Webroot Reputation Index
Webroot maintains a reputation score for more than 300 million URLs called the Webroot Reputation Index (WRI).
Webroot Reputation Index includes several hundred security related data points about a web site or IP address. For instance, many phishing sites reside on recently registered domains, so domain age acts as a signal for whether an associated site might have questionable content and reduces the site's WRI.
Similarly, it is common practice for malware providers to generate fake news sites and post links with relevant news stories that are picked up by search vendors. Webroot discovers these sites leveraging the Webroot Intelligence Network and gives them a low WRI.
Many enterprises use WRI in conjunction with Webroot category data to protect their users from harm. An enterprise may permit access to sites in the "News and Media" category (e.g., cnn.com, nytimes.com), but restrict access to all sites with a WRI less than 40. Users attemping to go to a "News and Media" site with a low WRI are given a warning that their computer may be at risk.
WRI data is available to both OEM and Web Service customers.
To see the WRI for a URL, use the URL Lookup text box on the left hand side of this page.
| WRI | Description | |
|---|---|---|
| 1-20 | ![]() |
These are high risk sites. There is a high probability that the user will be exposed to malicious links or payloads |
| 21-40 | ![]() |
These are suspicious sites. There is a higher than average probability that the user will be exposed to malicious links or payloads. |
| 41-60 | ![]() |
These are generally benign sites, but have exhibited some characteristics that suggest security risk. There is some probability that the user will be exposed to malicious links or payloads. |
| 61-80 | ![]() |
These are benign sites, and rarely exhibit characteristics that expose the user to security risks. There is a low probability that the user will be exposed to malicious links or payloads. |
| 81-100 | ![]() |
These are well known sites with strong security practices, and rarely exhibit characteristics that expose the user to security risks. There is a very low probability that the user will be exposed to malicious links or payloads. |









