How PhishFlag works

PhishFlag is a defensive tool: it inspects a link the way a security analyst would — structure first, then network behavior, then page contents, then external intelligence — and turns everything into one weighted score with a plain-English explanation.

What the scanner never does

  • It never executes JavaScript from the scanned page.
  • It never downloads files — HTML reading is capped at 200 KB and non-HTML bodies are discarded.
  • It never scans private or internal addresses (localhost, 10.x, 172.16–31.x, 192.168.x, 169.254.x, ::1), and every redirect hop is re-checked so a public site can't bounce the scanner into an internal network.
  • It never stores your raw IP — only a salted hash used for rate limiting.
  • It never fabricates results: a feed with no API key configured is labeled “not configured,” never guessed.

Risk bands

0–20Safe

No known threats were found. The URL is clean across all configured feeds and raised no structural or network red flags.

21–45Low Risk

A few weak signals (an unusual TLD, a shortener, a long URL). Nothing conclusive, but worth a second look.

46–70Suspicious

Multiple independent indicators. Treat the link with caution and avoid entering credentials.

71–90Dangerous

Strong evidence of malicious intent — threat-feed hits, brand impersonation, or credential-harvesting patterns.

91–100Phishing/Malware

Confirmed by verified threat intelligence (PhishTank verified, URLhaus match, admin blacklist). Do not visit.

Scoring weights (key signals)

Signals stack; the total is capped at 100. Structural heuristics alone are capped at 45 so the URL's shape can raise suspicion but never single-handedly condemn a site.

PhishTank verified phishing+50
URLhaus malware match+50
Google Safe Browsing hit+40
VirusTotal ≥3 engines malicious+30
AbuseIPDB confidence ≥75%+30
Brand misspelling / impersonation+25
IP address used as domain+20
Punycode / homograph hostname+20
Form posts credentials cross-domain+20
URL shortener+15
Invalid or expired SSL certificate+15
Long redirect chain (≥3 hops)+15
Obfuscated JavaScript patterns+15
Suspicious TLD+12
No HTTPS+10
Login form with password field+10

Honest limitations

No automated scanner is perfect. Brand-new phishing sites may not yet appear in any feed ("Unknown" or a low score is not a guarantee of safety), and legitimate sites can occasionally trip heuristics. A low score means this scan found no known threats — it never means a link is definitely safe. Always verify the sender before entering passwords, payment details, or personal information.