</> Web Validators

Google Web Risk Checker

Google Cloud's Web Risk Lookup API, checked for malware, social engineering, and unwanted software matches.

Distinct from the site's Google Safe Browsing checker -- this queries Google Cloud's separate Web Risk product directly. Checks the domain's canonical HTTPS URL, or the exact URL/path you enter. This is one independent signal used by the Domain Security Score, and can also be run on its own for any domain or URL.

Based on: Google Cloud — Web Risk Lookup API (uris.search) · Google Cloud — Web Risk ThreatType Reference +2 more

About this validation

Checks a URL against Google Cloud's Web Risk threat lists for malware, social engineering, and unwanted software.

Rules reviewed:
Sep 8, 2026

SEOTechTests methodology: Data source: a live Google Cloud Web Risk Lookup API (uris.search) query against MALWARE, SOCIAL_ENGINEERING, UNWANTED_SOFTWARE, and SOCIAL_ENGINEERING_EXTENDED_COVERAGE. FAIL when Google returns one or more threat matches; PASS on an empty response (no match found at request time); UNKNOWN on any authentication, permission, quota, or provider failure -- never converted to PASS. A matched threat is cached only until Google's own returned expireTime, exactly as Google's Lookup API caching guidance requires; a clean result uses a conservative site-chosen TTL, since Google documents no required negative-cache duration for this API. Distinct product and credential from this site's separate Google Safe Browsing checker -- SEOTechTests does not treat the two as automatically independent confirmations of the same underlying Google threat intelligence, and Web Risk's own severity is capped so it can't stack a second critical-tier override on top of a Safe Browsing hit for what may be the same source data. This is SEOTechTests' own normalization of Google's response, not an endorsement by Google of the Domain Security Score.

Standards and vendor-documented behavior can change. This reflects the source as last reviewed above, not a permanent guarantee.

FAQ

What does Google Web Risk Checker check?

It queries Google Cloud's Web Risk Lookup API for the domain's canonical URL (or the exact URL you enter) against Google's malware, social engineering, and unwanted software threat lists.[1]

Why does SEOTechTests use Google Web Risk?

Web Risk is Google Cloud's own maintained threat-intelligence product for URL-level abuse detection, offered as a straightforward Lookup API suited to checking one URL per request.[4]

What types of threats can Google Web Risk detect?

Four categories: Malware, Social Engineering, Unwanted Software, and an extended-coverage Social Engineering list -- see the threat type reference for Google's exact definitions of each.[2]

Does a PASS mean that the website is completely safe?

No. A successful lookup with no matches means the checked URL was not found in the queried Google Web Risk threat lists at that time -- it is not a guarantee that the website is safe, only that this one source found nothing at the moment of the request.

What does UNKNOWN mean here?

The lookup itself failed or couldn't be completed -- a missing API key, an authentication or permission problem, a quota limit, or a timeout. UNKNOWN is never treated as a passing result.

How is this different from the site's Google Safe Browsing checker?

Both are Google products for detecting unsafe URLs, but Web Risk and Safe Browsing are separate APIs with separate credentials. Because their underlying threat intelligence can overlap, SEOTechTests doesn't automatically count a match on both as two fully independent confirmations.