Security Scan Report: sageandcelery.com

Site favicon
Submitted: Sep 16, 2026, 8:47:36 AMCompleted: Sep 16, 2026, 8:48:39 AMpubliccompleted

AI Security Verdict

High Risk

Confidence: 82%

8
Risk Score

Legitimate-looking, long-established food blog whose WordPress appears compromised: critical IDS alerts show exploit-kit/Gholoader C2 traffic and a malicious third-party resource. Avoid until cleaned.

Risk Factors (5)
Critical exploit-kit command-and-control network traffic associated with the page load
Third-party script/font resource served from a Gholoader C2/TDS domain loaded by the page
Primary domain carries a single-source malware ('fakeupdates') threat-intel report
Evidence of WordPress compromise injecting malicious admin-ajax.php callbacks
Dynamic code execution observed (4 eval() calls, 1 Function() constructor call)
Domain age information unavailable

Details

Page Title

Sage & Celery • Creating the best version of you

Scan Type

public

Domain Name Analysis

Domain 'sageandcelery.com' uses the commercial generic top-level domain (.com) with no subdomain. The second-level label 'sageandcelery' is 13 characters long with 5 vowels and eight consonants. Segmentation suggests three words: sage, and, celery. Median word length comes out to 4 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://sageandcelery.com

Page Load Overview

19.06s
Total Load Time
6.8 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en-US
Text Length:5,954 chars
Detector Agreement:100%

Website Classification

Primary Category

adult content95% confidence
Type: spa
Method: ml+structural+ocr_tiebreaker

All Detected Categories

adult content
95%
corporate
35%
healthcare medical
27%
forum
25%
news/blog
20%

Detected Features

Search
Articles
Comments
OG: website
Schema.org

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
20104.17.24.14Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
3146.75.120.84Fastly · CDNFrankfurt am Main, Hesse, Germany
AS54113Fastly, Inc.
365.9.130.44Cloudfront · CDNUnited States
AS16509Amazon.com, Inc.
365.9.130.109Cloudfront · CDNUnited States
AS16509Amazon.com, Inc.
3104.20.23.134Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
374.220.219.234Phoenix, Arizona, United States
AS46606Unified Layer
3142.251.20.97Google · CDNUnited States
AS15169Google LLC
365.8.131.78Cloudfront · CDNUnited States
AS16509Amazon.com, Inc.
3172.67.205.249Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
3142.250.154.155Google · CDNUnited States
AS15169Google LLC
12235--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T19E33833CE448011B351EC6ADBCD572E8CB7E1635AD35176774B020948A58EFBE0E2B7A

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:gOJ8DO2o4TZdypa9LIEjEXNk3nFkXcI0i0Ie4fA/TdeGK:hJ8DjoIyp3EjEX0deGK

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:52022:iFIDxZFAwYCYITC9AlBxpGbOcAErGRqshAXLBCDGkYcgsaB3oMZAQyBhBEpCLBDQhQyDRUBOxBC1AoohgYIBMEMgeAGAwErF

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffe7ffc3c3c3e383
Perceptual Hash:e79299673a9c6988
Difference Hash:0e0c322f0f0f0b33
Wavelet Hash:ffe7d38381c1c181
Color Hash:#e0a66c

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data