Firefox 浏览器附加组件
  • 扩展
  • 主题
    • 适用于 Firefox
    • 字典和语言包
    • 其他浏览器网站
    • 适用于 Android 的附加组件
登录
PhishTriage 预览

PhishTriage 作者: Culfig OÜ

One-click phishing triage for Gmail, Outlook Web and any page. Reads nothing until you click Analyze.

0(0 条评价)0(0 条评价)
下载 Firefox 并安装扩展
下载文件

扩展元数据

屏幕截图
关于此扩展
PhishTriage tells you whether the thing in front of you is a phishing
attempt.
Open the suspicious email, or the login page that feels
wrong, and click Analyze. You get a verdict with a risk score, the indicators behind it, and what to do next.


On an ordinary web page the extension holds no standing access. It reads
the page under activeTab, which exists only in the moment you click.

One exception, and your browser shows it at install: on Gmail and
Outlook Web (mail.google.com, outlook.office.com,
outlook.office365.com, outlook.live.com) a content script is present
from the start, because that is how the Analyze button reaches the mail
toolbar. Nothing else is touched unless you switch on an optional
feature below.

From an email it sends the subject; the sender, recipient and reply-to
addresses; the body, with quoted threads and signatures stripped; the
links; and attachment filenames, not attachment contents. Who a message
claims to be from is the strongest single signal there is. From any
other page: the title, the visible text, the links, and the full address
including path and query.


A verdict argues; an artifact proves. When a web page you analyze comes
back Malicious or Suspicious, a screenshot of the visible tab and that
page's HTML go up with it, so the site can be reported to its host or
registrar. This is the one setting here that starts on: setup shows
it, and the switch is in the popup. Nothing is captured on a benign
verdict, and nothing on Gmail or Outlook Web, where the screenshot would
be of your inbox. Webmail on any other host counts as an ordinary page,
and there the picture is of your inbox — the privacy policy names the
providers this affects. Both are held in memory for the seconds the scan
takes, never written to your disk. Confirmed malicious is kept 12 months,
suspicious 30 days, and a capture a reviewer clears is deleted at once.


Background protection checks each site as it loads and shows a
full-page warning if it is known bad. Your browser asks permission
first; decline, or revoke later. Only the hostname is sent, not the page
you are on. Separate switches send full URLs instead, and cache a site
for an hour; both off.

File protection (Chrome, Edge, Brave) checks your downloads. A
fingerprint goes up with the file's name, its size, and what the
on-device check made of it; the file itself only when you ask for that
one file, or on every download if you switch on
Deep scan every file. Another switch holds files a page builds in your
browser and asks before they save, instead of warning after. For an
ordinary download the extension fetches the file's address a second time
— a browser hands an extension a download's details, not its contents —
and that request carries your cookies as the first did.


No third-party analytics, advertising or telemetry. No identity
permission: it never asks your browser or your mail provider who you
are. Your install is identified by a random id,
replaced at registration by one our server issues; it registers once at
install, sending that id, your browser name, and an enrolment token if
an administrator set one. The feedback buttons under a verdict record
your correction on your own device and send nothing.


Sign in from the popup and the portal opens to finish the link. An
administrator links the device to your organisation there; the extension
never takes a credential. For a fleet, push an enrolment token by
managed policy and devices join at install. Policy also pins the backend
and sets the monitoring, file-protection, deep-scan and evidence
switches for everyone, in either direction, so on a managed device a
switch may already be on, or held off.
评分 0(1 位用户)
登录以评价此扩展
目前尚无评分

已保存星级评分

5
0
4
0
3
0
2
0
1
0
尚无评价
权限与数据

必要权限:

  • 访问您在 mail.google.com 的数据
  • 访问您在 outlook.office.com 的数据
  • 访问您在 outlook.office365.com 的数据
  • 访问您在 outlook.live.com 的数据

可选权限:

  • 下载文件和读取与修改浏览器的下载历史
  • 获知浏览器导航时的行为状态

根据开发者所述,必要的数据收集:

  • 个人通信
  • 个人身份信息
  • 网站内容

根据开发者所述,可选的数据收集有:

  • 浏览活动
  • 网站活动
详细了解
更多信息
附加组件链接
  • 主页
  • 用户支持网站
  • 支持邮箱
  • 复制附加组件 ID
版本
1.0.0
大小
144.31 KB
上次更新
9 天前 (2026年8月14日)
相关分类
  • 隐私和安全
许可证
保留所有权利
隐私政策
阅读此附加组件的隐私政策
版本历史
  • 查看所有版本
标签
  • security
添加到收藏集
举报此附加组件
转至 Mozilla 主页

附加组件

  • 关于
  • Firefox 附加组件博客
  • 扩展工坊
  • 开发者中心
  • 开发者政策
  • 社区博客
  • 论坛
  • 报告缺陷
  • 评价指南

下载

  • Download Firefox
  • Windows
  • macOS
  • iOS
  • Android
  • Linux
  • All

最新版本

  • Nightly
  • Beta

商用版 Firefox

  • Enterprise

社区

  • Connect
  • Contribute
  • Developer

关注

  • Instagram
  • YouTube
  • TikTok
  • Bluesky
  • Podcast
  • 隐私
  • Cookie
  • 法律

除非另有注明,否则本网站上的内容可按知识共享 署名-相同方式共享 3.0 或更新版本使用。