=== PCrisk Trust Badge - Website Security Seal & Malware Scanner ===
Contributors: pcrisk
Tags: trust badge, trust seal, site seal, blacklist, woocommerce
Requires at least: 6.3
Tested up to: 7.1
Requires PHP: 7.4
Stable tag: 1.17.0
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Click-to-verify trust badge and security seal, backed by real malware, phishing and blacklist scans. Free monthly monitoring; daily scans on paid.

== Description ==

Shoppers who don't know your store ask one silent question before they type a card number: is it safe to buy here? PCrisk Trust Badge answers it with a seal they can click and check for themselves.

**PCrisk Trust Badge** monitors your site for free and - on a paid plan - puts a *"This website is safe"* seal on it. The seal is backed by a security scan. Anyone can **click the badge to open your live scan report**: malware scan results, blacklist checks, and a trust score, verified by PCrisk's website security scanner.

Every claim the badge makes is one your visitors can check for themselves.

An outside opinion on your site's safety. PCrisk scans your website from the public web rather than from inside WordPress - the way an antivirus engine, a search engine like Google, or a shopper's browser sees it - so you find out your online store has been hacked, defaced or blacklisted before your customers do. Continuous scanning covers virus and malware detection, phishing feeds, SSL validity and a domain blacklist checker across 90+ sources - among them Safe Browsing, Spamhaus, SURBL, PhishTank and URLhaus. Built for business sites and ecommerce stores with a hard-won reputation to protect.

= Free security monitoring, no card =

**The free plan is permanent, not a trial.** Install the plugin, connect your site, and you get a monthly security scan across 90+ engines and blacklists, your trust score and verdict inside WordPress, and the result of every monthly scan by email - clean or flagged.

Paid plans add the part your visitors see: the public click-to-verify badge, daily scans, and the live report it opens.

The badge itself is served by PCrisk rather than by the plugin, so the verification it displays is issued by the party that actually performed the scan.

= How the badge behaves =

* The badge shows only while your site is **actually passing** its latest security check (trust score 70 or higher).
* If a scan flags something, you get a **full report by email within minutes of that scan** - your risk score, how many engines flagged you, which threat databases list you, what the file scan found and how to fix it - and the badge takes itself down until the issue is resolved.
* One click opens the **live PCrisk scan report** for your domain: real scan date, real results, real trust score.

The badge is tied to the scan result, so it cannot stay up while your site is failing its own security check.

= Why site owners add it =

* **Turn security into social proof.** Shoppers hesitate on sites they don't know. A verifiable safety seal answers the question they're silently asking: *"Is it safe to buy here?"*
* **Give visitors something to check.** The badge opens your live scan report, so a cautious shopper can read the evidence for themselves.
* **Know first.** Every scan reports back by email, not just to a dashboard you have to remember to open - so you hear it from us, not from a customer, an ad platform, or a browser warning.

= Don't be the last to know your site got flagged =

Antivirus engines and search-engine warnings sometimes flag perfectly legitimate sites - a new TLD, a plugin's behaviour, a traffic spike, a pattern match gone wrong. Most site owners find out the hard way:

* A customer mentions your site won't load in their browser.
* An ad campaign gets suspended without warning.
* Email deliverability quietly drops and nobody can work out why.
* You check manually months later and realise you've been flagged the whole time.

By then the damage is done. PCrisk surfaces new detections within minutes of the scan that finds them - monthly on the free plan, daily on paid - so a one-off false positive becomes a ten-minute fix instead of something you discover months later. And if it *is* a false positive, PCrisk gives you a dispute path.

= What every scan checks =

Each scan runs your site through the full PCrisk detection stack - the same engine behind the public PCrisk website scanner. **The free plan runs it monthly; paid plans run it every day.**

* **Malware** - malicious code, obfuscated scripts and newly reported threats hidden in your HTML, JavaScript and embedded resources.
* **Phishing** - checked against global phishing feeds, so your site isn't mistaken for a fake-login or fraud page.
* **Blacklists** - your domain cross-referenced against 90+ security and threat-intelligence sources.
* **SSL** - certificate validity verified on every scan, so an expired or broken certificate is caught fast.
* **Reputation & outbound links** - domain reputation, popularity ranking, and the health of the sites you link out to.
* **Plain-English summary** - every finding explained without jargon, refreshed on every scan.

= Designed to fit your site =

Badge design and placement are yours to tune from the moment you install:

* **Four looks** - Shield, Ribbon, Minimal, and Bubble - in **light, dark, or auto** (auto follows your site's light/dark mode), in three sizes.
* **One-click placement** - footer (every page), after content, or a **floating corner badge** that follows visitors as they scroll.
* **WooCommerce placements, auto-detected** - put the badge on your shop page, product pages (above or below the Add to cart button), cart, and checkout - right where hesitant shoppers decide.
* **Gutenberg block** - drop the badge into any page or post, and give each one its own style, size, theme, alignment and spacing.
* **Live preview** - see exactly how the badge looks *and* where it sits, before you save anything.
* **Fine-tuning** - alignment, spacing around the badge, and a one-click "Disable all badges" switch that keeps your settings for later.
* **No API key, no DNS records** - the badge is matched to your domain automatically. Pick a placement and it appears by itself, or place it exactly where you want with the Gutenberg block.

= Built for WooCommerce stores =

For e-commerce stores, the plugin detects WooCommerce automatically and adds dedicated store placements to its settings - no setup needed. They show a live badge once your domain has an active PCrisk verification:

* **Product pages** - above or below the Add to cart button, or at the bottom of the product details
* **Cart** - next to the checkout button
* **Checkout** - beside the "Place order" button, where trust decides the sale
* **Shop page** - top or bottom of your product grid

Checkout is where trust matters most. Put the verified security badge at the exact moment of doubt, and let hesitant shoppers click to verify your store's safety for themselves. Site-wide placements (footer, floating) cover the rest of your store.

= How it works =

1. Install the plugin and **start free** - a guided setup explains what connecting shares, asks for your approval, then detects your domain and opens PCrisk sign-up. No payment details.
2. Your site is scanned. Trust score, verdict and blacklist status appear right in your WordPress admin.
3. Want the badge visitors can click? Upgrade, then pick a look and a spot - it goes live as soon as a scan comes back clean, and takes itself down if one ever doesn't.

**Free plan:** monthly security scan, your status in wp-admin, and every scan result by email - free forever, one site, no card. **Paid plans** add the part your visitors see: PCrisk issues a public verification for your domain, so the badge renders on your site, scans run daily, and your live report page and scan history go live - from $16.95/month, with a 14-day free trial of any paid plan. See [pricing and plans](https://scanner.pcrisk.com/trust-badge).

== Installation ==

1. Install and activate the plugin from **Plugins -> Add New Plugin** (search for "PCrisk Trust Badge").
2. Open **Trust Badge** in your admin menu. The first screen explains exactly what connecting shares with PCrisk (your site's domain, and ordinary browser request data) and waits for your approval - nothing is loaded from PCrisk before you agree, and you can skip straight to the design settings instead.
3. After you agree, pick how to begin - **start the 14-day free trial** or **continue with the free plan**. No payment details needed. Your first scan starts right away.
4. Check your security status in WordPress: trust score, verdict, blacklist status and when the next scan runs.
5. To show the public badge, upgrade, then pick a style and a placement - the live preview shows exactly what visitors will see. Once a scan comes back clean, your badge is live.

== Frequently Asked Questions ==

= How do I show a security badge on my WordPress website? =

Install PCrisk Trust Badge and connect your domain - that part is free. After upgrading, choose a placement (footer, after content, or a floating corner) and the badge appears by itself once a scan comes back clean - no code and no theme editing. If you'd rather pick the exact spot, drop the PCrisk Trust Badge block into any page or post instead. You can use both together.

= How do I check if my website has been hacked or blacklisted? =

Connect your domain and PCrisk runs an external web security check on it - virus and malware detection, phishing feeds, SSL validity, and a domain blacklist checker across 90+ security sources. Every scan reports back by email - monthly on the free plan - so you see the result either way, and anything found reaches you within minutes of the scan that found it, before your customers, your ad platform or a browser warning tells you.

= Do trust badges increase conversions? =

Trust signals reduce hesitation, especially for first-time visitors deciding whether to buy or sign up. The research is consistent:

* **19%** of shoppers have abandoned a checkout because they didn't trust the site with their card details (Baymard Institute).
* **51%** look for secure-site signals - a padlock, HTTPS, a trust badge - before buying (Bazaarvoice).
* **83%** of consumers say protecting their data is how a brand earns their trust (PwC).

Shoppers can't audit your security, so they look for signals of it. With a *click-to-verify* badge, a sceptical visitor can open your live scan report and check the evidence, which is exactly what turns hesitation into a completed order.

= What is a click-to-verify trust seal? =

A trust seal that links to live proof. Clicking the PCrisk badge opens your domain's public scan report - current malware scan results, blacklist status, and trust score.

= How do visitors know my website is safe? =

They don't have to take your word for it. The badge says *"This website is safe"* only while your latest PCrisk scan is clean, and one click shows the live report proving it - scan date, results, and score for your exact domain.

= Why isn't my badge showing yet? =

Three things have to be true: you're on a paid plan (the public badge isn't part of the free plan), your domain is connected at PCrisk, and its latest scan is clean (trust score 70 or higher). Until all three are true the badge stays hidden - on purpose. Resolve anything flagged on your PCrisk dashboard and the badge comes back by itself after the next clean scan. Nothing on your site breaks in the meantime.

= Do I need an API key or any code? =

No key to copy and no DNS record to add - the badge is matched to your site's domain automatically, and choosing where it appears is a click on the settings screen. Setup opens PCrisk sign-up with your domain already filled in. You're not limited to the automatic placements, though: the PCrisk Trust Badge block puts a badge exactly where you want it in any page or post, with its own style if you like.

= How do I add a trust badge to my WooCommerce store? =

The plugin detects WooCommerce automatically and adds store placements to its settings: shop page, product pages (above or below the Add to cart button), cart, and checkout (beside the Place order button). They show a live badge once your domain has an active PCrisk verification. Toggle the pages you want - and add the footer or floating badge to cover every other page of your store.

= Is the PCrisk Trust Badge plugin free? =

Yes - and so is the monitoring. The free plan scans your site every month, shows your trust score and blacklist status inside WordPress, and emails you if your site is ever flagged. No payment details, no time limit, and nothing in the free plan expires or downgrades later.

The part your visitors see - the public click-to-verify badge, daily scans and the live report page - is on paid plans, from $16.95/month, with a 14-day free trial of any paid plan. Current plans are listed at scanner.pcrisk.com/trust-badge.

= What do I get on the free plan? =

* A **monthly security scan** - malware, phishing, blacklists, SSL and domain reputation, across 90+ sources
* Your **trust score, verdict and blacklist status** in your WordPress admin
* **Every monthly scan result by email** - clean or flagged, so you always know where you stand

One site, no time limit, no card. Every design, placement and block in the plugin is unlocked from the moment you install it. What a paid plan adds is the part PCrisk performs: a public verification for your domain, so the badge renders for your visitors, plus daily scans, the live report page and scan history.

= Does the trust badge slow down my website? =

No. It's one small script, loaded deferred so it never blocks your page from rendering, and only on the pages where the badge actually appears. It also reserves its space in advance, so your layout doesn't shift as it loads.

= What happens if the scan finds malware on my site? =

You get a full report by email within minutes of that scan, on every plan - and if you're on a paid plan the badge takes itself down at the same time, so visitors never see a safety claim your scan doesn't back up. The report gives you: your risk score, how many of the 90+ antivirus engines flagged you, your threat-database status, what the website file scan found, and a link to open the full report and fix it. Fix the issue (or dispute the result from the report page if you think it's a false positive) and the badge returns by itself after the next clean scan. You don't have to touch the plugin.

= Can I place the badge in the footer, after posts, or in a floating corner? =

Yes - all three, from one settings screen: footer on every page, after your post/page content, or a floating corner badge that follows visitors as they scroll. On WooCommerce stores you also get dedicated store placements (shop, product, cart, and checkout pages), and you can drop the badge into any individual page with the Gutenberg block.

= Can I gate the badge behind my cookie/consent banner? =

Yes. The plugin provides a `pcrisk_trust_badge_enabled` filter (default `true`); returning `false` skips the badge **and** the remote script entirely for that page view - nothing is requested from scanner.pcrisk.com. For example, with a consent cookie:

`add_filter( 'pcrisk_trust_badge_enabled', function () { return isset( $_COOKIE['my_consent'] ) && 'yes' === $_COOKIE['my_consent']; } );`

The same filter also works as a per-page or per-template off switch.

= My caching or speed-optimisation plugin hides the badge =

JS optimisers (WP Rocket, LiteSpeed Cache, Autoptimize, SiteGround Optimizer and similar) often delay, combine or strip third-party scripts by default - the badge then never renders, with no error. Add `trust-badge.js` (or the whole `scanner.pcrisk.com` domain) to your optimiser's exclusion list: in WP Rocket under "Delay JavaScript execution" exclusions, in LiteSpeed Cache under "Tuning -> JS Excludes" (and "Delayed JS Excludes"), in Autoptimize under "JS optimisation exclusions". The badge script is a single small deferred file - excluding it does not affect your scores.

== Screenshots ==

1. The click-to-verify badge on a live store - visitors click it to open your live PCrisk scan report. Public badge on paid plans, from $16.95/month.
2. Free plan: your trust score, verdict and blacklist status right in your WordPress admin - no card, and nothing shown on your site.
3. What visitors see when they click: your live scan report - the "PCrisk Verified" certificate, trust score and 90+ security-engine checks.
4. One settings screen: pick the look, pick the spot - the live preview shows both before you save anything. Automatic placement, or place it by hand in the editor.
5. WooCommerce detected automatically - shop, product, cart and checkout placements, right where hesitant shoppers decide.
6. Four looks - Shield, Ribbon, Minimal, Bubble - each in light & dark, or auto to follow your theme, in three sizes.
7. Daily scans on paid plans, monthly on free - and on every plan, an email within minutes of any detection: risk score, engines flagged, threat-database status and what the file scan found.
8. Drop the badge into any page or post with the Gutenberg block - each block can carry its own style, size, theme and spacing.

== External services ==

This plugin connects to the PCrisk website security scanner (pcrisk.com) to power the badge:

**Nothing is contacted without your consent.** The admin screens make no request to PCrisk until you explicitly approve the connection on the plugin's setup screen (or the settings screen's connect card) - the approval text spells out what is shared before you agree. Your site's public pages load nothing from PCrisk until you enable an automatic placement or add the badge block, and the `pcrisk_trust_badge_enabled` filter (FAQ above) can gate even that behind your own consent tooling.

* **On your public pages, only where a badge is set to appear:** the badge script `https://scanner.pcrisk.com/badge/trust-badge.js` is loaded by your visitor's browser, which then requests your domain's current verdict. As with any externally hosted script, that request carries the visitor's IP address, browser user-agent and the page URL. PCrisk sets no cookies through the badge and does not track visitors across sites.
* **In your WordPress admin only, after you approve the connection:** the plugin's own settings screen and setup wizard request `https://scanner.pcrisk.com/api/badge/scan-summary/<your-domain>` to show your trust score and verdict, and load the badge and preview scripts (`trust-badge.js` and `trust-badge-preview.js`) plus flag icons from the same host to draw the live preview. If your site has never been scanned - or the last result is stale - those two screens also embed the PCrisk scan runner (`https://scanner.pcrisk.com/trust-badge/scan-embed`) to start a scan of your domain. The block editor loads the same preview assets and makes the same read-only summary request once per editing session, but only when the page you are editing contains a PCrisk Trust Badge block - it is what tells you there whether the badge will actually render for visitors. Your domain name - plus a marker identifying the request as coming from the WordPress integration - is all that is sent, and no other admin screen contacts PCrisk.
* **What comes back:** your scan status (clean or flagged), your plan state, trust score, last and next scan dates, and the badge itself.
* **Inbound, so PCrisk doesn't scan abandoned sites:** PCrisk's scanner periodically checks `your-domain/wp-json/pcrisk/v1/verify`, a small public endpoint this plugin provides, to confirm the plugin is still installed before spending a scan on your domain. It answers with a random site token, the plugin and WordPress versions, and when the badge dashboard was last used - nothing else, and the plugin itself never sends a request from your server.
* **Nothing is shown until you choose it:** no badge, link or credit appears on your site until you pick a placement. The plugin's settings and preview work whether or not you ever display one, and no plugin feature depends on displaying it.
* **Why it's needed:** the badge is a live security seal - without the scanner there is nothing truthful to display.

The free plan requires a PCrisk account (email only, no payment details). The public badge requires a paid subscription, which starts with a 14-day free trial. Service terms: [PCrisk Terms of Service](https://scanner.pcrisk.com/legal/terms-of-service) · [Privacy Policy](https://scanner.pcrisk.com/legal/privacy-policy).

== Changelog ==

= 1.17.0 =
* Initial release: **free** monthly security monitoring in wp-admin - trust score, verdict, blacklist status and every scan result by email, no card required.
* Paid plans: click-to-verify website security badge backed by daily PCrisk malware scans and blacklist monitoring.
* Four badge styles (Shield, Ribbon, Minimal, Bubble) in light & dark, three sizes.
* One-click placements - footer security badge, after content, floating corner badge - plus a Gutenberg trust badge block.
* WooCommerce integration, auto-detected - store trust badge placements on the shop page, product pages (above or below Add to cart), cart, and checkout.
* Live preview of look and placement, spacing controls, and a one-click hide-everywhere switch.
* Explicit consent step before anything is loaded from PCrisk in wp-admin.
* Automatic: the badge hides whenever the latest scan isn't clean.

== Upgrade Notice ==

= 1.17.0 =
First release - free monthly security monitoring in your WordPress dashboard, plus a click-to-verify site safety badge on paid plans.
