scriptapi.dev
Category: Malicious
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of scriptapi.dev
scriptapi.dev appears to be a developer-oriented domain, likely positioned around scripts, APIs, or web-development tooling based on its name and its technology-related classification. The .dev extension is commonly used for software, developer services, and technical platforms, which suggests the site may be intended to host code-related resources, API endpoints, or supporting web infrastructure rather than consumer-facing content.
Based on the available scan context, the domain is using Cloudflare-hosted infrastructure and presents a valid TLS certificate, which is typical for modern web services. However, the classification data is mixed: one source categorizes it as technology, while several others associate it with malicious or malware-related activity. No clear evidence in the provided scan identifies a public company, organization, or verified operator behind the domain.
Safety Assessment for scriptapi.dev
The scan results indicate elevated risk signals at the time of this scan. The domain was flagged by 13 out of 91 security engines, and multiple web-classification providers associated it with malicious, malware, spyware, or similarly risky activity. While one malware scan reported no flagged files in its limited file scan, it still attached a generic malicious-object label to the domain and to a referenced challenge URL, which adds to the cautionary picture rather than offsetting it.
Blacklist and threat-database results were more mixed. Major content-malice databases in the provided data did not list the domain at the time of this scan, and DNS-based blocklist checks were clean, but one additional blacklist source did report a listing. That combination can occur when a domain is newly emerging in abuse reports or when detection coverage is still uneven across systems.
The domain is over one year old, which modestly reduces the likelihood of a throwaway setup, but the relatively high multi-engine detection count remains the stronger signal here. Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site is fronted by Cloudflare and resolves to an IP address in Cloudflare's network, with hosting geolocated to Toronto, Canada in the provided data. It uses a valid TLS certificate issued by Google Trust Services, with expiry extending to 2026-08-10. The web server is identified as Cloudflare, and the observed flagged URL includes a challenge-platform path commonly associated with traffic filtering or bot checks.
From a domain-security perspective, the domain is registered through Namecheap, is approximately 632 days old, and is set to expire in September 2026. DNSSEC appears to be unsigned, which is not uncommon but does mean DNS responses do not benefit from DNSSEC validation. No direct TLS misconfiguration was provided in the scan data, so the main technical concern comes from reputation and detection signals rather than from certificate or hosting setup alone.
Share your experience with this website. Was it safe? Did you encounter any issues?