Suspicious Website
Gridinsoft currently classifies this site as Suspicious Website. The report highlights 2 blacklist detections and no established public user-review history. These risks are driven by active warning signals despite the site's longer domain history.
Trust signal radarNormalized trust signals for url.sgDomain Maturity: 3117 daysDomain MaturityWarning Cleanliness: 2 detectionsWarningCleanlinessSafety Level: 1 negative tag, 2 warning signalsSafetyLevelPositive Signals: 3 positive signalsPositiveSignalsPopularity: Estimated low traffic without Tranco or social profile dataPopularityTrust Zone: .sgTrust ZoneOperational Signals: 0 detected servicesOperationalSignalsLocation Credibility: Hosting country USLocation Credibility
Figure 1. Trust signal radar for url.sg. Larger shaded area indicates stronger trust signals.
How we scored url.sg
Tech signals:
Cloudflare Browser Insights, Clipboard Support
Positive signals:
strong independent trust
a long-term domain history (8.5 years)
an active SSL certificate (3 months)
multi-language support
Negative signals:
security-provider warnings
multiple malware or phishing blacklist detections (2)
limited independent reputation data
Last checked August 10, 2026 at 5:22 AM by
Gridinsoft Trust Model v2.5.1
Share this report?
Independent Gridinsoft analysis
What Gridinsoft observed on Url.sg
A Gridinsoft threat analyst reviewed the site directly and documented the evidence behind this decision.
Current review
Review ID
GMA-20260810051441-b5eb74d0
Reviewed
by Gridinsoft Threat Analyst
Analyst finding
URL Shortening Service — Destination-Specific Review Required
Evidence basis
First-party site analysisExternal vendor intelligence: Context only — not used for this decision
The reviewed root site and public service pages did not show behavior supporting the prior domain-wide Distributes Malware or Unwanted File Download classification, and no specific malware file, payload, URL, or hash was found there. However, url.sg is a user-controlled URL-shortening namespace whose individual short codes can redirect to destinations that were not enumerated or reviewed. The service root appears operational, but the safety of the whole domain is inconclusive and each suspicious short link requires destination-specific review.
Analyst findings
Medium1
Low1
Info3
Info01
Substantive URL-shortening service
The reviewed public pages consistently described and implemented the same URL-shortening, QR-code, bio-page, analytics, and API service, including same-origin account and support routes.
Info02
Prior malware-download classification not supported in reviewed scope
The direct first-party review did not identify an automatic or suspicious download, a malware payload, credential forwarding to an unrelated host, conditional external navigation, or other current behavior supporting a domain-wide malware-distribution classification.
Info03
Public short-link abuse reporting is available
The service exposed a dedicated same-origin report form for spam, fraud, malicious, and phishing short links, providing a public route for destination-specific abuse reports.
Medium04
User-controlled short-link destinations require separate review
The service accepts user-selected destinations and issues redirecting short codes. The clean reviewed root and public service pages do not establish that every existing or future short code is safe, so the whole url.sg redirect namespace cannot receive a domain-wide Safe verdict from this scope.
Low05
Privacy and terms documentation needs correction
The privacy-policy link was unavailable and the Terms and Conditions page contained placeholder text. These gaps reduce transparency but did not demonstrate malware delivery in the reviewed scope.
Review 6 documented observations
View evidence
01Content
The reviewed public site presented a coherent URL-shortening and link-management service with substantive pricing, developer API, QR-code, bio-page, contact, account, and abuse-reporting interfaces.
Page elementThe homepage described URL shortening, analytics, targeting, QR codes, link management, branded domains, and an authenticated developer API as parts of the same service.
Page elementPricing, Developer API, QR Codes, Bio Pages, Contact, registration, and login pages consistently used the url.sg service identity and same-origin navigation.
Page elementThe public Report Link page accepted reports for spam, fraudulent, malicious, or phishing short links through the same-origin /report/send endpoint.
02Navigation
Repeated direct requests to the root and reviewed public pages returned the expected same-site content without an unrelated redirect, conditional external destination, or automatic download.
HTTP status200
Final URLhttps://url.sg/
Analyst observationBrowser-like, curl, Googlebot, and Bingbot client profiles all received HTTP 200 at the same https://url.sg/ destination with the same URL-shortener page title and purpose.
Analyst observationThe reviewed pricing, developer, QR-code, bio-page, contact, report, registration, and login routes each returned HTTP 200 at their expected url.sg destination.
03Form
The reviewed public forms and client code used same-origin endpoints for shortening, authentication, contact, and abuse reporting; no credential forwarding to an unrelated host was identified in the reviewed public code.
Page elementThe public shortening form posted a user-supplied destination to the same-origin /shorten endpoint and requested a Google reCAPTCHA token before submission.
Page elementRegistration and login forms submitted to the same-origin /user/register/validate and /user/login/auth endpoints.
Page elementContact and short-link abuse reports submitted to the same-origin /contact/send and /report/send endpoints.
Analyst observationThe public shortening workflow was not submitted because doing so would create a new public short link; the reviewed client code displayed the returned short URL and QR-code controls without initiating navigation or a download automatically.
04Download
The reviewed public scripts implemented ordinary interface, form, QR-code, and link-management behavior. No specific executable, malware payload, suspicious automatic download, or unrelated script-delivery mechanism was identified.
Analyst observationQR-code PNG, PDF, and SVG download routes were attached to explicit user controls after a link is created; the reviewed code did not trigger them automatically.
Analyst observationNo specific malicious file, payload, URL, or hash was identified in the reviewed public scope.
05TLS
The active hostname resolved through its published DNS and presented a currently valid HTTPS certificate and several response-security headers.
DNS factA records: 104.21.87.35 and 172.67.140.117; authoritative name servers: angela.ns.cloudflare.com and tom.ns.cloudflare.com.
Certificate factGoogle Trust Services WE1 certificate for url.sg and *.url.sg, valid from 2026-07-31 through 2026-10-29.
Certificate factThe reviewed HTTPS response included X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Origin-Agent-Cluster, and cross-domain-policy restrictions.
06Limitation
The reviewed policy presentation was incomplete: the privacy-policy link returned a not-found page and the Terms and Conditions page contained placeholder text.
HTTP status404
Page elementThe Terms and Conditions page displayed the placeholder sentence: Please edit me when you can. I am very important.
Analyst observationThese are transparency and documentation weaknesses; they were not evidence of malware delivery in the reviewed site behavior or code.
Scope and limitations
The review covered the root domain and listed public unauthenticated pages; no account was created, no credentials were submitted, and private dashboard, billing, administrative, and authenticated API flows were not accessed.
The public shortening form was not submitted because that would create a new public short link. The form and its client-side behavior were reviewed without creating content on the service.
A URL-shortening platform can redirect individual short codes to user-selected third-party destinations. This domain-level result does not certify every existing or future short code; a specific suspicious short link requires destination-specific review.
The result applies to the site content, code, infrastructure, and behavior reviewed at the recorded time and does not predict future changes.
What is Url?
According to its current page title, url.sg presents itself as “URL Shortener URL.sg - URL Smart Generator - URL”. The sections below evaluate the site-specific reputation and technical findings.
Figure 2.
Website screenshot for Url.sg.
2026-08-10 08:22:37
This domain was registered March 9, 2018 at 12:26 PM through the company Web Commerce Communications (S) Pte Ltd
and had the owner Gridinsoft privacy protected.
Complaint contact not found.
Is url.sg safe?
Use caution with url.sg. Its current Gridinsoft trust score is 35/100; review the site-specific findings below before use.
Why is url.sg marked "Suspicious Website"?
Gridinsoft's current assessment of url.sg is based on generic page wording. Context considered alongside those findings includes limited public traffic history. The listed status means the domain currently appears in Gridinsoft's own Threat List; it is not a consensus of external providers. 2 of 25 publicly displayed security sources report a warning.
A structured view of the site's detected themes, page signals, and related online footprint elements.
Registration Form
Automated page analysis detected form or data-entry functionality on url.sg. Forms can involve user-submitted information, so verify ownership and privacy terms before entering data.
Cookie Consent
This site implements a cookie-consent interface for managing tracking and data-collection preferences.
Multilanguage
The website provides multi-language support, demonstrating international accessibility and commitment to diverse user populations. Multi-language implementation typically indicates professional development standards and global operational scope, representing a positive trust indicator.
Google Tag Manager
This website uses Google Tag Manager to add and update tracking tags on its website.
Cloudflare Browser Insights
This website is proxied through Cloudflare's CDN/network and has Cloudflare Browser Insights enabled.
Clipboard Support
AI-generated Text
url.sg contains text patterns consistent with machine-generated or AI-assisted content production.
Long Term Domain
This site is registered for an extended period, which is generally a positive continuity signal.
Established Domain
This site has maintained active domain presence over time, indicating operational continuity.
Listed by Gridinsoft
Gridinsoft Internet Security classified url.sg as unsafe. As a VirusTotal partner, our detections contribute to broader protection across tools and browsers.
If you own Url.sg and want to challenge the trust score, please submit a review request via portal.gridinsoft.com. There you can claim your profile and add verified company/contact details. If you cannot access the portal, email legal(at)gridinsoft.com with proof of legitimacy and contact details. We never charge website owners for reviews or reconsideration requests. For more information, please review our Disclaimer.
A website report warns you. A PC scan protects you.
Unsafe sites can leave adware, unwanted apps, or hidden malware in downloads and browser settings. Run Gridinsoft Anti-Malware to check what may already be on this Windows PC.
Checks active threats, startup items, and suspicious downloads
Finds adware and unwanted apps linked to unsafe websites
Shows scan results before you decide what to remove
Your comment is currently undergoing moderation and will be published shortly.
Help protect others by sharing this page on social media! The more people who know about url.sg, the fewer chances they have to deceive someone else.Help others evaluate url.sg by sharing this page on social media!
Help protect others by sharing this page on social media! The more people who know about url.sg, the fewer chances they have to deceive someone else. Help others evaluate url.sg by sharing this page on social media!