SUSPICIOUS

Warning signs detected

Real AI companion subscription site with clean scans yet frequent user complaints over refunds and token billing. Several risk indicators suggest caution. This site might be legitimate — but treat it as unverified until you can independently confirm.

Security Review

Is candy.ai legit or a scam?

Our verdict:Suspicious· 55/100

Real AI companion subscription site with clean scans yet frequent user complaints over refunds and token billing.

candy.aiScanned 9d ago
0
Trust score
SUSPICIOUS
Heuristics 91·MT 62
Category tags
ai-companionsubscription-service#Subscription Trap75% MT confidence

These checks passed — but they don't clear the site. A clean antivirus result, valid SSL, and a calm server only mean it isn't hosting malware; they say nothing about whether the business is real. This verdict is based on the site's conduct and content, not a malware detection.

View density

Analysis Summary

Threat Intelligence
0/92
All engines report clean
Domain Age
Registration date unknown
MT Intelligence
Suspicious
Moderate likelihood · 75% confidence

MT Intelligence

Advanced threat intelligence
MT Security Analyst
Moderate scam likelihoodengineMT · Guardiantrust62/100
MT AgentLive web researchVisual inspection
0%
Confidence
The site presents itself as a paid AI girlfriend platform offering chat, voice, and images. Our antivirus network and browser blocklists returned completely clean results with no malware or phishing flags. The domain has existed since 2017 and is operated by an active Malta-registered company. However the evidence package shows 200 complaints plus multiple independent review aggregator and Reddit reports focused on accidental purchases, refund refusals, and poor support. These billing issues are common enough to warrant caution even though the service itself is not a fake storefront or data harvester.
Full dossier
Analysis complete

Page Content

The homepage promotes an AI girlfriend app with options to create characters, chat, and access premium uncensored features. It contains registration buttons and links to Discord and help pages but no visible contact email or postal address.

Infrastructure

Valid SSL certificate, clean hosting IP with zero abuse reports, and no malicious redirects. External scripts load from known CDNs and analytics providers only.

Domain History

Registered in December 2017 through GoDaddy and still active, far older than typical scam domains. Operated by EverAI Limited, a Malta company listed in the business registry.

Web Reputation

Mixed user feedback with both positive and negative reviews on independent sites; no evidence of cloning or brand impersonation.

Risk Factors
3
  • Hundreds of user complaints about refunds and subscription cancellations on review platforms.
  • No contact email or physical address displayed on the site.
  • Frequent criticism of token usage and billing transparency in Reddit threads.
Positive Signals
3
  • Zero detections across our antivirus network and browser blocklists.
  • Domain registered in 2017 with an active Malta business registration.
  • independent review aggregator and multiple review summaries rate the service as a legitimate operating company.
AI Recommendation
If you try the service, use the shortest subscription possible and document all billing steps. Cancel immediately if the experience does not match expectations.
Next-gen fraud intelligence
Evidence-backedCross-checked

Website Preview

Screenshot of candy.ai
LIVE RENDER
candy.ai

Automated page render — captured in a safe sandbox. What an ordinary visitor would see when loading the site.

Web Research Findings

Our live research agent queries scam-report databases, consumer-review sites, news coverage, and general web search for candy.ai, then cross-checks business-registration records and look-alike domain patterns. Everything below is pulled from what it actually found.

Business registration
Active · Malta
Site traces back to an actively registered business.
Clone check
Not a clone
No well-known site's layout or branding detected here.
Typosquat check
No look-alike match
The domain doesn't resemble any well-known brand's spelling.
Web mentions
3 scam reports · 200 complaints · 3 positive
Key findings
7 headline facts from open-web research
  • Domain candy.ai registered December 16, 2017 via GoDaddy; expires 2027; privacy-protected WHOIS.
  • Operated by EverAI Limited (Malta company C107181); payments processed under EverAI name for discretion.
  • Trustpilot: 381 reviews, overall 3.8/5; frequent complaints about refunds, token usage, and subscription cancellations.
  • Scamadviser rates it 'Very Likely Safe' with trust score 100, despite mixed reviews and hidden owner identity.
  • Multiple independent reviews (2025-2026) state it is a legitimate operating business since ~2023 delivering advertised AI companion features, not a vanishing scam.
  • Reddit threads in r/Chatbots show mixed user experiences: praise for images/voice, criticism of pricing, UI, and value.
  • No detected scam families or brand references; domain not a recent creation or obvious clone.
Scam reports (3)
Direct quotes from public scam databases, forums, and news.
  • Trustpilotopen

    "Accidental purchases, no refund, no response. I purchased a Premium Yearly subscription on 23 May 2026. At no point during checkout was I shown a refund policy..."

  • Reddit r/Chatbotsopen

    "Candy AI is total dogshit, run away."

  • Reddit r/Chatbotsopen

    "I feel like such an idiot trying candy ai, I gave into the hype. 10 minutes in and it’s horrible just horrible."

Positive reviews (3)
Quotes indicating the site is legitimate.
  • Trustpilotopen

    "Easy to use, it's an open gate to your wildest dreams. AI is a bit hard to master at the beginning, but the characters are really astounding."

  • Scamadviseropen

    "In summary, we think candy.ai is legit and safe for consumers to access. Trust Score 100"

  • Multiple review sitesopen

    "Candy AI is a legitimate subscription business. It delivers the product it advertises, processes payments correctly, and has a real support team."

Business registration
Status: active · Malta

EverAI Limited, registered with Malta Business Registry under C107181, address 56 Central Business Centre, Triq Is-Soll, Santa Venera SVR 1833, Malta. Also trademark CANDY.AI owned by EverAI Limited.

Research summary
Narrative write-up from our AI analyst, grounded on the facts above

Our research found three scam-related mentions on independent review aggregator and Reddit highlighting refund problems and poor experiences. Three positive mentions describe the service as legitimate with working features. A Malta company registration confirms an active business behind the site since around 2023, though complaints about billing remain common.

Antivirus Engines

Clean pass · verified
Clean across 92 engines

We cross-check every URL against our antivirus network of 92 malware and blacklist engines. None of them flagged this URL in the last scan.

0Malicious0Suspicious61Harmless92Engines
Clean
Kaspersky
Clean
Bitdefender
Clean
Microsoft
Not in pass
ESET-NOD32
Not in pass
Avira
Not in pass
Sophos
Clean
Fortinet
Clean
Google Safebrowsing
Clean
Emsisoft
Clean

No engine detections. The URL passed every antivirus and blacklist engine we queried in this scan. Stay vigilant — AV coverage is only one signal among many.

Security Scans

Blacklist Check
Not flagged on major threat lists

Checked against the major public blocklists used by browsers and security tools — no hits.

Contact Verification

We fetched the page and looked for real-world contact details. Legitimate businesses almost always publish an email on their own domain, a phone number, and a postal address. Scam shops usually don't.

What We Found
No clear contact details on the page
Emails on site's domainNone
Phone numbers107181 56
Postal addressNot listed
Linked social profiles1
Signal Summary
Several contact red flags
  • No contact email found anywhere on the page.
  • No postal address visible on the page.
  • Phone number listed (107181 56).

Domain & Encryption

Encryption Certificate
StatusValid
ProtocolTLSv1.3
IssuerGoogle Trust Services · WE1
ExpiresAug 24, 2026 (88d)
Self-signedNo
Hosting & Technology
HostingCloudflare, Inc.
Server locationUS
Web servercloudflare

Redirect Chain

Hops
1
Cross-domain
No
Lookalike
No
Punycode
No
  • 1301http://candy.ai/
  • 2200https://candy.ai/

Server Reputation

Abuse Intelligence
Confidence score0%
Reports on file0
ISPCloudflare, Inc.
Usage typeContent Delivery Network

Scam-Type Likelihood

1 scam-type patterns detected
Scam-Type Likelihood

0 of 13 categories showed signals

We check every URL against 13 distinct scam categories so the verdict tells you not just how risky the page is, but what kind of risk it carries. Each meter pulls from page signals, web reports, our AI analyst, vision, and the scam-network cluster — not from raw AV labels.

Top match: Subscription Trap
Subscription Trap
Low-level signals
0/100
  • AI analyst tagged this as a subscription trap.

Suspicious free-trial offer

This page combines a "free trial" or "$1 trial" pitch with auto-renew / rebill language — a classic negative-option billing trap.

  • Treat candy.ai as unverified

    Do not enter credentials or send money until you have independently verified the business.

  • Your card will be charged the full price after the trial

    Most subscription traps bill the full amount ($49-$149) 14 days after sign-up, and every month thereafter. "Cancel anytime" often means you must call a foreign support line that's deliberately hard to reach.

  • If you already signed up — call your bank today

    Ask your bank to block future charges from the merchant and dispute any charges already made. Many banks will issue a new card number to prevent recurring billing. Save the confirmation email as evidence.

  • Report the billing scheme

    Report to the FTC (reportfraud.ftc.gov) or your national consumer-protection body — subscription traps are specifically illegal in most jurisdictions when the auto-bill terms aren't clearly disclosed.

    Open

Reputation Sources

How this domain rates across independent threat-intelligence and blocklist providers.

Google Safe Browsing
Not listedCheck ↗
VirusTotal
Not listedCheck ↗
AbuseIPDB
Not listedCheck ↗

Referenced Domains

Outbound domains this page links to or loads resources from. Each links to its own security scan.

Safety FAQ

Common questions about this site, answered from the scan data on this page. These are auto-generated — not hand-written — so they always match the underlying report.

  • Our automated security review marked candy.ai as suspicious. Several warning signs were detected; it may still turn out legitimate, but you should verify it through independent channels before trusting it with money or credentials.

Final Verdict

0
Trust / 100
Final Verdict·candy.ai
SUSPICIOUS

Candy.ai is an AI girlfriend chat and image service. It is a real registered business with clean technical scans but faces hundreds of complaints about refunds and billing. Review the cancellation policy and start with a short subscription only.

If you try the service, use the shortest subscription possible and document all billing steps. Cancel immediately if the experience does not match expectations.

AV engines
92
MT passes
2
Net signals
0
Scan another URL
Security review completemalwaretips.com/url-scan
Recently scanned

Other Suspicious reports

Browse all reports
Community review

User reviews & comments(0)

Share your experience — "Lost $200 on a fake checkout" is more useful than "Scam". Your review helps others avoid traps.

Loading…
Loading comments…
This report is generated automatically by combining threat intelligence, domain signals, and an AI security analyst. It is informational, not legal advice. Always use your own judgement before sharing personal information or money online.