

The click-to-verify badge on a live store - visitors click it to open your live PCrisk scan report. Public badge on paid plans, from $16.95/month.
Shoppers who don’t know your store ask one silent question before they type a card number: is it safe to buy here? PCrisk Trust Badge answers it with a seal they can click and check for themselves.
PCrisk Trust Badge monitors your site for free and – on a paid plan – puts a “This website is safe” seal on it. The seal is backed by a security scan. Anyone can click the badge to open your live scan report: malware scan results, blacklist checks, and a trust score, verified by PCrisk’s website security scanner.
Every claim the badge makes is one your visitors can check for themselves.
An outside opinion on your site’s safety. PCrisk scans your website from the public web rather than from inside WordPress – the way an antivirus engine, a search engine like Google, or a shopper’s browser sees it – so you find out your online store has been hacked, defaced or blacklisted before your customers do. Continuous scanning covers virus and malware detection, phishing feeds, SSL validity and a domain blacklist checker across 90+ sources – among them Safe Browsing, Spamhaus, SURBL, PhishTank and URLhaus. Built for business sites and ecommerce stores with a hard-won reputation to protect.
The free plan is permanent, not a trial. Install the plugin, connect your site, and you get a monthly security scan across 90+ engines and blacklists, your trust score and verdict inside WordPress, and the result of every monthly scan by email – clean or flagged.
Paid plans add the part your visitors see: the public click-to-verify badge, daily scans, and the live report it opens.
The badge itself is served by PCrisk rather than by the plugin, so the verification it displays is issued by the party that actually performed the scan.
The badge is tied to the scan result, so it cannot stay up while your site is failing its own security check.
Antivirus engines and search-engine warnings sometimes flag perfectly legitimate sites – a new TLD, a plugin’s behaviour, a traffic spike, a pattern match gone wrong. Most site owners find out the hard way:
By then the damage is done. PCrisk surfaces new detections within minutes of the scan that finds them – monthly on the free plan, daily on paid – so a one-off false positive becomes a ten-minute fix instead of something you discover months later. And if it is a false positive, PCrisk gives you a dispute path.
Each scan runs your site through the full PCrisk detection stack – the same engine behind the public PCrisk website scanner. The free plan runs it monthly; paid plans run it every day.
Badge design and placement are yours to tune from the moment you install:
For e-commerce stores, the plugin detects WooCommerce automatically and adds dedicated store placements to its settings – no setup needed. They show a live badge once your domain has an active PCrisk verification:
Checkout is where trust matters most. Put the verified security badge at the exact moment of doubt, and let hesitant shoppers click to verify your store’s safety for themselves. Site-wide placements (footer, floating) cover the rest of your store.
Free plan: monthly security scan, your status in wp-admin, and every scan result by email – free forever, one site, no card. Paid plans add the part your visitors see: PCrisk issues a public verification for your domain, so the badge renders on your site, scans run daily, and your live report page and scan history go live – from $16.95/month, with a 14-day free trial of any paid plan. See pricing and plans.
This plugin connects to the PCrisk website security scanner (pcrisk.com) to power the badge:
Nothing is contacted without your consent. The admin screens make no request to PCrisk until you explicitly approve the connection on the plugin’s setup screen (or the settings screen’s connect card) – the approval text spells out what is shared before you agree. Your site’s public pages load nothing from PCrisk until you enable an automatic placement or add the badge block, and the pcrisk_trust_badge_enabled filter (FAQ above) can gate even that behind your own consent tooling.
https://scanner.pcrisk.com/badge/trust-badge.js is loaded by your visitor’s browser, which then requests your domain’s current verdict. As with any externally hosted script, that request carries the visitor’s IP address, browser user-agent and the page URL. PCrisk sets no cookies through the badge and does not track visitors across sites.https://scanner.pcrisk.com/api/badge/scan-summary/<your-domain> to show your trust score and verdict, and load the badge and preview scripts (trust-badge.js and trust-badge-preview.js) plus flag icons from the same host to draw the live preview. If your site has never been scanned – or the last result is stale – those two screens also embed the PCrisk scan runner (https://scanner.pcrisk.com/trust-badge/scan-embed) to start a scan of your domain. The block editor loads the same preview assets and makes the same read-only summary request once per editing session, but only when the page you are editing contains a PCrisk Trust Badge block – it is what tells you there whether the badge will actually render for visitors. Your domain name – plus a marker identifying the request as coming from the WordPress integration – is all that is sent, and no other admin screen contacts PCrisk.your-domain/wp-json/pcrisk/v1/verify, a small public endpoint this plugin provides, to confirm the plugin is still installed before spending a scan on your domain. It answers with a random site token, the plugin and WordPress versions, and when the badge dashboard was last used – nothing else, and the plugin itself never sends a request from your server.The free plan requires a PCrisk account (email only, no payment details). The public badge requires a paid subscription, which starts with a 14-day free trial. Service terms: PCrisk Terms of Service · Privacy Policy.