Issue abstract: Norton Safe Web rates safeage[.]eu and its www hostname as Warning, categorised as URL:Botnet. The site is clean and I believe this is a false positive. Two submissions filed on 31 August have not changed the rating.
Note: domain names are written in defanged form (brackets around the dot) because new accounts cannot post links here.
Detailed description:
I am the owner and operator of safeage[.]eu, a Dutch webshop selling mobility and daily-living aids for elderly and less-abled customers. The site runs WordPress/WooCommerce behind Cloudflare.
Alert ID: 4d352ec5c0b5/2026-08-27T09:41:51.093Z
Detection observed: 27 August 2026, 09:41 UTC
What I have already done
On 31 August I filed false-positive reports through the Norton submissions portal, separately for the bare domain and the www hostname. Both were acknowledged with the “48 business hours” message. Three days on, both still return a Warning rating.
Why I believe the site is clean
Our developer completed a full server-side audit: no malware, no backdoors, no web shells, no modified core or plugin files, no unknown administrator accounts, no unexpected scheduled tasks.
An independent Sucuri SiteCheck scan returns no malware and no blacklist entries. Google Safe Browsing reports “No unsafe content found” (checked 31 August 2026).
Of 36 reputation engines checked via aggregated scanning, only Norton, Avira and Gridinsoft flag the domain. Bitdefender, Dr.Web, Fortinet, SURBL, Spam404, PhishTank, OpenPhish and URLhaus all report nothing.
Certificate Transparency shows only five hostnames on the domain (apex, www, mail, webmail, dashboard). There are no forgotten or abandoned subdomains.
Norton Safe Web itself rates our hosting IP as safe, which suggests the classification is attached to the domain name rather than to hosted content.
One thing that may be triggering the automated rating
Our homepage opens preconnect and dns-prefetch connections to api.config-security[.]com and conf.config-security[.]com. Despite the name, these are not a security service. They are the endpoints used by the Triple Whale analytics pixel (TriplePixel), a commercial e-commerce attribution product that we license and actively use.
I can see how a heuristic would read repeated beacons to a domain called “config-security” as botnet-like behaviour. Norton Safe Web rates that domain itself as safe. If this is what is driving the classification, I would very much like to know, because it would keep recurring after any manual clearance.
Impact
A meaningful share of our customers cannot reach the shop. Our conversion rate on paid traffic roughly halved. Our customer base skews older and disproportionately runs pre-installed Norton products, so the effect on us is severe.
I am happy to provide the full audit report, server logs or any other evidence a reviewer needs, and I can supply the exact URLs privately. Any pointers on getting this escalated would be much appreciated.
Thank you.
Thomas












