WebGuard by Elevven11
1 rating
)Overview
Spot suspicious websites, protect sensitive information and understand security risks while you browse. Free and private.
WebGuard checks the page you are on for the signs of phishing, and warns you before you hand sensitive information to a site that should not have it. Every check runs on your device. There is no account, no subscription, no analytics and no server. Online checks are off by default, and with them off WebGuard makes no network requests at all. WHAT IT CHECKS Website security — HTTPS, URL structure, redirect parameters, credentials embedded in an address, unusual ports, encoded addresses and risky file types. Phishing — brand impersonation across 34 commonly imitated services, typosquatting, homograph and mixed-script characters, brand names hidden in subdomains, and a page title that disagrees with its domain. Domains — registered-domain extraction, raw IP addresses used as hosts, Punycode, and subdomains dressed up to look like domains. Forms — login and payment form detection, passwords sent over http, and forms that post to a different domain than the one you are on. Passwords — strength, common passwords and character substitutions, keyboard runs and sequences, and a breach check that never transmits your password. Sensitive data — API keys, tokens, JWTs, private keys, database connection strings, card numbers checked with Luhn, IBANs and crypto addresses, in text you select. Privacy — 124 known trackers, third-party requests, cookies and local storage. Threat lists — known malicious and phishing addresses, matched on your device against downloaded hash prefixes. HOW IT REPORTS Low Risk, Suspicious, High Risk or Unknown. Never "safe". Only High Risk interrupts you. Suspicious puts a badge on the toolbar icon and waits to be asked. No single weak observation can produce a warning: risk is the sum of several signals, each scaled by how confident the check is, because a warning you learn to click through protects nobody. A blocklist miss is not evidence of safety, so threat-list coverage is reported separately from the verdict. "Checked against current lists and not listed", "no lists downloaded" and "lists out of date" are three different answers, and WebGuard will not present the last two as a clean result. PRIVACY Password fields are never read. The input monitor skips them entirely. Passwords are never transmitted. The breach check hashes the password on your device and sends the first five characters of that hash, which returns a bucket of several hundred candidates to compare locally. The service cannot learn your password, or even its full hash. Secrets are never stored. The sensitive-data scanner returns an offset and a mask, never the matched value, so nothing downstream of it can display, keep or send a credential even by accident. The addresses you visit are never sent. Threat lists are downloaded and matched on your device. The only request in the product derived from a page carries four bytes of a hash, which a great many addresses share. History is off by default, and a record holds only a hostname, a verdict, a score and a time. Pages you merely visit are never recorded. Settings has a reset that clears every piece of local data. WHAT WEBGUARD IS NOT Not an antivirus, not a password manager, and not a guarantee. It helps you make a safer decision with better information. It cannot promise a site is safe, and it does not replace security software. KEYBOARD Ctrl+Shift+W checks the current website and Ctrl+Shift+U scans selected text for sensitive data. Both can be changed at chrome://extensions/shortcuts. Free, and staying free. WebGuard carries one house advertisement for the studio's own work, at the foot of the popup, labelled "Ad", served from a list that ships inside the extension: opening the popup makes no request and tells nobody it was opened. One click turns it off permanently. MIT licensed, from Elevven11 Studio.
5 out of 51 rating
Details
- Version1.0.0
- UpdatedOctober 3, 2026
- Offered byElevven11 Studio
- Size407KiB
- LanguagesEnglish
- Developer
Email
elevven11studio@gmail.com - Non-traderThis developer has not identified itself as a trader. For consumers in the European Union, please note that consumer rights do not apply to contracts between you and this developer.
Privacy
This developer declares that your data is
- Not being sold to third parties, outside of the approved use cases
- Not being used or transferred for purposes that are unrelated to the item's core functionality
- Not being used or transferred to determine creditworthiness or for lending purposes
Support
For help with questions, suggestions, or problems, visit the developer's support site