These demo pages are deliberately crafted phishing lookalikes. With the PhishLens extension installed, visiting them fires a real in-page warning โ driven by page-content signals (credential forms, urgency language, hidden iframes), not just the URL.
โ ๏ธ Fake "PayPal โ account suspended" page password form posting cross-site over HTTP ยท urgency copy ยท CVV field ยท hidden iframe โ Ordinary banking page (control) same-origin HTTPS form ยท calm copy โ should score lowEdit-distance + confusable-character folding catches paypa1, g00gle, Cyrillic lookalikes and punycode tricks like xn--pple-43d.com.
Abused TLDs, user@host deception, raw-IP hosts, shorteners, subdomain stuffing, path keywords (/verify /billing), entropy analysis.
Password forms posting off-domain or over HTTP, requests for CVV/SSN/OTP, hidden iframes, and urgency language ("verify within 24 hours").
Every flag carries a human-readable reason โ the tool teaches users why a link is dangerous, not just that it is.
git clone https://github.com/Georgefifth/phishlens.gitchrome://extensions โ enable Developer mode โ Load unpacked โ select phishlens/extension/about:debugging โ This Firefox โ Load Temporary Add-on โ pick manifest.json