Verdict
coffeecatcafe.org shows high-risk / scam indicators.
This assessment found strong scam indicators. Do not pay, sign in, or share personal details with this site.
| What this site appears to be | Retail storefront focused on coffee and home goods with product listings, ratings, prices, and standard ecommerce features (cart, add-to-cart, buy now). Includes promotional banners (VIP program, discounts), shipping and return policy text. |
|---|
Evidence status and limitations
Evidence completeness: UNKNOWN
- The real-world operator identity was not independently verified.
- Module-level completeness metadata is unavailable for this legacy report.
At a glance
The checks that decide most of this verdict.
| Malware engines | 13 flagged itVirusTotal | Risk |
|---|---|---|
| Google Safe Browsing | Not listedGoogle | Clear |
| Abuse reports on the host | 0 reportsAbuseIPDB; shared hosting inflates this count | Noted |
| Domain age | 2 months oldMost scam domains are under a year old | Risk |
| Web archive | Archived since 2018Public history exists | Clear |
| Certificate | Encrypted connectionIssued by WE1 | Noted |
The page as captured
Key findings
- Automated classification: Sensitive Interaction Risk.
- Domain age: less than 1 year (registration continuity).
- Public web-archive history exists since 2018.
- At least one reputation service TrustSniffer consulted had flagged this domain at assessment time.
Full analysis
Security Alert
Fortinet, Sophos flagged this site in external intelligence checks, indicating elevated compromise/scam exposure that requires immediate caution.
This website is an online retail storefront presenting coffee, kitchen, and home-goods merchandise through product listings, prices, ratings, promotional offers, cart functionality, and checkout, with an apparent business model based on direct consumer sales and a VIP sales program.
Scam/Impersonation Risk
The site carries a critical sensitive-interaction risk because external security intelligence recorded a confirmed blacklist status, 13 malicious detections, and one suspicious detection, including detections associated with Fortinet and Sophos. This is a direct contradiction to the otherwise ordinary storefront presentation. The homepage appears to be a conventional shop for items such as milk frothers, kettles, espresso machines, coffee tables, and tea accessories, with “up to 40% off” promotions and a VIP program; the page review found no obvious phishing indicators, hidden forms, wallet activity, or suspicious external submissions. Those benign page characteristics do not offset the confirmed external threat signals, and the site should not be treated as suitable for login, credential submission, checkout, or other sensitive interaction. No distinct legal-entity identity contradiction or brand impersonation was identified in the supplied page analysis.
- External reputation telemetry: 13 malicious detections, 1 suspicious detection, `external_blacklist: true`, and Tier-1 threat detections associated with Fortinet and Sophos.
- Homepage: standard ecommerce content for coffee, kitchen, and home products, including cart/checkout functions, promotional banners, shipping information, and return-policy text.
- Behavioral inspection: 0 wallet-connect runs, 0 wallet-sensitive runs, 0 wallet-drainer runs, 0 hidden forms detected, and 0 external posts or external XHR requests.
Regulatory Verification Notes
The available evidence does not independently verify the operator’s real-world identity, and the site’s legal and governance disclosures remain unclear. The website presents itself as a retailer rather than a regulated financial service, but the available pages do not establish a legal entity, corporate registration, or applicable consumer-protection status. A separate broker-reputation dataset reported no match; this is limited contextual information and is not a licensing or regulatory determination. Historical provenance is also inconsistent: the historical record places the domain’s continuity in the 2018–2025 period, while the current registration record reports a 2026 creation date. That discrepancy should be resolved before relying on the site for commercial engagement.
- Domain records: historical domain age `8.030116358658454` years with first seen `2018-08-09T20:01:00Z`; current registration record lists creation `2026-06-19T10:22:33Z` and age `0.17` years.
- Web-archive telemetry: `0` total snapshots, first seen `2018-08-09T20:01:00Z`, last seen `2025-07-17T05:02:18Z`, and `8` years tracked.
- Hosting telemetry: served from `AS13335` through `CLOUDFLARENET - Cloudflare, Inc., US`.
- Transport encryption: TLS issued by `WE1`, validation level `DV`, valid to `2026-11-15T19:11:23+00:00`.
What to Verify Next
Before any commercial interaction, an independent party should establish the operator’s legal identity through corporate and consumer-protection records applicable to the seller’s claimed jurisdiction. The terms, shipping, returns, contact, and checkout pages should then be checked for consistent seller details, enforceable return arrangements, payment protections, and an independently confirmed support channel. Until those checks are completed and the external detections are resolved, sensitive engagement should remain suspended.
- Legal and policy pages: confirm that the seller’s legal name, jurisdiction, terms of sale, shipping obligations, and returns process are internally consistent.
- Checkout flow: confirm the merchant descriptor, payment processor, refund mechanism, and availability of buyer-protection controls before any transaction.
- Contact page: independently confirm the published business and support channels through a separate, trusted route.
Summary Verdict
The overall posture is critical and unsuitable for sensitive interaction. The site’s conventional retail appearance is outweighed by confirmed external threat and blacklist contradictions, while the operator’s identity remains unverified.
Infrastructure Integrity
Cloudflare CDN/WAF protection is present, with all observed addresses belonging to Cloudflare edge infrastructure and no origin-server address observable in the analysis. This reduces direct exposure of the hosting origin and may mitigate some infrastructure-level abuse, but it does not establish legitimacy or counteract the external reputation findings.
Closing Assessment
Prospective users should not log in, submit credentials, provide payment information, or conduct other sensitive transactions through the site unless independent identity, merchant, and security verification produces a satisfactory resolution.
Written analysis generated 2026-08-21 by the TrustSniffer Analysis Engine from the evidence in this report.
What the analysis found
2 findings contributed to this verdict, raised by registration and ownership, analysis engine, external reputation.
01 Governance Risk
- The public registration record for this domain is incomplete.Registration and ownership
rule:KF_WHOIS_INCOMPLETE
02 Sensitive Interaction Risk
- The analysis matched a pattern TrustSniffer treats as a direct threat to a visitor.Analysis engine
signal:direct_threat - An external threat feed lists this domain: either Google Safe Browsing marked it malicious, or a significant number of malware engines flagged it.External reputation
rule:EXT_BLACKLIST_CRITICAL
Identity verification
| Status | UNVERIFIED |
|---|---|
| Identity score | 30/100 |
| Identity verification confidence | 50% |
- No on-site identity signals detected
Identity verification measures whether the site can be independently connected to a real-world brand or person. It is separate from the classification confidence.
What TrustSniffer observed
First-party facts recorded during the assessment of coffeecatcafe.org.
- The request stayed on coffeecatcafe.org. It was not redirected to another domain. Clear
- Registration is published under Spaceship, Inc.. Clear
- DNS for this domain is served by cloudflare.com, across 2 name servers. Noted
- The registration is paid up to 2027-06-19. Noted
- The earliest public archive of this site is from 2018-08-09. Clear
- It is hosted on CLOUDFLARENET, from a server in US. Noted
Domain intelligence
| Registrar | Spaceship, Inc. |
|---|---|
| Hosting | CLOUDFLARENET - Cloudflare, Inc., US |
| Country | US |
| Server IP | 2606:4700:3031::6815:12a2 |
| Name servers | stella.ns.cloudflare.com, venkat.ns.cloudflare.com |
| SSL issuer | WE1 |
| SSL expiry | 2026-11-15 |
| Domain age | 0.17 years (continuous registration) |
| Domain expiry | 2027-06-19 |
| Archive first seen | 2018-08-09 |
| Archive snapshots | Not counted (archive lookup incomplete) |
| Reputation | VirusTotal: 13 flagged | AbuseIPDB: 0 reports | Google Safe Browsing: 0 matches |
About this assessment
A trust score summarises the evidence TrustSniffer could collect about coffeecatcafe.org at assessment time. It is a starting point for your own judgement, not a guarantee: a high score means the signals were consistent with a legitimately operated site, a low or critical score means several risk patterns were present.
TrustSniffer assesses a website from the evidence it can collect at a point in time: domain registration and age, hosting and certificate, the content the site served, and third-party reputation feeds. A score is a summary of that evidence, not a guarantee and not a legal finding. There is no human rating and no user review in it. A site can change after it is assessed.