What 10,502 Online Stores Reveal About Trust Signals
Most advice about spotting a dubious online store repeats the same rules of thumb: check how old the domain is, look for a returns policy, see whether they have social accounts. We had the chance to test those rules against data rather than intuition — we run automated public-signal checks on 10,502 independent online stores, and this is what the corpus actually shows.
Two of the findings cut against the standard advice. Read the methodology and limitations before quoting any of it; several of these numbers measure what an automated checker can see, which is not the same as what exists.
Finding 1: domain age is a weak predictor on its own
"Check the domain age" is the most repeated piece of advice in this space. Across 7,576 stores where we could read a WHOIS creation date, the correlation between domain age and our overall trust score is r = 0.144 — positive, but weak. Age carries real information at the extremes and very little in the middle.
| Domain age | Stores | Mean trust score | No social presence | Avg. policy pages (of 4) |
|---|---|---|---|---|
| <6 months | 55 | 49.5 | 52.7% | 1.95 |
| 6–12 months | 148 | 59.3 | 50.7% | 2.01 |
| 1–2 years | 442 | 76.5 | 43.2% | 1.83 |
| 2–5 years | 1,489 | 78.6 | 34.5% | 1.9 |
| 5–10 years | 2,038 | 79.6 | 27.7% | 1.91 |
| 10+ years | 3,404 | 81.6 | 22.3% | 2.02 |
The mean score climbs steeply from 49.5 for domains under six months to 76.5 by the one-to-two-year mark, then flattens — the gap between a two-year-old store and a ten-year-old one is only about 3.0 points. A brand-new domain is worth extra care. A three-year-old domain is not meaningfully safer than an eleven-year-old one, and treating age as a headline signal will mislead you in both directions.
Finding 2: newer stores publish more policy pages, not fewer
The intuition is that young stores cut corners on paperwork. The corpus says the opposite: stores under six months old carry an average of 1.95 of the four standard policy pages, more than every other age bracket including the 10+ years group at 2.02.
The likely explanation is not virtue but defaults. Modern store platforms ship privacy, terms, refund and shipping templates out of the box, so a store built last month starts with them; one built a decade ago on an older stack often never added them. That makes policy-page presence a decent signal of platform vintage and a poor signal of trustworthiness. Note the small sample in that youngest bracket (55 stores), which is why we would not lean on it hard.
Finding 3: absent social presence tracks age strongly
Social presence is the signal that separates age brackets most cleanly. 52.7% of stores under six months old link to no major social platform at all, falling steadily to 22.3% among domains over ten years old. Across the whole corpus, 27.68% link to none.
Where the 10,502 measured stores do have a presence:
- Facebook — 62.64%
- Instagram — 52.71%
- Youtube — 24.51%
- Twitter — 22.61%
- Linkedin — 15.05%
- Pinterest — 13.16%
- Tiktok — 11.23%
The TikTok figure (11.23%) is worth noting given how much attention TikTok-advertised storefronts get in scam coverage: they are a real phenomenon but a small share of independent e-commerce overall.
Finding 4: complete policy coverage is the exception
Only 2,218 stores (21.1%) publish all four standard policy pages where our checker can find them, while 2,259 (21.5%) have none we could detect. By type:
| Page | Not detected |
|---|---|
| privacy | 34.96% |
| terms | 40.94% |
| refund | 64.14% |
| shipping | 66.53% |
| contact page | 12.88% |
Refund and shipping policies are missing far more often than privacy and terms, which is the reverse of what a shopper cares about — privacy policies are driven by regulation, whereas the pages that tell you what happens when an order goes wrong are the ones most often absent. If you check one thing before buying from an unfamiliar store, make it the returns policy.
Methodology and limitations
We checked 10,502 independent online stores, each fetched once. Signals are read from the homepage plus a small set of conventional policy-page paths. Data as of 2026-08-10. Figures update when the corpus is re-analysed.
These limitations genuinely constrain the numbers above:
- Detection is not existence. Every "missing" figure means not discoverable by an automated check of the homepage and common paths. A policy linked only from a checkout flow, rendered by JavaScript after load, or placed at an unconventional URL reads as absent here. Treat these as floors on what exists, not counts of what does not.
- Language coverage is partial. Policy-page detection recognises English, German, French, Spanish and Italian naming conventions. Stores operating in other languages — Dutch, Polish, Russian, Portuguese and Vietnamese all appear in this corpus — are undercounted, so the true coverage rates are higher than reported.
- Two signals are excluded entirely. Our physical-address check only reliably matches English street-address formats, so it under-detects non-English sites by roughly threefold and is not reported here. Third-party review lookups were blocked for effectively the whole corpus, so review presence is also excluded.
- WHOIS coverage is incomplete. A creation date was available for 7,576 of 10,502 domains (72.1%); age findings cover only those.
- The sample is not representative of all e-commerce. It skews heavily toward one platform (WooCommerce at 85.43%) and toward independent stores rather than marketplaces or large retailers. Median domain age is 8.9 years and only 2.68% are under a year old, so this is a corpus of mostly established small stores.
- Correlation, not causation. The trust score is computed from several of the same signals broken out in these tables, so the age/score correlation is not independent evidence.
Related
See also Shopify vs WooCommerce: trust signals compared, or all research.
Browse the underlying pages
Every store in this analysis has its own signal breakdown. Browse the full A–Z index, or by platform, country, or trust level.