api.modeflow.app
Category: Technology
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of api.modeflow.app
api.modeflow.app appears to be an API subdomain rather than a consumer-facing website. The visible response in the screenshot is a simple JSON-style message stating, "Please contact the site owner for access," which suggests the endpoint may be restricted to authorized users, developers, or internal application traffic instead of serving public content.
Based on the hostname structure, this subdomain is likely associated with a broader Modeflow service or application hosted under the modeflow.app domain. The use of an "api" prefix commonly indicates backend functionality such as authentication, data exchange, or application integration. No clear public branding, company details, or service description are exposed on the scanned page itself, so the operator and exact purpose cannot be fully confirmed from the available page content alone.
Safety Assessment for api.modeflow.app
Scan results indicate elevated risk signals at the time of this scan. The domain was flagged by 9 out of 90 security engines, with several classifying it as phishing or otherwise malicious. In addition, one threat-database provider listed the domain with a generic malicious-object label, while major browsing and URL-based blacklist checks shown in the scan were otherwise clean. The on-page content is minimal and access-restricted, which limits direct verification of the service's intended purpose.
At the same time, the malware scan of the retrieved content did not identify malicious files, and no external links, referenced domains, or iframes were found in the scanned response. The domain is also more than three years old, which can be a stabilizing factor, but age alone does not outweigh a multi-engine phishing consensus.
Based on these findings, this website may pose potential risks to visitors or systems interacting with it.
Technical Description
The subdomain is served over HTTPS with a valid TLS certificate issued by a mainstream certificate authority, and it is fronted by Cloudflare infrastructure. The server resolves to a Cloudflare IP address in Toronto, Canada, and uses Cloudflare nameservers. This setup may provide CDN and reverse-proxy functionality, but it can also obscure the origin server from public view.
DNSSEC appears to be unsigned, which means DNS responses may not benefit from DNSSEC validation. No obvious malicious scripts, external resources, or iframe activity were identified in the limited scanned content, but the endpoint returned only a restricted-access message, so the scan had limited visibility into any protected functionality behind the API.
Share your experience with this website. Was it safe? Did you encounter any issues?