Item logo image for PhishDestroy + FFraud Guard

PhishDestroy + FFraud Guard

ExtensionPrivacy & Security
Item media 3 (screenshot) for PhishDestroy + FFraud Guard
Item media 1 (screenshot) for PhishDestroy + FFraud Guard
Item media 2 (screenshot) for PhishDestroy + FFraud Guard
Item media 3 (screenshot) for PhishDestroy + FFraud Guard
Item media 1 (screenshot) for PhishDestroy + FFraud Guard
Item media 1 (screenshot) for PhishDestroy + FFraud Guard
Item media 2 (screenshot) for PhishDestroy + FFraud Guard
Item media 3 (screenshot) for PhishDestroy + FFraud Guard

Overview

Blocks phishing and malicious websites using PhishDestroy domain intelligence and FFraud IP reputation.

PhishDestroy + FFraud Guard is a browser navigation guard designed to reduce exposure to known phishing domains and malicious web infrastructure. It combines PhishDestroy domain intelligence with cautious FFraud IP-reputation checks and gives you control over how aggressively protection behaves. HOW PROTECTION WORKS The extension checks top-level HTTP and HTTPS pages as they begin to load. The page is briefly hidden while a decision is requested, for no longer than approximately 2.6 seconds. If a blocking rule matches, navigation is replaced with a local warning page showing the domain, risk information, intelligence source and reason for the decision. You can go back, inspect the details or deliberately add the domain to your personal allowlist. If no blocking condition matches, the page is shown normally. Local and private-network addresses are excluded. Domains belonging to the protection services themselves are also excluded to prevent loops. A domain on your personal allowlist bypasses all protection, including its subdomains. THREAT INTELLIGENCE USED 1. PhishDestroy local threat database The primary defence is a merged local database built from five public PhishDestroy sources: Primary, Active Domains, Community, Community Live and Root Domains. The official PhishDestroy allowlist is applied before entries are stored. Ordinary feed entries use exact-hostname matching; only entries from the dedicated Root Domains source can extend blocking to subdomains. This is intended to improve coverage without automatically treating every sibling on shared hosting as malicious. The feeds are downloaded sequentially from the public PhishDestroy GitHub repository on first installation and are scheduled to refresh every four hours. The Options page opens on first install and shows live progress while sources download, domains are deduplicated and the local database is built. You can also refresh it manually. If the required Primary feed or official allowlist fails, an existing working database is preserved rather than replaced with an incomplete or unprotected one. For lower IndexedDB overhead, approximately one million domains can be packed into roughly 1,024 database buckets instead of using one database object per domain. Upgrades migrate away from the earlier per-domain store and rebuild the compact database during the next refresh. Settings reports the approximate compact payload size. 2. PhishDestroy API fallback When enabled, domains not blocked by the local feed are checked against the live PhishDestroy Threat API. A domain is blocked only when the API marks it as a threat and its risk score meets your configured PhishDestroy threshold. The default threshold is 40, corresponding to High severity in the extension's displayed scale. API results are cached locally for six hours. 3. FFraud public-IP intelligence When enabled, the hostname is resolved through Cloudflare DNS-over-HTTPS using A and AAAA queries. Up to three resulting public server IP addresses are checked with FFraud. FFraud does not block merely because an address is associated with a VPN, proxy, Tor exit node, hosting provider or data centre. An FFraud block requires all of the following: the score meets your configured threshold (85 by default), FFraud reports the address as a confirmed abuser, and the returned evidence is relevant to a web threat such as phishing, malware, credential theft, command-and-control, botnet activity, a web attack or an exploit kit. FFraud results are cached locally for 30 minutes. CONTROLS AND INFORMATION You can: • enable or disable protection; • enable or disable the local PhishDestroy feed, live API fallback and FFraud checks separately; • change the PhishDestroy and FFraud blocking thresholds; • enable Strict Mode; • add trusted domains to a local allowlist; • check a website manually; • refresh the threat feed; • view checked and blocked counters, individual source results, compact database size and last-refresh information; • see live download/database-building progress during a refresh; • see an ON or OFF badge on the toolbar icon when the extension is pinned. Browsers do not allow an ordinary extension to pin itself. The first-run Options page explains how to pin it from the browser's Extensions menu. Strict Mode is off by default. In normal mode, a failed or timed-out live check does not by itself block the page. With Strict Mode enabled, the extension blocks when the PhishDestroy API is required but cannot be reached. Strict Mode does not turn the extension into an offline guarantee and may prevent access during a service or network outage. DATA HANDLING To perform enabled live checks, the extension may send: • the website hostname to the PhishDestroy API; • the hostname to Cloudflare DNS-over-HTTPS; • the public IP addresses returned by DNS to FFraud. It also downloads the five public PhishDestroy intelligence feeds and official allowlist from GitHub. As with ordinary internet requests, those service providers can receive connection metadata such as the device's public IP address. URL paths, query strings, page text, images, form contents, passwords and keystrokes are not sent to PhishDestroy, Cloudflare or FFraud by this extension. The full URL is used inside the browser to make and display a decision. For blocked pages, the extension keeps a local history of up to 100 block records; a record can include the full blocked URL, hostname, time, score, severity, source, reason and resolved IP. Settings, allowlists, counters, downloaded intelligence and cached results are also stored locally in Chrome. The extension's executable JavaScript is included in the installed package; it does not download and execute remote code. HOW PROTECTIVE IS IT? This extension can stop navigation when the available intelligence identifies the hostname or its public infrastructure strongly enough to satisfy the configured rules. Local-feed matches are fast, while live services can add more recent or infrastructure-based evidence. The conservative FFraud rule is intended to reduce false positives from shared hosting, VPNs, proxies and similar infrastructure. It is not a guarantee that a site is safe. New or short-lived threats may not yet appear in any feed, services can be unavailable, attackers can change domains or infrastructure, and legitimate sites can occasionally be misclassified. In normal mode, unavailable live services fail open. Reducing thresholds or enabling Strict Mode can increase blocking but can also increase false positives or prevent access during outages. Adding a domain to the allowlist disables protection for that domain and its subdomains. The extension does not analyse page content, scan downloaded files, inspect passwords or form submissions, remove malware already on the device, or replace Chrome Safe Browsing, antivirus software, security updates, multi-factor authentication and careful judgement. It should be used as an additional layer of defence, not as the only security control.

Details

  • Version
    0.0.0.4
  • Updated
    August 29, 2026
  • Size
    29.98KiB
  • Languages
    English (United Kingdom)
  • Developer
    Email
    2e0lxy.daren@gmail.com
  • Non-trader
    This developer has not identified itself as a trader. For consumers in the European Union, please note that consumer rights do not apply to contracts between you and this developer.

Privacy

Manage extensions and learn how they're being used in your organization

PhishDestroy + FFraud Guard has disclosed the following information regarding the collection and usage of your data. More detailed information can be found in the developer's privacy policy.

PhishDestroy + FFraud Guard handles the following:

Location
Web history
User activity

This developer declares that your data is

  • Not being sold to third parties, outside of the approved use cases
  • Not being used or transferred for purposes that are unrelated to the item's core functionality
  • Not being used or transferred to determine creditworthiness or for lending purposes

Support

For help with questions, suggestions, or problems, visit the developer's support site

Google apps