Spot the fake before you type.
WebGuard checks the page you are on for the signs of phishing, and warns you before you hand sensitive information to a site that should not have it. It runs on your device, and online checks are off by default.
Eight kinds of trouble
No single weak signal can produce a warning. Risk is the sum of several observations, each scaled by confidence, because a warning you learn to click through protects nobody.
Website security
HTTPS, URL structure, redirect parameters, embedded credentials, unusual ports, encoded addresses and risky file types.
Phishing
Brand impersonation across 34 commonly imitated services, typosquatting, homograph and mixed-script characters, brand names hidden in subdomains, and a page title that disagrees with the domain.
Domain analysis
Registered-domain extraction, raw IP hosts, Punycode, and subdomains dressed up to look like domains.
Forms
Login and payment form detection, passwords sent over http, and forms that post to a different domain than the one you are on.
Passwords
Strength, common passwords and character substitutions, keyboard runs and sequences, plus a breach lookup that never transmits your password.
Sensitive data
API keys, tokens, JWTs, private keys, connection strings, card numbers (Luhn checked), IBANs and crypto addresses in text you select.
Privacy
124 known trackers, third-party requests, cookies and local storage. Informational: if trackers moved the safety verdict, most of the web would turn orange and the verdict would stop meaning anything.
Threat lists
Known malicious and phishing URLs, matched on your device against downloaded hash prefixes. The addresses you visit are never sent.
Four verdicts. Never "safe".
A blocklist miss is not evidence of safety. WebGuard reports how much of a check it was actually able to complete, rather than presenting an empty database as a clean result.
Mostly, you don't
Protection runs as pages load. The rest is there when you want to ask something specific.
It watches
Pages are checked as they load. Only a High Risk verdict interrupts you.
You ask
Click the toolbar icon or press Ctrl Shift W for the full breakdown of the current site.
You check text
Select something and press Ctrl Shift U to scan it for credentials before you paste it anywhere.
You decide
Every signal shows what it saw. Trust a site and WebGuard stops warning you about it.
Chrome gives a shortcut to one extension at a time, and quietly declines to bind one another extension already holds. Paste chrome://extensions/shortcuts into the address bar to see what is actually assigned, and to set your own.
Nothing about the pages you visit leaves your browser
A tool that reads every page you open has to be worth trusting with that. Here is exactly what WebGuard does with it.
Online checks are off by default
With them off, WebGuard makes no network requests at all and every check runs on your device. Turning them on is your decision, made in settings.
Passwords are never transmitted
The breach check hashes the password on your device and sends the first five characters of that hash, which returns a bucket of several hundred candidates to compare locally. The service cannot learn the password, or even its full hash.
Password fields are never read
The input monitor skips them entirely. Their values are not read, not scanned, and not counted.
Secrets are never stored
The sensitive-data scanner returns a label, a confidence, an offset and a mask. There is no field in the result for the matched value, so nothing downstream of it can display, keep or send a credential even by accident.
Threat lists are downloaded, not queried
Matching happens on your device against synced hash prefixes. The only request derived from a page carries four bytes of a hash, which a great many addresses share.
History is off by default
Turned on, a record holds a hostname, a verdict, a score and a time, and nothing else fits in it. Pages you merely visit are never recorded. Settings has a reset that clears every piece of local data.
What WebGuard is not
It is not an antivirus, not a password manager, and not a guarantee. It helps you make a safer decision with better information. It does not replace security software, and it cannot promise a site is safe.
That is why there is no "safe" verdict. The most WebGuard will say is that the checks it was able to run found nothing.
Common questions
What does it cost?
Nothing, and it stays that way. There is no account and no subscription. WebGuard carries one house advertisement for the studio's own work, labelled "Ad", served from a list that ships inside the extension, and one click turns it off permanently.
Why does it need access to every site?
Because checking a page after you have already typed your password into it is no use. Automatic protection means reading each page as it loads, and Chrome asks for that access at install. What gets read is listed in full in the privacy policy: the address, the shape of the forms, resource hostnames, counts and the title. It is sent nowhere.
Does it send the sites I visit to a blocklist service?
No. The lists are downloaded to your device as hash prefixes and matched locally, so almost every page resolves with no network activity at all. The single exception is confirming a prefix hit on a prefix-only list, which sends four bytes of a hash that a great many addresses share.
Is checking my password against a breach list safe?
The password is hashed in the popup on your device, and only the first five characters of that hash are sent. That selects a bucket of roughly eight hundred hashes, which comes back in full and is compared locally. The service sees five hexadecimal characters and cannot reconstruct your password or its full hash. The check is also off unless you have turned online checks on.
Which browsers does it work in?
Chrome 116 and later, and the Chromium browsers that install Chrome extensions, such as Edge, Brave and Opera. It is a Manifest V3 extension.
It flagged a site I know is fine. What now?
Add it to your trusted sites from the popup and WebGuard stops warning you about it. Every signal shows what it saw, so you can judge whether the finding is wrong or whether the site is doing something it should not. If it is a genuine false positive, we would like to hear about it.
Not answered here? Extension support has the troubleshooting for WebGuard, and what to include if you need to report a bug.
Ready when you are
It installs in a click and costs nothing. While you are here: we also build websites, and we have more extensions on the way.