Security Scan Report: www.saa.gov.uk

Submitted: Jan 22, 2026, 2:23:35 PMCompleted: Jan 22, 2026, 2:24:29 PMpubliccompleted
Loading additional data...

Summary

This website contacted 4 IPs in 1 country across 4 domains to perform 18 HTTP transactions. The main domain is saa.gov.uk and was registered NaN years ago.

Submitted URL: https://www.saa.gov.uk/central/

The Cisco Umbrella rank of the primary domain is #887,104 of the top 1 million websites

AI Security Verdict

High Risk

Confidence: 90%

8
Risk Score

Likely a compromised WordPress page harvesting credentials; do not submit any data.

Risk Factors
Compromised WordPress site indicator
Credential harvesting form (password field without username)
Hidden password fields
Low ranking in Cisco Umbrella for a purported official site
Domain age information unavailable

Details

Page Title

Central Scotland – Scottish Assessors Association Sites

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

government public service

(56%)

Domain Information

You're looking at domain 'www.saa.gov.uk' on the United Kingdom country-code top-level domain (.gov.uk) and includes subdomain 'www'. Count 3 characters in 'saa' with two vowels and one consonant. Tokenizing the label suggests 3 words: s, a, a. Average segment length settles at 1 character. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://www.saa.gov.uk/central/

Page Load Overview

2.85s
Total Load Time
65
HTTP Requests
4
Domains
428 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:4,956 chars
Detector Agreement:100%

Website Classification

Primary Category

government public service56% confidence
Type: spa
Method: ml+structural

All Detected Categories

government public service
56%
government
48%
real estate property
37%

Detected Features

Search

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
17172.66.158.152United States
AS13335CLOUDFLARENET
16192.178.170.95United States
AS15169GOOGLE
16142.251.140.163United States
AS15169GOOGLE
16104.16.175.226United States
AS13335CLOUDFLARENET
654--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T13353F8F368ACD13B516B52CDA070F728DAE6D107CB059254B7FC52AC9F91F9A09A3309

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:HPSyppU+qKo2bq2ZOOckJtiA8ZRXo1v3xqPXUzxyXT/kMhxYDIuDTXD8pRkSlz7C:HPL/UZKo2WLOckJtiA8ZRXo1v3xqPXUd

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:63735:YCiAAgAUBMoNwIKsAPgHEUgBRIGYBUKAEEIAg2QMAYJEAgdQmR8CpEFEL2nkOTR0CARY0UFAc8BAICUIMCw0XAgFESHyAQrQ

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:7f7f8080ffffff00
Perceptual Hash:d7d085807e76788d
Difference Hash:e0c210082ae9e849
Wavelet Hash:7e3f808088ffff00
Color Hash:#7c931f

Scan History

Scan history not available

Unable to load historical scan data