Skip to content
WikiHidden

How we assess

The evidence model behind every status, confidence level, address and impersonation report on WikiHidden.

Updated

WikiHidden documents publicly reported information about hidden-web services and entities. It is a research and safety resource. It does not facilitate transactions and does not endorse anything it lists.

What counts as evidence

  • Observations — automated checks, analyst reviews and third-party reports. Each records what responded and, separately, whether identity was assessed.
  • References — published reporting, academic work, court and government records, and archives. A reference counts as independent when the entity does not control it and it is not a copy of another listed source.
  • Review decisions — a person confirming, dismissing or overriding something, with a recorded reason.

Which addresses are published

For legitimate services — newsrooms, whistleblowing systems, privacy tools, search engines, archives, infrastructure — a profile lists the official website and the official onion address, each with the source it was taken from: the operator's own site, the official SecureDrop directory, or a long-running public list that requires proof of ownership.

No address is published for threat actors, marketplaces, seized services or scam reports. Those profiles exist to document status, history and impersonation; they are not a way in. Lookalike and phishing addresses are never published anywhere on the site.

A listed address is a record of what a source published, not a guarantee. Before relying on one, compare it with the operator's own site.

Identity confidence levels

  • High — three or more independent sources, identity continuity observed, a stable history and no unresolved conflicts. No single signal can produce this level.
  • Medium — at least two independent sources, with either continuity or corroboration still incomplete.
  • Low — a single-source claim, a break in identity continuity, or an unresolved conflict over who operates the identity.
  • Unverified — nothing on file independently supports the identity yet.

Every profile lists the signals that produced its level, marked as supporting, weakening or context, so the reasoning can be checked rather than trusted.

What automation may and may not do

Automated processes record observations, move entities between observed online, intermittent, offline and unknown, detect stale data, and flag possible duplicates and changes of identity.

Automation never labels anything as seized, closed, an exit scam, a scam, a threat actor, official or verified. When it sees something that might warrant one of those — a seizure banner, a changed identity key, a long outage — it opens a review for a person. Impersonation reports created by automation stay private until confirmed.

Impersonation being reported is not a mark against the original

Well-known entities attract imitators. A high lookalike count raises the risk that what someone encounters is fake; it does not lower confidence in the documented entity. The two are shown separately for that reason.

Translations

The interface and these guides are translated with machine assistance. Entity descriptions may be machine-translated, and are labelled when they are. Wherever versions differ, the English text is the reference.

Corrections

Records are wrong sometimes. Corrections are welcome from anyone, including the entities documented here; see About.