# Watch Google Web Risk flags (Web Risk monitor)

The **Web Risk** monitor (API type `webRisk`, shown in the app as **Web risk**) checks your URL against Google's
Web Risk lists - the reputation data behind browser warnings for phishing, malware and unwanted software. If your
site is compromised or wrongly flagged, visitors see a red warning page instead of your site; this monitor tells
you when that starts.

:::tip[Usually attached]
If the site already has a Website or API monitor, switch on **Web Risk** there instead - see
[Attach sub-checks to a monitor](/monitors/types/attached-sub-checks/).
:::

## At a glance

| | |
|---|---|
| API type token | `webRisk` |
| Runs from | HostTracker's own internal check network, using Google's Web Risk service - no location picker |
| Schedule | every 12 hours, fixed (**Fixed interval: every 12 hours**) |
| Plan gates | Web Risk is a package feature (`attachedWebrisk`) |

## How it decides

- **Down** when Google lists the URL under any threat type; the alert names the threat types found.
- **Up** when the URL is not listed.
- If Google's service cannot be reached, the monitor keeps its previous verdict until the next successful lookup,
  so an outage on Google's side never flips it on its own.
- While the URL stays flagged, a still-down reminder is sent at every check (every 12 hours) to contacts subscribed
  to still-down reminders.

Unlike the other expiry and blacklist checks, Web Risk checks the **whole URL** you enter, not just the host.

## Settings reference

A Web Risk monitor has no type-specific settings. The name, tags, **Full Log**, **Open Stats** and subscriptions
work as described in [Common monitor fields](/monitors/types/http/#common-monitor-fields).

| Setting (app label) | API field | Type / allowed values | Default | Plan limits | What it does for you |
|---|---|---|---|---|---|
| **Url / Domain / IP** | `url` | URL or domain | required | - | The address checked against the lists. |
| Interval | `interval` | ignored | 12 hours | - | Fixed; a sent value is replaced and the response carries a warning. |
| Locations | `locations` | not accepted | - | - | Sending pools is refused. |
| Settings | `settings` | must be empty | - | - | A standalone Web Risk monitor accepts no settings. |

## Set it up in the app

1. On the **Sites** dashboard, click **Add Monitor** and choose **Web risk** in **Monitoring Type**. If your
   package does not include it, the type is marked **not in your package**.
2. Enter the URL in **Url / Domain / IP** and a name.
3. Check **Alert Subscriptions** and click **Save**.

## Do it with the API or MCP

```bash
curl -X POST https://api2.host-tracker.com/monitor \
  -H "Authorization: Bearer $HT_TOKEN" -H "Content-Type: application/json" \
  -d '{ "type": "webRisk", "url": "https://www.example.com/" }'
```

Update the URL or name with `PATCH /monitor/{id}`, for example `{"url": "https://shop.example.com/"}`.

MCP: `create_monitor(type="webRisk", url="https://www.example.com/")` - no `interval`, no `pools`.

Read the latest verdict with `GET /monitor/{monitorId}/attached` - the `webRisk` block carries `verdict`,
`threats[]` and `checkedAt` - or `get_monitor(id, expand="attached")`.

## What happens next

The first lookup runs shortly after you save, then every 12 hours. If the site is flagged, find the cause (often
injected code or a compromised plugin), clean it, and request a review in Google Search Console; the monitor turns
Up at the first check after Google removes the listing.

## Limits and gotchas

- `403 package_limit` - your package does not include Web Risk.
- `422 invalid_settings` - any member inside `settings`.
- `422 validation_failed` with `reason: pool_not_supported_for_type` - omit `locations`.
- A listing can take up to 12 hours to show.

## Related

- [Attach sub-checks to a monitor](/monitors/types/attached-sub-checks/)
- [DNSBL / blacklist monitor](/monitors/types/dnsbl/)
- [Website / HTTPS monitor](/monitors/types/http/)
