How PhishFlag works
PhishFlag is a defensive tool: it inspects a link the way a security analyst would — structure first, then network behavior, then page contents, then external intelligence — and turns everything into one weighted score with a plain-English explanation.
What the scanner never does
- It never executes JavaScript from the scanned page.
- It never downloads files — HTML reading is capped at 200 KB and non-HTML bodies are discarded.
- It never scans private or internal addresses (localhost, 10.x, 172.16–31.x, 192.168.x, 169.254.x, ::1), and every redirect hop is re-checked so a public site can't bounce the scanner into an internal network.
- It never stores your raw IP — only a salted hash used for rate limiting.
- It never fabricates results: a feed with no API key configured is labeled “not configured,” never guessed.
Risk bands
No known threats were found. The URL is clean across all configured feeds and raised no structural or network red flags.
A few weak signals (an unusual TLD, a shortener, a long URL). Nothing conclusive, but worth a second look.
Multiple independent indicators. Treat the link with caution and avoid entering credentials.
Strong evidence of malicious intent — threat-feed hits, brand impersonation, or credential-harvesting patterns.
Confirmed by verified threat intelligence (PhishTank verified, URLhaus match, admin blacklist). Do not visit.
Scoring weights (key signals)
Signals stack; the total is capped at 100. Structural heuristics alone are capped at 45 so the URL's shape can raise suspicion but never single-handedly condemn a site.
Honest limitations
No automated scanner is perfect. Brand-new phishing sites may not yet appear in any feed ("Unknown" or a low score is not a guarantee of safety), and legitimate sites can occasionally trip heuristics. A low score means this scan found no known threats — it never means a link is definitely safe. Always verify the sender before entering passwords, payment details, or personal information.