{"id":3769,"date":"2017-09-29T13:12:10","date_gmt":"2017-09-29T19:12:10","guid":{"rendered":"https:\/\/www.whitefirdesign.com\/blog\/?p=3769"},"modified":"2017-09-29T13:12:10","modified_gmt":"2017-09-29T19:12:10","slug":"what-it-takes-for-sitelock-to-claim-a-website-is-at-low-risk","status":"publish","type":"post","link":"https:\/\/www.whitefirdesign.com\/blog\/2017\/09\/29\/what-it-takes-for-sitelock-to-claim-a-website-is-at-low-risk\/","title":{"rendered":"What It Takes for SiteLock to Claim a Website is At Low Risk"},"content":{"rendered":"<p>One of the more recent activities from the web security SiteLock that seem like it could be classified as a scam, is a score, from &#8220;low&#8221; to &#8220;medium&#8221; to &#8220;high&#8221;, that is supposed to indicate how likely a website is to be hacked.<\/p>\n<p>We first ran across it when a Forbes contributor <a href=\"https:\/\/www.forbes.com\/sites\/kalevleetaru\/2017\/08\/10\/how-minimizing-cyber-risk-can-actually-increase-it\/\">wrote about<\/a> how they were told that their website, which consists of a &#8220;static HTML page with a few images and a few locally hosted CSS, font and JavaScript files&#8221;, was at &#8220;medium&#8221; risk based on this score. When the author of the article raised question about this, SiteLock couldn&#8217;t even explain a way that the website could be hacked that was considered by their score despite claiming it was at &#8220;medium&#8221; risk of that happening. Another element that makes this seem like a scam was that SiteLock provided supposed percentages of the risk that that got to &#8220;medium&#8221; risk, which don&#8217;t seem believable. Most of the risk, 64%, came from the &#8220;Site size and the number of distinct components&#8221;, despite the website having only one page and no components that seem like they could have lead to the website being exploited.<\/p>\n<p>With SiteLock claiming that website was at &#8220;medium&#8221; risk, we wondered what it would take for SiteLock to claim is at &#8220;high&#8221; risk. A couple weeks later we got the answer, when we were contacted by someone that had been notified <a href=\"https:\/\/www.whitefirdesign.com\/blog\/2017\/08\/31\/123-reg-sending-out-scammy-emails-based-on-baseless-sitelock-risk-assessments\/\">that their website was at &#8220;high&#8221; risk based on the scoring<\/a>. So what kind of website is at &#8220;high&#8221; risk? One that only contained static HTML pages, but it did have multiple pages, so maybe that is enough for them to make that claim.<\/p>\n<p>The question that then left us with was what it would take for a website to receive a &#8220;low&#8221; risk score. The answer it seems, based on a recent tweet we ran across, is for a website where the domain name that isn&#8217;t even registered:<\/p>\n<blockquote class=\"twitter-tweet\" data-width=\"550\">\n<p lang=\"en\" dir=\"ltr\"><a href=\"https:\/\/twitter.com\/SiteLock?ref_src=twsrc%5Etfw\">@SiteLock<\/a> You email me security reports for a non-existent website. <a href=\"https:\/\/twitter.com\/hashtag\/LOL?src=hash&amp;ref_src=twsrc%5Etfw\">#LOL<\/a> <a href=\"https:\/\/twitter.com\/hashtag\/FAIL?src=hash&amp;ref_src=twsrc%5Etfw\">#FAIL<\/a> <a href=\"https:\/\/t.co\/XAs8rwhjrC\">pic.twitter.com\/XAs8rwhjrC<\/a><\/p>\n<p>&mdash; Brett (@BrettJo02676296) <a href=\"https:\/\/twitter.com\/BrettJo02676296\/status\/910973572213903361?ref_src=twsrc%5Etfw\">September 21, 2017<\/a><\/p><\/blockquote>\n<p><script async src=\"\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<p>This isn&#8217;t the only recent issue we have seen with SiteLock and an unregistered domain name, as several weeks ago we discussed a claim from <a href=\"https:\/\/www.whitefirdesign.com\/blog\/2017\/09\/07\/sitelock-claimed-website-had-critical-severity-malware-due-to-link-to-unregistered-domain-name-in-comment\/\">SiteLock that a website contained &#8220;critical&#8221; severity malware due to a link to an unregistered domain name<\/a>.<\/p>\n<p>In looking for other instances of the &#8220;SiteLock Platform Digest&#8221; show in that tweet, we ran across someone that <a href=\"https:\/\/en.forums.wordpress.com\/topic\/who-is-sitelock-and-why-are-they-sending-emails-saying-they-scanned-my-site\">had received it unsolicited<\/a> and SiteLock tried to claim that it was sent due to a web host, despite the web host having nothing to do with SiteLock.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>One of the more recent activities from the web security SiteLock that seem like it could be classified as a scam, is a score, from &#8220;low&#8221; to &#8220;medium&#8221; to &#8220;high&#8221;, that is supposed to indicate how likely a website is to be hacked. We first ran across it when a Forbes contributor wrote about how &hellip; <a href=\"https:\/\/www.whitefirdesign.com\/blog\/2017\/09\/29\/what-it-takes-for-sitelock-to-claim-a-website-is-at-low-risk\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;What It Takes for SiteLock to Claim a Website is At Low Risk&#8221;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[25],"tags":[39,158],"class_list":["post-3769","post","type-post","status-publish","format-standard","hentry","category-bad-security","tag-sitelock","tag-sitelock-platform-digest"],"_links":{"self":[{"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/posts\/3769","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/comments?post=3769"}],"version-history":[{"count":3,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/posts\/3769\/revisions"}],"predecessor-version":[{"id":3772,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/posts\/3769\/revisions\/3772"}],"wp:attachment":[{"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/media?parent=3769"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/categories?post=3769"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/tags?post=3769"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}