This company has verified ownership of the profile and can respond to reviews.
Low Security Risk
Signals are mixed:
security-provider warnings, with additional caution from unclear social-profile authenticity.
Trust signal radarNormalized trust signals for baikuder.comDomain Maturity: 5491 daysDomain MaturityWarning Cleanliness: 1 detectionsWarningCleanlinessSafety Level: 1 negative tagsSafetyLevelPositive Signals: 3 positive signalsPositiveSignalsPopularity: Estimated low traffic without Tranco or social profile dataPopularityTrust Zone: .comTrust ZoneOperational Signals: 1 detected servicesOperationalSignalsLocation Credibility: Hosting country TWLocation Credibility
Figure 1. Trust signal radar for baikuder.com. Larger shaded area indicates stronger trust signals.
How we scored baikuder.com
Tech signals:
Wordpress Platform, Cloudflare Browser Insights, SEO Optimization, Extended Data
Positive signals:
a long-term domain history (15 years)
the domain owner has claimed this profile
extended data
Negative signals:
security-provider warnings
unclear social-profile authenticity
Context signals:
visible website content
Last checked September 3, 2026 at 6:27 PM by
Gridinsoft Trust Model v2.5.3
Share this report?
Independent Gridinsoft analysis
What Gridinsoft observed on baikuder.com
A Gridinsoft threat analyst reviewed the site directly and documented the evidence behind this decision.
Current review
Review ID
GMA-20260903173912-fa772fd5
Reviewed
by Gridinsoft Threat Analyst
Analyst finding
Safe
Evidence basis
First-party site analysisExternal vendor intelligence: Contradictory context โ not used for this decision
The independent current review supports Safe for the observed public deployment of baikuder.com. All 51 current public pages and posts served the same office-supplies site without a phishing form, unrelated redirect, executable or archive delivery, malware payload, or harmful action. Public urlscan evidence confirms that /sima/index2.php was a concrete Microsoft-branded password prompt in October 2022 and that /sima.zip was recorded as a phishkit-tagged archive. Those exact paths now return HTTP 404 and are absent from the current inventory. The remaining SOCRadar and OTX indicators are current domain-level blacklist or bulk-feed context without a live exact object. They contradict the current first-party result but do not justify retaining a broad Gridinsoft warning for the deployment reviewed now. Continued WordPress hardening and monitoring remain appropriate because the historical incident was concrete.
Analyst findings
Info4
Info01
No current harmful behavior reproduced in the reviewed public deployment
The root, www variants, all 51 current public pages and posts, navigation, product catalog, policies, and same-origin contact form consistently served the Baikuder office-supplies site. No current phishing form, unrelated redirect, automatic program or archive delivery, malware payload, credential receiver, exploit, or harmful action was reproduced.
Info02
A concrete 2022 phishing object is historical and no longer served
The 2022 urlscan evidence is stronger than a domain-only label: it preserves an exact baikuder.com path rendering a Microsoft-branded password prompt and a separately recorded phishkit-tagged ZIP. All tested historical paths now return HTTP 404 and are absent from the current public inventory. This supports a remediated historical compromise, not an active phishing deployment.
Info03
Current blacklist indicators do not identify a live harmful object
The current SOCRadar result and repeated OTX pulses are domain-level blacklist or bulk-feed indicators. They do not supply a current exact URL, file, payload, hash, or observed harmful action. The public evidence therefore distinguishes the real but removed 2022 phishing path from the current propagated domain category.
Info04
Shared Cloudflare infrastructure is neutral context
The apex and www names use Cloudflare and a valid certificate, but those facts alone neither prove safety nor reproduce abuse. The current verdict follows from the exact public behavior and historical-path checks, not from the shared IP addresses or TLS certificate.
Review 8 documented observations
View evidence
01Navigation
The HTTPS root served the Baikuder office-supplies site, and the HTTP root plus the www variants converged on the same HTTPS apex. The public WordPress API enumerated 12 pages and 39 product or news posts. All 51 unique current public URLs returned HTTP 200 on baikuder.com without an unrelated final host.
HTTP status200
Final URLhttps://baikuder.com/
Page elementThe current public inventory contained 51 unique same-host pages and posts; all 51 returned HTTP 200.
Page elementThe reviewed catalog presented desk organizers, filing and storage products, business supplies, writing supplies, and individual CLS product pages.
02Form
The About, Contact, policy, catalog, and product pages consistently identified Baikuder as the office-supplies brand of CLS Industry Inc. The contact details matched the separate CLS corporate site. The only form found in the current public inventory was a same-origin contact form requesting ordinary name, email, subject, and message fields; no password, one-time code, payment-card field, or unrelated-brand sign-in was present. The form was not submitted.
Page elementAbout and Contact pages identify CLS Industry Inc., its Taiwan address, [email protected], and +886-4-22352206.
Public artifact URLhttps://www.cls.com.tw/CLS_Story.php
Page elementThe contact form action was /contact/ on baikuder.com.
Analyst observationNo current public form requested a password, one-time code, payment-card number, wallet secret, or unrelated account credential.
03TLS
The apex and www names resolved through Cloudflare and served the same site. The current certificate covered baikuder.com and *.baikuder.com from 2026-07-10 through 2026-10-08. DNS also published mail.cls.com.tw as the mail exchanger and a Google site-verification record. Shared Cloudflare addressing is infrastructure context and did not establish either harmful or safe behavior by itself.
DNS factbaikuder.com and www.baikuder.com resolved to Cloudflare anycast addresses during the review.
DNS factThe MX target was mail.cls.com.tw, and the apex published a Google site-verification TXT record.
Certificate factLet's Encrypt YE1 certificate valid 2026-07-10 through 2026-10-08 for baikuder.com and *.baikuder.com.
Analyst observationCloudflare shared-network placement was treated only as infrastructure context, not as a threat finding or a clean-site guarantee.
04Download
The complete current 51-URL public inventory and its WordPress-rendered content contained no link to an executable, installer, mobile package, script package, or archive. The reviewed navigation did not start an automatic download or an unrelated redirect, and no specific current malware file, payload URL, payload hash, credential receiver, exploit, or harmful action was identified.
Analyst observationNo .exe, .msi, .apk, .dmg, .zip, .rar, or .7z link was present in the current public page and post content.
Analyst observationNo automatic download, unrelated final host, current phishing form, malware payload, or harmful execution was reproduced.
05Historical content
Public urlscan records establish a concrete historical incident rather than only a domain label. On 2022-10-11, an OpenPhish-sourced scan of /sima/index2.php returned HTTP 200 with the title 'Sign in to your account'; the preserved screenshot showed a Microsoft-branded password prompt on the non-Microsoft baikuder.com host. A separate scan recorded /sima.zip as application/zip with miteru and phishkit tags. The ZIP bytes and a file hash were not available in the retrieved public record, so no malware-family or execution claim is made for that archive.
Public artifact URLhttps://urlscan.io/result/00cc286b-e90d-4d7a-b357-cc493892c708/
Public artifact URLhttps://urlscan.io/result/d98a3d83-428e-437e-b928-bd7fa9ae467b/
HTTP status200
MIME typeapplication/zip
Analyst observationThe historical page visibly requested a password under Microsoft branding on baikuder.com; the retrieved evidence did not prove where submitted data was sent.
Analyst observationThe historical ZIP was recorded and tagged as a phish kit, but its bytes, hash, and sandbox execution trace were unavailable for this review.
06HTTP response
The historical paths /sima, /sima/, /sima/index2.php, /sima/index2.php/, and /sima.zip each returned the current Baikuder HTTP 404 page as text/html. None appeared in the current public page or post inventory. Later urlscan observations from 2022 through 2026 show the credential path transitioning through 403 or 500 responses to ordinary 404 pages.
HTTP status404
MIME typetext/html; charset=UTF-8
Analyst observationAll five tested /sima variants returned HTTP 404 and none was linked from the current 51-URL public inventory.
Public artifact URLhttps://urlscan.io/domain/baikuder.com
07Historical content
The exact appealed host is also the registrable parent domain, so exact-host and parent-domain searches concern the same apex; www was checked separately. urlscan returned 25 public records, including the concrete 2022 phishing URL and ZIP, followed by later root pages and 404 responses. OTX returned repeated 2026 bulk-feed phishing pulses with baikuder.com as a domain indicator and seven URL observations; its latest root observation showed HTTP 200 with no Google Safe Browsing match. The current OpenPhish feed and exact public searches of Hybrid Analysis, Triage, ANY.RUN, URLhaus, and the exact historical URLs returned no current sample-level match. Authentication-only or unavailable APIs were not treated as clean evidence.
Public artifact URLhttps://urlscan.io/domain/baikuder.com
Public artifact URLhttps://otx.alienvault.com/indicator/domain/baikuder.com
Analyst observationA precise historical phishing page was independently distinguishable from current domain-only blacklist and bulk-feed indicators.
Analyst observationNo current malware sample, payload hash, or live harmful exact URL was found in the reviewed public scanner, sandbox, threat-intelligence, or feed indexes.
08Historical content
The Internet Archive availability service reported successful apex snapshots from 2018-08-06 and 2019-08-15. It reported no stored snapshot for /sima/index2.php or /sima.zip. Direct replay and the CDX listing were unavailable during the review, so the archived apex content was not used to assert what those pages displayed. The current site and public registration data separately show long-running domain and business continuity.
Public artifact URLhttps://web.archive.org/web/20180806074937/http://baikuder.com/
Public artifact URLhttps://web.archive.org/web/20190815203022/http://baikuder.com/
Analyst observationArchive availability identified two successful apex captures but no capture of either exact historical /sima object.
Analyst observationUnavailable archive replay was recorded as a limitation and not interpreted as clean content.
Scope and limitations
The appealed exact host is also the registrable parent domain, so exact-host and parent-domain OSINT both refer to the baikuder.com apex. The www variant was checked separately.
The review covered the current Gridinsoft report, HTTP and www redirects, all 51 current public WordPress pages and posts, navigation, forms, linked downloads, the exact historical /sima paths, DNS, TLS, public URL scanners, threat-intelligence indexes, sandbox-index searches, a current phishing feed, and available archive metadata.
No form was submitted, no account was created, no credential or personal information was entered, and no executable or archive was run.
The review did not inspect private server files, logs, administrator accounts, mailboxes, unpublished endpoints, WordPress administration, or the internal cause of the 2022 phishing publication.
The historic /sima.zip record exposed its URL, MIME type, and phishkit tag, but not retrievable bytes, a file hash, or a sandbox execution trace. No specific malware family or payload behavior is attributed to that archive.
Internet Archive replay and CDX listing were unavailable, while its availability API reported apex snapshots but no snapshot for either exact /sima object. Unavailable or authentication-only sources were recorded as unverified, not as clean.
Public search, URL-scanner, threat-intelligence, sandbox, feed, and archive indexes are incomplete; absence from an index does not prove that an unindexed event never occurred.
Safe describes the public deployment and exact paths observed at the recorded time. It does not guarantee future content, private server state, WordPress plugin security, account security, or that a remediated compromise cannot recur.
We reviewed baikuder.com and found mostly positive signals. Current checks lean toward a legitimate, lower-risk profile, although a few caution points still keep it short of a fully verified standing. The current trust score is 85/100. Key signals include security-provider warnings, a domain age of 15 years, and visible website content. Verify key details before sharing personal information or relying on the site for important actions.
FAQ
Is baikuder.com safe?
Based on current analysis, baikuder.com appears to be generally safe. The final verdict also reflects manual expert review. Basic verification is still reasonable before relying on the site.
Why does baikuder.com look trustworthy?
Key factors include registrar information (Net-Chinese Co., Ltd.) and hosting in US. The trust score blends security detections, domain and infrastructure signals, and on-page behavior patterns. The overall assessment is moderated by unclear social-profile authenticity, which keeps the report in a more cautious posture despite the cleaner technical checks.
Baikuder Digital Footprints
A structured view of the site's detected themes, page signals, and related online footprint elements.
Cookie Consent
This site implements a cookie-consent interface for managing tracking and data-collection preferences.
Fake Social Media Links - Risk
This site: Automated analysis found social media icons or links that did not lead to recognizable public profiles. This can result from outdated, incomplete, or template-based content. Check the links directly before relying on them to confirm the site's public presence.
Wordpress Platform
Our analyzer determines that website baikuder.com is using WordPress CMS. WordPress is the most popular content management system, powering over 43% of websites globally.
Google Tag Manager
This website uses Google Tag Manager to add and update tracking tags on its website.
Cloudflare Browser Insights
This website is proxied through Cloudflare's CDN/network and has Cloudflare Browser Insights enabled.
SEO Optimization
The baikuder.com website employs search engine optimization (SEO) techniques to improve its visibility and ranking in search engine results pages (SERPs).
jQuery Library
Extended Data
This site includes extended structured page data about entities, offerings, or site metadata.
Established Domain
This site has maintained active domain presence over time, indicating operational continuity.
Claimed Company Profile
The company behind baikuder.com has claimed its profile in the Gridinsoft portal and provided verified ownership details.
External provider warnings: 1/27
This section shows what independent external security sources say about this site.
A warning appears when one or more sources report malware, phishing, abuse, or other safety concerns. Each row shows the source and its verdict.
If no source reports a warning, the site is shown as clear in this section.
SOCRadar
Phishing
External provider results for Baikuder.com, last checked September 3, 2026.
โ VirusTotal
Domain Information
CreatedSeptember 14, 2011 at 10:06 AMUpdated: May 12, 2026 at 9:37 AM ยท Expires: September 14, 2027 at 2:06 AM
Domain Age15 years
RegistrantPersonal information withheldProtected by Gridinsoft
Hosting ProviderAS13335 Cloudflare, Inc.San Francisco, California, US
SSL CertificateYE1SSL certificate not verifiedTLS 1.3 ยท from July 10, 2026 at 1:34 AM ยท to October 8, 2026 at 1:34 AM
Name Servershaley.ns.cloudflare.com wesley.ns.cloudflare.com
Content from the analyzed website
Quoted for security analysis. These statements belong to the source website and are not endorsed by Gridinsoft.
Original page titleHome - Baikuder ็พ็งๅคง
Original descriptionSince our establishment in 1975, CLS Industry Inc. has evolved from a precision mold manufacturer in Taiwan into a trusted global OBM partner. ใ็พ็งๅคง๏ผBaikuder๏ผใๆฏ็ฑๅฐ็ฃ้บ่ณขไผๆฅญ่กไปฝๆ้ๅ ฌๅธ๏ผ...
Detection SignaturesThese signatures are used to generate the security fingerprint below.
Cookie ConsentFake Social Media Links - RiskWordpress PlatformSEO OptimizationjQuery Library
Verified ServicesThis domain has been verified by the following legitimate services and organizations, confirming authentic ownership and proper email security configuration.
Google Verification
Domain ownership verified by Google.
Security FingerprintUnique identifier based on site analysis
If you own Baikuder.com and want to challenge the trust score, please submit a review request via portal.gridinsoft.com. There you can claim your profile and add verified company/contact details. If you cannot access the portal, email legal(at)gridinsoft.com with proof of legitimacy and contact details. We never charge website owners for reviews or reconsideration requests. For more information, please review our Disclaimer.
A website report warns you. A PC scan protects you.
Unsafe sites can leave adware, unwanted apps, or hidden malware in downloads and browser settings. Run Gridinsoft Anti-Malware to check what may already be on this Windows PC.
Checks active threats, startup items, and suspicious downloads
Finds adware and unwanted apps linked to unsafe websites
Shows scan results before you decide what to remove
Your comment is currently undergoing moderation and will be published shortly.
Help protect others by sharing this page on social media! The more people who know about baikuder.com, the fewer chances they have to deceive someone else.Help others evaluate baikuder.com by sharing this page on social media!
Help protect others by sharing this page on social media! The more people who know about baikuder.com, the fewer chances they have to deceive someone else. Help others evaluate baikuder.com by sharing this page on social media!