PhishLens

Real-time phishing detection that runs entirely in your browser โ€” and explains itself.
100% client-side no uploads, no tracking browser extension + web analyzer TLN Cybersecurity Challenge 2026

๐Ÿ” Analyze a link โ€” right here, right now

๐ŸŽฃ Live bait pages (test the extension)

These demo pages are deliberately crafted phishing lookalikes. With the PhishLens extension installed, visiting them fires a real in-page warning โ€” driven by page-content signals (credential forms, urgency language, hidden iframes), not just the URL.

โš ๏ธ Fake "PayPal โ€” account suspended" page password form posting cross-site over HTTP ยท urgency copy ยท CVV field ยท hidden iframe โœ… Ordinary banking page (control) same-origin HTTPS form ยท calm copy โ†’ should score low

How it works

Typosquat & homoglyph radar

Edit-distance + confusable-character folding catches paypa1, g00gle, Cyrillic lookalikes and punycode tricks like xn--pple-43d.com.

URL forensics

Abused TLDs, user@host deception, raw-IP hosts, shorteners, subdomain stuffing, path keywords (/verify /billing), entropy analysis.

Page-content signals

Password forms posting off-domain or over HTTP, requests for CVV/SSN/OTP, hidden iframes, and urgency language ("verify within 24 hours").

Explainable score

Every flag carries a human-readable reason โ€” the tool teaches users why a link is dangerous, not just that it is.

Install the extension (2 minutes)

  1. Clone the repo: git clone https://github.com/Georgefifth/phishlens.git
  2. Chrome โ†’ chrome://extensions โ†’ enable Developer mode โ†’ Load unpacked โ†’ select phishlens/extension/
  3. Firefox โ†’ about:debugging โ†’ This Firefox โ†’ Load Temporary Add-on โ†’ pick manifest.json
  4. Browse normally โ€” the toolbar badge shows each page's risk. Open this page's bait links to see it fire.