89
/100
prowl
Benchmarked Aug 14, 2026

PhishStats

Phishing database

securitydatabasedata platform_profile
Benchmark Your API

Score Breakdown

Auth Simplicity 10/10
First-Try Success 10/10
Latency 9/10
Documentation 9/10
Token Efficiency 9/10
Consistency 8/10
Error Clarity 8/10
Parseability 8/10

Benchmark Analysis Log

Full LLM thinking from the 4-phase benchmark pipeline.

Analyze
```json
{
  "service_type": "platform",
  "base_url": "https://phishstats.info",
  "auth_method": "none",
  "auth_config": {},
  "endpoints": [
    {
      "path": "/api/phishing",
      "method": "GET",
      "description": "Real-time phishing feed returning JSON entries with URLs, IPs, domains, and scoring."
    },
    {
      "path": "/search",
      "method": "GET",
      "description": "Web UI search of the phishing database by URL, IP, domain, or keyword."
    },
    {
      "path": "/api-docs",
      "method": "GET",
      "description": "Interactive API documentation and example requests."
    },
    {
      "path": "/about",
      "method": "GET",
      "description": "Information on the project history, mission, and community contribution.",
      "auth_method": "none"
    },
    {
      "path": "/faq",
      "method": "GET",
      "description": "Frequently asked questions covering rate limits, data freshness, and scoring."
    }
  ],
  "pricing_model": {
    "type": "free",
    "details": {
      "description": "Completely free and open to the infosec community. No API keys or registration required.",
      "cost": 0,
      "key_requirement": "none",
      "usage_limits": "As per FAQ, API rate limiting applies to prevent abuse but is not commercialized."
    }
  },
  "rate_limits": {
    "unknown": "Not publicly specified; FAQ indicates practical limits to protect service availability."
  },
  "capabilities": [
    "Real-time phishing intelligence feed",
    "JSON REST API for phishing data",
    "Phishing database search across URLs, IPs, and domains",
    "Phishing score/scoring system",
    "Web-based search interface",
    "Historical phishing data since 2014",
    "Security research and threat hunting support",
    "Community-driven data enrichment",
    "SOC/SIEM/SOAR integration via API"
  ],
  "raw_analysis": "PhishStats is a long-standing (since 2014) free phishing intelligence platform serving the information security community. It operates with no authentication, providing open access to a real-time phishing feed via a simple JSON REST API and a web search interface. The service is mature and trusted by researchers, SOC analysts, and threat hunters. It offers capabilities for threat hunting, incident response, and SIEM/SOAR integrations. The platform appears to be free with no pricing tiers, likely funded by community support or institutional backing. Rate limits are not explicitly documented, suggesting they are managed on an availability basis. The absence of auth simplifies integration but means data is public and not for private tracking. Its maturity and longevity make it a reliable, low-friction source for phishing indicators, though it lacks advanced features like API keys, subscription dashboards, or enterprise SLAs. Overall, it is a valuable free resource for security monitoring and research rather than a commercial product."
}
```
Execute

3/3 tests passed

TestEndpointStatusLatency
website_uptimeGET /200110ms
robots_txtGET /robots.txt20061ms
llms_txtGET /llms.txt20053ms
Interpret
{
  "overall": 88,
  "dimensions": {
    "token_efficiency": 9.0,
    "first_try_success": 10.0,
    "response_parseability": 8.5,
    "error_clarity": 7.5,
    "doc_quality": 9.0,
    "auth_simplicity": 10.0,
    "latency": 9.0,
    "consistency": 8.0
  },
  "pricing_normalized": {},
  "issues": [
    "No security headers detected on website responses.",
    "Limited documentation on API rate limits and specific response schemas in the llms.txt preview.",
    "No explicit status page or uptime history found, though current checks passed."
  ],
  "recommendations": [
    "Add security headers (e.g., CSP, X-Content-Type-Options) to improve trust and security.",
    "Publish detailed API response schemas and rate limit specifics in llms.txt for easier agent integration.",
    "Consider adding a public status page for transparency and consistency monitoring."
  ]
}

Agent Readiness

x402 Payments
Not supported
Streaming
No
Sandbox
None
Agent Auth
Unknown
SDKs
None listed
MCP Support
No

Embed your Prowl badge

Show your live agent-readiness score on your own site. Free, no auth — it updates as your score changes.

Prowl agent-readiness badge
<a href="https://prowl.world/service/phishstats">
  <img src="https://prowl.world/badge/phishstats.svg" height="56" alt="Agent-readiness on Prowl">
</a>

Options: ?style=light|dark · ?size=sm|md · ?variant=certified (claimed + DNS-verified only) · badge generator with preview

Want the full interactive view?

See operational metrics, LLM evaluations, agent readiness, and more.

Open in Dashboard