Item logo image for ExecFence — stop paste-and-run scams

ExecFence — stop paste-and-run scams

ExtensionPrivacy & Security
Item media 4 (screenshot) for ExecFence — stop paste-and-run scams
Item media 1 (screenshot) for ExecFence — stop paste-and-run scams
Item media 2 (screenshot) for ExecFence — stop paste-and-run scams
Item media 3 (screenshot) for ExecFence — stop paste-and-run scams
Item media 4 (screenshot) for ExecFence — stop paste-and-run scams
Item media 1 (screenshot) for ExecFence — stop paste-and-run scams
Item media 1 (screenshot) for ExecFence — stop paste-and-run scams
Item media 2 (screenshot) for ExecFence — stop paste-and-run scams
Item media 3 (screenshot) for ExecFence — stop paste-and-run scams
Item media 4 (screenshot) for ExecFence — stop paste-and-run scams

Overview

Warns you before you paste a command a website told you to run in Terminal or PowerShell. Never uploads what you copy.

ExecFence protects you from a fast-growing scam called "ClickFix." A web page — often a fake CAPTCHA, a fake "verify you are human" check, or a fake browser/error message — tells you to copy a command, open Terminal, PowerShell, or the Windows Run box, paste it, and press Enter. The command it quietly placed on your clipboard downloads and runs someone else's program on your computer. Your antivirus usually stays quiet, because you opened the terminal and ran it yourself. ExecFence watches for exactly that trap. The instant a page combines a "verification" or "fix this" story with an instruction to leave the browser and a real, runnable command, it steps in with a clear warning — before you paste — and tells you, in plain words, what the page asked you to do and what that command would actually do (does it reach the internet? download a program? run what it downloads?). You can clear the tricked clipboard, close the tab, inspect the command, or continue anyway. You are always in control. It is built to be quiet. On the pages developers really do copy commands from — GitHub, Homebrew, package managers, Stack Overflow — it stays silent. It only speaks up when a page is trying to trick you. Private by design: • Everything is checked on your own computer. Nothing is sent to any server. • It never reads your system clipboard — it only inspects what a page writes. • It keeps a local log of warnings (site, time, rule, and a hash of the command — never the command text), which you can view, export, or clear. Nothing ever leaves your device. One permission only (storage), no access to your browsing history, no network access. ClickFix is the first scam ExecFence covers; the same protection extends to fake updates, fake tech support, and clipboard-swap tricks. Privacy practices tab (this is where the other 5 live) Single purpose → Warn users before they run a command that a website socially-engineered them into pasting into a terminal (the ClickFix / fake-CAPTCHA scam), and explain what that command would do. Permission justification → "storage" → Stores the user's settings and a local history of warnings (site, time, matched rule, and a SHA-256 hash of the command — never the command text) so the user can review, export, and delete them. Everything stays on the user's device. Permission justification → host access / "all sites" (this is error #1 — it's asking about the content script running on every site) → The scam can appear on any website, including legitimate sites that have been compromised, so the extension must inspect each page for the scam pattern. It reads the page only to detect the pattern and never stores or transmits page content. Are you using remote code? → select No. (That alone clears error #2 — "No" needs no justification. Everything the extension runs ships inside the package.) Data usage → for "Does this item collect user data?" the honest answer is that it collects none — declare no data collected, then tick all three certification checkboxes at the bottom: not sold/transferred to third parties (outside approved cases) not used for anything unrelated to the single purpose not used for creditworthiness / lending

Details

  • Version
    0.3.0
  • Updated
    September 28, 2026
  • Size
    66.67KiB
  • Languages
    English (United States)
  • Developer
    Acid Alchamy
    613 Greenway Rd Henderson, NV 89002-8318 US
    Website
    Email
    radtkechristopher@yahoo.com
  • Non-trader
    This developer has not identified itself as a trader. For consumers in the European Union, please note that consumer rights do not apply to contracts between you and this developer.

Privacy

Manage extensions and learn how they're being used in your organization
The developer has disclosed that it will not collect or use your data. To learn more, see the developer’s privacy policy.

This developer declares that your data is

  • Not being sold to third parties, outside of the approved use cases
  • Not being used or transferred for purposes that are unrelated to the item's core functionality
  • Not being used or transferred to determine creditworthiness or for lending purposes

Support

For help with questions, suggestions, or problems, visit the developer's support site

Google apps