Product

Verifiko

Explainable URL risk detection, built as a layered analysis pipeline.

A solo product that scores suspicious URLs for phishing and malware risk — and shows why. A layered pipeline behind a FastAPI service returns an explainable score with a per-signal decision trace instead of one opaque number. Live at verifiko.es.

Role

Solo project — product engineer. AI-assisted implementation; the spec, the review and the verification are mine.

Type

Product

Context

Context

Verifiko analyzes a suspicious URL and returns a risk verdict an analyst can actually review — not just "malicious", but which signals contributed and why.

It runs as a real product: a FastAPI service with a React and Vite workspace, built so the reasoning behind a score is visible and a verdict can be trusted or challenged.

Problem

Problem and constraints

The hard part is not flagging a bad URL; it is doing it without an opaque score, and fetching untrusted targets safely so the analyzer cannot be turned into an SSRF vector.

External lookups — registration data, TLS, reputation feeds, HTML fetches — fail or rate-limit, so the verdict has to stay sensible when some signals are missing.

Approach

Approach and technical decisions

A layered pipeline: static URL heuristics including typosquatting, domain recency from registration data, TLS and transport validation, and HTML credential-harvest inspection.

Reputation is aggregated across independent feeds and only counts when at least two agree, with a circuit breaker so an unavailable feed cannot skew the verdict.

Optional headless detonation sits behind a toggle, off by default, for deeper inspection of evasive pages.

Every verdict carries a per-signal decision trace, so the score is explainable instead of a single opaque number.

Architecture

Architecture

  1. 1Clean Architecture: explicit domain, application, infrastructure and entrypoint layers with ports and adapters.
  2. 2A durable async worker runs enrichment off the request path: jobs are persisted in PostgreSQL and dispatched through a signed QStash queue.
  3. 3FastAPI, SQLAlchemy and PostgreSQL with Alembic migrations; a React, TypeScript and Vite analyst workspace.

Decisions

Key decisions

01

Security by construction: an egress guard on every outbound fetch to prevent SSRF, plus signed webhooks (HMAC) and QStash signature verification on the async path.

02

Resilience: per-day quotas and rate limiting that fail open on outage, with heavier functions like detonation and reputation behind feature toggles, off by default.

03

Hardening and auditability: CSP and security headers on the API, and an explainable decision trace kept central so every verdict stays reviewable.

Outcome

Outcome

The result is a verdict you can defend: on a small, 40-URL labeled offline corpus the detection scores precision 1.00, recall 0.82 and a 0.00 false-positive rate, with 0.90 accuracy, measured by a deterministic evaluation harness.

The behavior is reproducible — 457 automated tests across 61 files — and the explainable trace lets a reviewer see exactly why a URL was flagged.

On PageSpeed Insights (1 Oct 2026) the site scored Performance 99, Accessibility 100, Best Practices 96 and SEO 100 on both mobile and desktop. The repository is private; source is available on request.