Update PhishClean 1.5.0 is live on Chrome and Firefox: reported phishing sites blocked for free, and fake virus pages caught. Edge follows shortly. See what's new →
3.4 billion phishing emails are sent every day - FBI

Your browser is leaking
PhishClean stops it.

Catches phishing pages, leaked secrets, and stolen credentials in real time - 100% on your device.

Live on Chrome, Firefox & Edge 15-day free trial and no credit card required

Try these right now - no install, no signup, 100% private

View all 7 tools →

You're more exposed than you think
🎣

Phishing pages that look identical to the real thing

A pixel-perfect clone of your bank's login, hosted on secure-bankofamerica.com. You type your password. It goes to someone in another country. Chrome Safe Browsing might catch it hours later - if someone reports it first. Most phishing pages only exist for a few hours, which is exactly long enough to harvest credentials and disappear before the blocklist updates.

🔑

Tokens leaking from URLs and storage

JWTs in query strings get logged everywhere - analytics, proxies, browser history, every extension with URL access. One XSS vulnerability on the page and localStorage tokens are gone too.

👻

Auth headers sent to the wrong server

A compromised third-party widget quietly copies your Authorization headers to an external domain. Your session is hijacked. The page looks completely normal. You'd never know unless something was watching the network requests.

🔐

Secrets in client-side code

AWS keys (AKIA...), Stripe live keys, GitHub tokens - hardcoded in JavaScript bundles where any visitor can read them. Bots scrape for these patterns constantly. One leaked key can cost thousands.

🔓

HTTPS silently stripped to HTTP

Coffee shop WiFi. A man-in-the-middle downgrades your connection. You see your bank's real content - unencrypted.

Everything PhishClean watches for
✅

Link safety tooltips

Hover any link to see a safety check - green tick, yellow caution, or red alert.

Free
🔒

Password field detection

Flags pages with login forms that could be phishing.

Free
🌐

Domain mismatch

Catches forms that submit credentials to a different domain.

Free
🔎

Secret Leak Scanner

Detects AWS, Stripe, GitHub, Slack, Twilio, SendGrid keys in page source.

Pro
🔐

Private key detection

Catches exposed RSA/EC private keys - critical security risk.

Pro
🔓

HTTPS downgrade alerts

Warns when you're redirected from HTTPS to HTTP.

Pro
⚠️

HTTP password warning

Alerts when password fields appear on unencrypted pages.

Pro
📄

JWT token leak detection

Spots JWT tokens exposed directly in URLs.

Pro
📡

Auth header monitoring

Detects Authorization headers sent to third-party domains.

Pro
💻

Hidden iframe detection

Finds invisible iframes that could capture credentials.

Pro
🔗

Backlink impersonation

Flags pages that borrow trust with real brand policy links, logos, and support assets.

Pro
👁

Visual anomaly heuristics

Detects unusual form structures that don't match typical logins.

Pro
🗃

Token storage scanning

Checks localStorage for exposed tokens and secrets.

Pro
🔍

URL parameter scanning

Flags sensitive params like token, auth, session in URLs.

Pro
🌐

HTTPS context switch

Detects navigation from HTTPS sites to HTTP pages.

Pro
📍

Login region analysis

Checks login area layout against typical patterns.

Pro
Three steps. Zero data shared.
1

Install the extension

Get PhishClean from the Chrome Web Store, Firefox Add-ons, or Edge Add-ons, click install, and confirm the permissions prompt. Protection starts immediately — no account, no card. Reported-phishing blocking, link safety and password-field checks run permanently, and the other 17 signals run free for 15 days. When the trial ends those 17 pause and the permanent three keep going. Works on Chrome, Firefox, Edge, and any Chromium-based browser (Brave, Vivaldi, Arc).

2

Every page gets checked - silently

Each time a page loads, PhishClean runs its detection signals right inside your browser. It checks the DOM for exposed API keys, inspects form actions for domain mismatches, looks for hidden iframes, and flags HTTPS-to-HTTP downgrades. All of this happens locally. Nothing leaves your machine.

3

You see a warning only when it matters

No notification spam. If PhishClean finds something - a login page that sends credentials to a different domain, a leaked Stripe key in page source, a suspicious iframe - you get one clear alert explaining what's wrong and what you can do about it.

Simple, fair pricing
Monthly Annual Save 45%
15-Day Trial
$0 for 15 days
  • Full protection for 15 days
  • All 20 detection signals included
  • No account, no card — starts at install
  • Local whitelist management
  • 60+ trusted domains built-in
  • Privacy-first architecture

The 15-day trial starts at install — no account, no card. When it ends, reported-phishing blocking, link safety and password-field checks keep running for free; subscribe to restore the other 17 signals.

Security scanning as an API
Free tier - 30 requests/hour

Integrate phishing detection into your app

8 REST endpoints covering URL scanning, password analysis, email phishing detection, header authentication checks, JWT security audits, secret leak scanning, full page risk scoring, and backlink impersonation detection.

Free tier: 30 req/hr with no key. Upgrade to Pro ($19/mo), Business ($49/mo), or Enterprise ($700/yr) for up to unlimited requests with API key authentication.

Works with Claude, Gemini, Copilot, and any HTTP client via our MCP server.

# Check a URL for phishing
POST /api/v1/check-link
POST /api/v1/check-password
POST /api/v1/check-email
POST /api/v1/analyze-headers
POST /api/v1/decode-jwt
POST /api/v1/scan-secrets
POST /api/v1/scan-page
POST /api/v1/analyze-backlinks
# Example
curl -X POST /api/v1/check-link \
-d '{"url":"https://paypal-secure.xyz"}'

8 Endpoints

URL, password, email, headers, JWT, secrets, full page scan, backlinks

Free tier, no key

30 req/hr free. API keys for Pro, Business & Enterprise tiers.

AI-Ready (MCP)

Works with Claude, Gemini CLI, and Microsoft Copilot

API pricing & keys
MCP Server on npm npm i phishclean-mcp
How we compare
Feature PhishClean Pro Chrome Safe Browsing Norton Safe Web McAfee WebAdvisor
Phishing page detection Yes Yes Yes Yes
Form domain mismatch Yes No No No
API key / secret scanning Yes No No No
Private key detection Yes No No No
JWT token leak detection Yes No No No
Auth header monitoring Yes No No No
HTTPS downgrade alerts Yes Partial No No
localStorage scanning Yes No No No
100% local / private Yes Sends URLs to Google Cloud-based Cloud-based
Detection signals 18 Blocklist Reputation Reputation
Price $9/mo Free Free Free
Zero data leaves your browser. Ever.

Stays on your device

  • All page analysis and scoring
  • Phishing detection heuristics
  • Secret and API key scanning
  • URL and token scanning
  • Whitelist and preferences
  • Alert history

Touches our server

  • Install ID (UUID)
  • Account email and license status (trial/paid)
  • Extension version number
  • Nothing else. Ever.
Common questions
Does PhishClean see my passwords or browsing history?

No - and it can't, by design. Every detection signal runs inside your browser tab. Your passwords, URLs, and page content never leave your machine for detection. We only collect the account and billing information needed to activate and manage your subscription: your install ID, account email, license state, and extension version.

What does the Secret Leak Scanner detect?

It checks page code locally in your browser for exposed secret patterns that should not be publicly visible — things like AWS access keys (they start with AKIA), live Stripe keys (sk_live_), GitHub personal access tokens, Slack webhooks, Twilio and SendGrid keys, and RSA/PEM private keys. Test keys and common documentation examples are filtered out to reduce false positives. More detail on the Secret Leak Scanner page.

What happens before I pay?

Protection starts the moment you install, with no account. Every signal runs free for 15 days - including secret scanning, JWT detection, HTTPS downgrade alerts, iframe analysis and auth header monitoring. When the trial ends, three signals keep running permanently - blocking of reported phishing sites, hover-to-check link safety, and a warning when a login form posts your password to a different domain - and the other 17 pause until you subscribe.

Do I need an account to use PhishClean?

No. Protection runs from the moment you install, with no account and no card. We ask for an email once during the trial, so your plan follows you to another browser and survives a reinstall - you can decline and keep using it. An account is only required to subscribe.

Does it slow down my browser?

We haven't seen it. PhishClean runs its checks once when a page finishes loading - it's a quick pass through the DOM, not a persistent background process. There are no network requests involved in detection (everything is local), so there's nothing to add latency. On a typical page it finishes in low single-digit milliseconds.

Will it trigger alerts on Google, Amazon, or my bank?

No. We maintain a built-in list of 60+ trusted domains - Google, GitHub, Amazon, Microsoft, major banks, payment processors, identity providers - and those skip detection entirely. You can also add your own domains to the whitelist if you use internal tools or staging environments that you trust.

Which browsers does it support?

PhishClean is available on the Chrome Web Store, Firefox Add-ons, and Edge Add-ons. Any Chromium-based browser - Brave, Vivaldi, Arc - can also install it from the Chrome Web Store.

How is PhishClean different from Google Safe Browsing?

Google Safe Browsing, which is built into Chrome and Firefox, checks each address against a list of sites already reported as dangerous. A phishing page set up this morning isn't on that list yet. PhishClean doesn't rely on a list: it reads the page you're on and checks what it does, such as a login form that sends your password to a different domain. The two work well together. See the full comparison.

Can PhishClean catch a brand-new phishing site?

Yes. Many phishing pages are online for less than a day, so they disappear before blocklists catch up. PhishClean doesn't need to have seen a site before. It looks for warning signs in the page itself, such as a lookalike domain, a login form that posts to another site, or a page copying a brand it doesn't belong to.

What happens when PhishClean finds a suspicious page?

It shows a warning over the page with a risk score and the reasons it was flagged. You can go back, ignore it once, or trust the domain if you know it's safe. PhishClean warns rather than blocks, so the decision is always yours. If you already entered a password or card number, follow our recovery guide.

Why does PhishClean ask to read data on all websites?

To check a page, PhishClean has to be able to look at it, and phishing can appear on any site, so your browser shows this standard permission. The checks run on your device: the pages you visit and what you type are not sent to us for detection. The source code is public if you want to verify it.

How much does PhishClean cost?

All checks are free for the first 15 days, with no card needed. After that it's $9 a month or $59 a year. In India, prices are in rupees. If you don't subscribe, three checks stay free for good: blocking of reported phishing sites, hover-to-check link safety, and the warning when a login form sends your password to another domain.

Can I use PhishClean with my antivirus or ad blocker?

Yes. Ad blockers filter network requests, and most antivirus browser extensions check sites against a reputation list. PhishClean checks what the page itself is doing, so it catches different things and runs alongside them without conflict. See how it compares with other security extensions.

I clicked a phishing link. What should I do?

If you only opened the page, close it and don't enter anything. If you typed a password, change it on the real site and anywhere you reuse it, then turn on two-factor authentication. If you entered card or bank details, call your bank straight away. Our step-by-step guide covers each case.

Does PhishClean work on phones?

PhishClean is made for desktop browsers: Chrome, Firefox, Edge, and Chromium-based browsers such as Brave. Most phone browsers don't support extensions, so for now it's a desktop tool.

Can I see PhishClean's source code?

Yes. The extension's code is public on GitHub, so anyone can check what it does and confirm that detection runs locally.

Can I get a refund?

If something is not working right, reach out to support@phishclean.com and we will help. Refund handling depends on the payment status and issue details, so contact us and we will review it quickly.

Get in touch

Need help?

Have a question about PhishClean, need support, or want to report a bug? We'd love to hear from you.

You can also reach us directly at support@phishclean.com