Security Scan Report: metamask-docs-p13jojaa8-consensys-ddffed67.vercel.app

Redirected to:
https://metamask-docs-p13jojaa8-consensys-ddffed67.vercel.app/metamask...
Site favicon
Submitted: Sep 21, 2026, 12:45:24 AMCompleted: Sep 21, 2026, 12:46:30 AMpubliccompleted

This website contacted 8 IPs in 1 country across 11 domains to perform 19 HTTP transactions. The main domain is metamask-docs-p13jojaa8-consensys-ddffed67.vercel.app and was registered 6 years ago.

Submitted URL: http://metamask-docs-p13jojaa8-consensys-ddffed67.vercel.app/metamask-connect/

Effective URL:

https://metamask-docs-p13jojaa8-consensys-ddffed67.vercel.app/metamask...
Redirected

AI Security Verdict

High Risk

Confidence: 75%

7
Risk Score

Unofficial Vercel-hosted page copying MetaMask developer documentation, flagged by a single-source phishing report and IDS alerts for abused cloud hosting. No forms found, but treat as high-risk.

Risk Factors (2)
Primary domain reported as phishing by threat intelligence (single-source).
IDS alerts for actor-abused cloud hosting service (vercel.app) in DNS and TLS SNI.
Domain age information unavailable

Details

Page Title

MetaMask Connect - Dapp Wallet Integration SDK | MetaMask developer documentation

Scan Type

public

Domain Name Analysis

The domain name 'metamask-docs-p13jojaa8-consensys-ddffed67.vercel.app' uses the application-focused generic top-level domain (.app) with subdomain 'metamask-docs-p13jojaa8-consensys-ddffed67'. The second-level label 'vercel' is 6 characters long with two vowels and 4 consonants. Word splitting yields two words: ver, cel. Average segment length settles at 3 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of http://metamask-docs-p13jojaa8-consensys-ddffed67.vercel.app/metamask-connect/

Page Load Overview

8.28s
Total Load Time
1.9 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:5,923 chars
Detector Agreement:80%

Website Classification

Primary Category

technology software82% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

technology software
82%
cryptocurrency blockchain
66%
documentation technical
65%
corporate
35%
cryptocurrency
22%

Detected Features

OG: website
Schema.org

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
5216.198.79.131Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
218.245.31.100Cloudfront · CDNUnited States
AS16509Amazon.com, Inc.
2104.17.208.5Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
264.239.123.129Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
218.245.31.78Cloudfront · CDNUnited States
AS16509Amazon.com, Inc.
264.29.17.131Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
264.239.123.65Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
218.245.31.35Cloudfront · CDNUnited States
AS16509Amazon.com, Inc.
198--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1A48123B2E310AD2877534BA9B515F054C362E31BDA9E181276EC03A45BE8770A5F3B53

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

48:SsCSyfpmATWgGi79ViVxL8ewFzErNl1Ve/b+gY9W:JPycgWVq9Ms1YL1hW

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:4050:gIQE00IAgEgCACAAABACBIQiAUALAAwhABAAIAEARBEoQEIAGKAE0BCAAAOQFCBAoLIABDAOSEBJCCYFBAARBABgAAAgBIgY

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffffc7573f1f2f3f
Perceptual Hash:81fcda03ed747c12
Difference Hash:b0a92fd6f6f6deee
Wavelet Hash:42ff87031f03073f
Color Hash:#80862d

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data