent platforms, newsletter popups, and chat widgets; each step can be turned off.
- Capture controls: full-page shots with lazy images loaded, CSS-element capture, dark mode, device presets or custom viewports, retina scale, custom CSS and JavaScript, clicks, hidden selectors, selector or network-idle waits, request blocking, headers, cookies, user agent, authorization, timezone, geolocation, transparent backgrounds, resizing, caching, signed links, asynchronous jobs, webhooks, bulk capture of up to 100 URLs per call, usage reporting, and PDF options.
- Agent access: an MCP server provides
take_screenshot,get_page_info, andcapture_pdftools for Claude, Cursor, and other MCP clients. - Billing behavior: bot checks or CAPTCHAs, blank pages, timeouts, failed loads, and cache hits are not billed; inspect the
X-Page-VerdictandX-Billedheaders.
How to check a suspicious URL safely
- Do not open it first. Copy the URL as text. Be careful with links that contain personal tokens, session identifiers, password-reset parameters, or private invitation codes.
- Classify the question. Use a reputation lookup for a fast list check, a browser-like scanner for redirects and behavior, or a site-owner scanner for your own domain.
- Check submission privacy. VirusTotal says submitted indicators enter its dataset, and URLVoid says submissions are shared with security companies. Use a non-sensitive test URL when possible.
- Use two different signals for high-risk links. For example, combine a reputation lookup with a behavior scan. Multiple clean results still do not prove safety.
- Inspect the destination without authenticating. Never enter credentials, approve a push request, download an unexpected file, or disable security controls merely because a scanner reports no issue.
- Escalate when the context is sensitive. Ask your security team to analyze targeted, confidential, or work-related links in an approved sandbox.
Automating a URL check
For a reputation or behavior service, use its documented API and authentication method. Do not assume that a web form and an API have identical privacy, quotas, or commercial terms.
Example: preserve the URL as data in Python
from urllib.parse import quote
import requests
url = "https://example.com/path?q=one%20two"
# Send the URL only to a service whose submission policy you accept.
response = requests.post(
"https://api.example-scanner.invalid/scan",
json={"url": url},
timeout=30,
)
response.raise_for_status()
print(response.json())
The endpoint above is a structural example, not a real service URL. Replace it with the endpoint and authentication documented by the scanner you selected.
Example: cURL workflow
curl --fail-with-body --max-time 30 \
-H 'Content-Type: application/json' \
-d '{"url":"https://example.com/"}' \
'https://api.example-scanner.invalid/scan'
Or skip the browser setup
For a visual record of a page, call ScreenshotNeo directly. See the ScreenshotNeo API documentation for the complete option list.
cURL
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
Python
import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)
Node.js
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' }); const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
Cookie banners, newsletter popups, and chat widgets are removed before the shot. Bot checks, blank pages, and failed loads are never billed. The MCP server lets AI agents take screenshots, inspect page information, and capture PDFs. The Free plan includes 1,000 screenshots a month with no card, and paid plans start at $5 for 3,000 shots. Create a free ScreenshotNeo account.
How to interpret a scan result
| Result | What it means | What to do next |
|---|---|---|
| Flagged by a reputation list | The provider has an entry or detection associated with the URL, domain, or indicator. | Do not visit it; verify the alert with another trusted source and report it through your organization’s process. |
| Redirects to another domain | The visible link is not the final destination. | Review every hop and the final domain before deciding whether it is legitimate. |
| Suspicious scripts or requests | The page contacted resources or behaved in a way that needs investigation. | Inspect domains, IPs, downloads, and page context in an approved analysis environment. |
| Clean | No problem was identified under that service’s methods at that time. | Keep the original context in mind; new, targeted, or authenticated threats can evade remote scanners. |
| Unavailable or timeout | The service could not complete its check. | Retry later or use another method. Treat an unavailable result as unknown, not safe. |
Troubleshooting common problems
The scanner says clean but the message still looks suspicious
Check the sender, domain spelling, urgency, requested action, and destination after redirects. A clean result is not a guarantee; both Sucuri and Bitdefender document limitations on remote scanning.
The URL contains a private token
Do not submit it to a community or shared dataset. VirusTotal warns that submitted and queried indicators enter its dataset, while URLVoid says submissions are shared with security companies. Ask the owner to revoke or replace the token before analysis, or use an approved private sandbox.
A shortened URL is hard to evaluate
Use a service that expands it, such as Bitdefender Link Checker, or inspect the redirect chain in a behavior-oriented scanner such as urlscan.io. Do not follow the redirect in your normal authenticated browser.
The scanner cannot access the page
The page may require authentication, block the scanner, depend on a region, or simply be offline. Try an approved browser-like analysis service and record the failed result. A timeout is not evidence of safety.
Sucuri reports no malware on a site you own
Remote scanners have limited access. Review server files, access logs, CMS users, plugins, dependencies, and hosting controls directly. Sucuri explicitly says remote results are not guaranteed.
ScreenshotNeo returns a non-image response
Read the HTTP status and the X-Page-Verdict and X-Billed headers. Bot checks or CAPTCHAs, blank pages, timeouts, failed loads, and cache hits are not billed. Adjust waits, selector targeting, blocked resources, headers, cookies, or user-agent settings when the page needs them.
Performance, reliability, and cost considerations
- Latency: list lookups are generally simpler than a full browser visit. Behavior scans and screenshots must load resources, execute scripts, and follow redirects, so allow longer timeouts.
- Repeatability: results can change as blocklists, page content, redirects, and third-party resources change. Store the timestamp, submitted URL, final URL, and provider result.
- Privacy: use the least sensitive representation possible. Never send credentials or private tokens to a public submission service unless its policy and your organization permit it.
- Coverage: combine reputation and behavior evidence for important decisions. No single remote scanner sees every server-side, authenticated, or newly deployed threat.
- Cost: verify each provider’s current quotas and commercial terms before building automation. ScreenshotNeo includes 1,000 shots per month free with no card; Starter is $5 for 3,000, Growth $15 for 15,000, Pro $39 for 60,000, Scale $99 for 250,000, and Business $249 for 1,000,000. Yearly billing gives two months free, and every feature is on every plan.
- Caching: if you automate visual capture, choose a cache TTL that matches how often the page changes. ScreenshotNeo cache hits are not billed.
FAQ
Can a URL scanner prove a link is safe?
No. It reports what the selected service observed or already knew. New, targeted, authenticated, or conditional threats can be missed.
Should I scan a password-reset URL?
Not through a public or community dataset unless you understand the exposure. Treat the token as compromised and use an approved private workflow.
Which scanner is best for a website I own?
Start with Sucuri SiteCheck for a remote malware and blacklist check, then review the site directly. Use urlscan.io or Kaspersky’s sandbox when you need page behavior details.
Do scanners expand shortened links?
Bitdefender Link Checker says it expands shortened URLs before checking them. Behavior-oriented scanners can also reveal redirect chains.
What does ScreenshotNeo detect?
ScreenshotNeo is a capture and page-verdict service, not a malware reputation database. It helps you record what rendered and tells you whether the capture was clean, failed, blocked, blank, or served from cache through response headers.
How many scanners should I use?
For a high-risk link, use at least two different kinds of evidence, such as a reputation lookup plus a browser-like behavior scan. Do not treat agreement as proof.
