Chromium-based, for example Chrome, Edge, Brave, Opera, Vivaldi.
Firefox-based, for example Firefox on desktop and on Android, LibreWolf, Waterfox, Zen, Floorp.
Those are the best-known ones rather than a full list. Whether any particular browser takes the package is up to its own extension policy.
- What is Visilant?
- Real-Life Example: How Visilant Could Stop a Phishing Attack
- Key Features
- Getting Started
- Privacy Considerations
- Reproducible Builds
- Limitations
- Contributing & Feedback
Visilant is a lightweight, cross-browser extension designed primarily to protect you from phishing sites that aim to steal your credentials by tricking you into voluntarily entering them, typically through visual similarity to legitimate websites.
The core idea is simple: most phishing websites are those you have never visited or visited very rarely. Unlike traditional antivirus solutions, Visilant's approach can immediately alert you about phishing sites – even those newly created and not yet included in any security blacklists or antivirus databases.
Visilant counts your visits to all websites and provides two layers of protection: proactive – analyzing links on the page before you click them, detecting URL mismatches and suspicious domains – and reactive – alerting you when you interact with an unfamiliar site (interaction types are customizable).
Visilant does not block websites, downloads or navigation outright. Its alerts are advisory, and the optional paste guard can delay a paste on an unfamiliar site until you review the warning.
Imagine you're exhausted after a long flight or simply distracted by everyday demands. You click on a link that seems to be from a trusted service. Without Visilant, you might inadvertently enter your credentials on a visually convincing fake site, unknowingly handing them over to attackers – as cybersecurity expert Troy Hunt (creator of Have I Been Pwned) described after a 2025 phishing incident. Even if you’ve successfully identified phishing attempts in the past, a single moment of inattention can lead to a compromise. Phishing-resistant authentication, such as passkeys where a service supports them, is an important complementary defence. Visilant instead provides a visual prompt to pause, reconsider and verify the address before you enter credentials.
Visilant can analyze links on a page before you navigate, giving you visibility into where each link leads and whether you've been there before. Some sites can cause harm the moment you open them – no login or interaction required – so knowing the destination beforehand is critical.
This is a significant step up over the original reactive-only approach: instead of warning you after you've already landed on an unfamiliar site and started typing, Visilant now surfaces the destination domain and its familiarity status before you click, so you can compare the link text against the actual target and catch impersonation attempts up front.
- Link Tooltip: Checking an external link (one pointing to a different host than the current page) shows a compact tooltip with the destination domain, the facts its familiarity verdict was drawn from – visits, active days and how long the site has been known, whichever of those you judge by – and a familiarity indicator (familiar / unfamiliar / never visited). The trigger is configurable: right-click is the default, hover waits for a chosen delay, and left-click prevents navigation until you choose to proceed – the safest option.
- URL Mismatch Detection: A classic phishing trick is making a link's visible text look like one domain (e.g.
paypal.com) while the actual destination is completely different. Visilant detects this and shows a side-by-side comparison table with the familiarity status and every familiarity fact for both domains, check by check. - Punycode / Unicode Detection: Domains containing non-Latin characters that visually resemble Latin ones (homograph attacks) are flagged, with the ASCII (punycode) representation displayed.
- Shortened URL Detection: Shortened links (bit.ly, t.co, etc.) hide the real destination – a classic trick in clone phishing. Visilant can resolve them to reveal where they actually lead. Three modes: off, on-demand (button in tooltip), or automatic. You can also display the full redirect chain, resolve arbitrary URLs (not just known shorteners), maintain your own list of shortener domains (marking any domain as a shortener on the fly, after which the popup marks it as one), or configure remote shortener lists to augment the built-in list.
- Navigation Intercept (opt-in): When enabled, clicking a link to an unfamiliar site triggers a full-screen confirmation dialog before navigation proceeds. The dialog shows the destination domain, your visit history with it, any mismatch or punycode warnings, and the resolved real destination if the link uses a shortener. You can go back or continue at your discretion.
- Context Menu Integration: Where the browser supports extension context menus, right-clicking a link offers "Check domain safety", which opens the dashboard for that domain in a new tab, and "Check link safety", which shows the full dialog on the spot when the right-click trigger is the one you chose. It compares the link's text with where the link really goes, reading the text at the moment you right-click so the page cannot change it first, and it answers for links within the same site and for
mailto:links too. Selected text has "Check selected text with Visilant", and an image has "Scan QR code with Visilant". The domain check is there whether or not Link Safety is enabled in settings. - Scope Control: Link Safety can be active on all websites, only on specific domains (e.g. your email client), or everywhere except certain domains (e.g. your intranet).
Wherever an address is shown – the link tooltip, the intercept dialog, the popup, the check field – Visilant states what is notable about it. None of these is a verdict. They are facts about the address, shown next to your visit history so you can judge it yourself.
- Structural markers: credentials hidden in the authority (
https://paypal.com@evil.net), a bare IP address in place of a name, a whole domain placed in front of the real one (paypal.com.evil.net, named as "looks like paypal.com, but the real site is evil.net"), unusually deep subdomain nesting, and a single label written in two alphabets at once. Each rests on how URLs and DNS work, so an attacker cannot avoid one without giving up the trick it enables. - Resemblance to sites you know: an address that looks like a domain from your own visit history is called out – a swapped character (
pаypal.comwith a Cyrillic а), a digit standing in for a letter (paypa1.com), a typo (payapl.com), the familiar name padded out (paypal-secure.com,googlesupport.com), or a whole familiar domain parked in the subdomains. Because the comparison uses your history rather than a shipped list of brands, it differs for every user and an attacker cannot test a domain against it in advance. Strong matches are shown prominently, while weaker resemblances stay quiet so they never train you to dismiss the warning. - External lookups: a collapsed list of links to third-party services – VirusTotal, urlscan.io and Google Safe Browsing out of the box. These are links, not integrations: no API keys, no rate limits, and nothing is requested until you click one. The list is editable in settings, one
Name = https://example.com/check/{domain}per line, so you can point it at whatever you actually use.
The part after the @ is a domain like any other, so everything above applies to it – plus what is particular to mail:
- Public services and disposable mail: an address at a service anyone can register with is marked as one, so you judge the name before the @ rather than the domain, and a temp-mail domain is called out as itself. Both lists ship built in, take additions of your own, and can be topped up from a URL.
- Where the mail is actually read: nobody ever opens
gmail.com– Gmail is read onmail.google.com– so an address domain collects no visits of its own, and its counter is a zero that can never move. Visilant maps the well-known providers to the mailbox their mail is read on and reports the visits from there. You can map anything the built-in table misses yourself. - Resemblance to a provider: for addresses only, the well-known mail providers join your own history as something an address can be one letter away from. Ordinary browsing warnings keep comparing against your history and nothing else.
Visilant employs several techniques to help you spot spoofed domains:
- Domain Highlighting: Marks the characters worth a second look – digits, separators, and anything outside the Latin alphabet. Latin letters are deliberately left unstyled: colouring them would read as a verdict on the ordinary part of an address and drown out the one character that matters.
- Punycode Display: Toggle between Unicode and Punycode (ASCII) formats to reveal internationalized domain attacks where characters look identical to Latin ones.
- Secure Rendering: Uses a specialized rendering component to prevent visual spoofing techniques.
Clicking the extension icon reveals a dashboard where you can:
- View visit statistics for the current domain and its subdomains.
- Pick the Number: The list of related hosts draws one figure per host, and you choose which – visits, active days, days known, or how many checks the host passes. The heading above it says whether the family adds its members up or takes its strongest single one, because only visits add up: a day spent on
mailand onaccountsis one day of knowing Google rather than two. - Sort Sites: Order the list by that number or by name, to understand your history with a domain family.
- Customize Display: Toggle domain highlighting, change text case (uppercase/lowercase), switch Punycode modes, and adjust font size on the fly.
- Per-Site Warnings Switch: Turn the warnings for the current site off, or back on. It lives here and nowhere in the page: a page can print "press Don't show again to continue" beside its own login form, and it cannot reach the popup. The settings page lists every site you have silenced.
- Per-Site Anti-Tampering Toggle: See whether tamper detection is active for the current site and quickly disable or re-enable it without leaving the popup.
- Check Anything by Hand: A field opened from the popup takes a link, a bare domain, an email address or a QR code image – pasted, dropped or picked from disk – and reports the same facts as everything above. The same check is a right-click away on any selected text, and opens in the page you are already on.
- Light / Dark / System Theme: Pick a theme that suits your environment or follow your system preference.
- Responsive Layout: The popup and settings adapt to narrow widths – works when opened in a tab or on mobile-form-factor windows.
- One Site With or Without www.:
www.example.comandexample.comare counted, judged and silenced as one site, so a bank you read daily atwww.does not look new the first time a link drops the prefix. A link between the two stays on the site. Records kept separately by earlier versions are merged once, automatically. - Local Resource Ignoring: Visilant automatically ignores internal hosts (like
localhostor intranet sites without dots in the hostname), preventing unnecessary alerts during development or local network usage.
Visilant implements multiple layers of protection to ensure reliable operation even on malicious sites:
- Early Injection: Content scripts load at
document_start, so protection starts early in the page load. - Event Capturing: Keyboard, input and clipboard listeners are registered in the capture phase so the extension can handle them early in the event flow.
- Anti-Tampering Protection: A MutationObserver watches the extension's in-page UI. Removal or concealment is repaired first and reported only if it keeps happening – a site that draws its own pages throws its body away on every route and loses the container as a side effect, so once it is put back it stays back, while a page set on removing it has to keep taking it away. What survives that is an alarm and a system notification. The check can still be disabled per-site (from the popup or via an exclusion list in settings) for trusted sites that set it off anyway.
- Randomized DOM Footprint: The extension container uses a randomly generated ID for each page load, making it harder for malicious scripts to detect Visilant's presence by querying specific element IDs.
- Overlay Protection: In-page warnings use maximum z-index and fixed positioning, and while a panel is on screen the tamper watcher also checks whether the page is covering it.
-
Install Visilant from your preferred browser's extension store:
- Visilant for Chromium-based browsers – Chrome, Edge, Brave, Opera, Vivaldi and the rest.
- Visilant for Firefox-based browsers – Firefox, LibreWolf, Waterfox, Zen, Floorp, and Firefox for Android.
-
Pin the Visilant icon to your browser toolbar for constant visibility (recommended due to Script Injection Limitations). On Firefox for Android there is no toolbar to pin to – the icon, its colour and its counter are all there, under Extensions in the browser menu.
-
Click the Visilant icon to open the extension popup. It provides an overview of your visit history for the current site and allows quick access to display settings.
-
Click the Settings icon (gear) in the popup to open the full configuration page. Configure the extension according to your preferences:
-
Familiarity rules: Decide what makes a site "familiar", in a section of its own. Three checks are available, and all are enabled by default: visits (10), active days (5) – separate days you were there, which a single afternoon of clicking cannot fake – and how long the site has been known, counted in days since your first recorded visit (10 days). Switch on the ones you want and choose how many have to pass: all of them, any one of them, or a set number, such as two of three. Everything else the extension does follows from this one verdict.
- Every check surface – the link tooltip, both confirmation dialogs, the comparison table, the in-page panel and the popup's check field – lists the facts behind its verdict, and only the checks you have switched on. Show what each check needs decides how: off, the facts come one per line, as
Visits: 3, with the bar one hover away, on, they come as a small table of check, value, bar and a pass mark, which takes more room and leaves nothing to remember. - Note: Active days and first-visit dates only exist for sites recorded since those fields were added, and a site without them cannot pass those checks. A history import fills them in for every site the browser still remembers – for anything older than that, or removed by a clearing of history, there is nothing left to read, and the settings page says which case you are in. On Firefox for Android there is no history to read at all, so the older records keep only their visit count and everything visited from now on carries both dates from its first visit.
- Every check surface – the link tooltip, both confirmation dialogs, the comparison table, the in-page panel and the popup's check field – lists the facts behind its verdict, and only the checks you have switched on. Show what each check needs decides how: off, the facts come one per line, as
-
Toolbar icon:
- Choose whether the icon carries a counter, and what that counter shows: any one of the checks you have switched on, or how many of them the site passes. With a single check in use there is nothing to choose between, so the question is not asked.
- Enable/disable icon color change to red for "unfamiliar" sites. On a site whose warnings you turned off, the same verdict comes in grey instead – the site is still unfamiliar, you have only asked not to be told about it. Anti-tampering is a separate switch and keeps working there.
-
Link safety:
- Link Safety is enabled by default. It analyzes external links on pages and shows a tooltip with the destination domain's familiarity status.
- Choose the tooltip trigger: right-click (the default – nothing appears until you ask for it), left-click (safest – prevents navigation until you review), or hover, which waits out a delay of your choosing before it opens.
- Configure familiarity fact visibility in tooltips: always, never, only for unfamiliar sites, or only for familiar sites.
- Optionally enable navigation intercept to require confirmation before visiting unfamiliar sites.
- Configure shortened URL detection: off, on-demand button, or automatic. Optionally show the full resolved URL (not just the domain), display the redirect chain, resolve arbitrary URLs (not just known shorteners), or maintain your own list of custom shortener domains. You can also point the extension at remote shortener lists to keep the built-in list up to date.
- Set the scope: all websites, only specific domains, or everywhere except certain domains.
-
General: Choose a light, dark, or system-matching theme, and decide whether the settings page explains itself. The explanations are on by default and worth keeping unless you know the settings by heart – switching them off only makes the page shorter.
-
Email addresses: Add to the built-in lists of public email services and disposable mail domains, keep either topped up from a URL, and map an address domain to the site its mail is read on.
-
External lookups: Edit the third-party services offered under a checked domain, one
Name = https://example.com/check/{domain}per line. Clear the field for none at all. -
Anti-tampering: List the sites where the tamper check should stay out of the way – ones that rebuild their page constantly and set it off for no reason.
-
Notifications:
- Select notification triggers: typing, copying, or both (see Notification Triggers for details).
- Select notification styles: browser notifications, in-page warnings, or both.
- Hold pastes on unfamiliar sites (opt-in): instead of only warning you, the first paste on an unfamiliar site is stopped and nothing is inserted until you have looked at the address. Allowing it pastes nothing by itself – you press paste again and it goes through as an ordinary paste, and the page stops asking.
- Sites you have silenced: The warnings for one site are turned off in the popup, whatever the familiarity rules say about it, and this list names every site you have done that to – one host to a line. Delete a line to bring its warnings back. A site on the list that is familiar by now gets no warnings anyway, so the page names those sites and removes them with one button. An opt-in setting does the same on its own: a site leaves the list on your next visit once it is familiar, which matters only if you later make the familiarity rules stricter. The in-page warning deliberately carries no such button, only a line saying where the switch is: a page that wants to be trusted can write "press Don't show again to continue" beside its own login form, and it has no way to reach the popup.
- You can also disable notifications completely if you prefer a non-intrusive browsing experience. However, be sure to check the visit count on the extension icon during important interactions, as otherwise, the extension's effectiveness is greatly diminished.
Every section carries a reset in its corner, which puts that section back to how it ships and leaves the rest of the page alone.
-
-
Your browser history is imported when Visilant is installed, so the counter starts with the sites you already know instead of treating every one of them as new. It reads every recorded visit, down to the date you first opened each site and the number of separate days you have been there. The import is read on the device and stays there – nothing is uploaded, and no site is contacted. It can be cancelled while it runs, resumes where it stopped, and the button in Your data re-runs it whenever you want.
- Note: Dates are labelled "first known visit" because they can only reflect what is still in your browser history – clearing history removes visits that cannot be recovered.
The extension triggers alerts (if enabled) only during specific interactions that phishing sites commonly exploit:
-
Keyboard Input or Content Paste: Alerts trigger when text is entered or pasted into editable fields. The extension listens for ordinary typing as well as for text arriving another way, such as an IME, dictation, a phone's suggestion bar or autofill. Keyboard shortcuts and navigation keys do not trigger an input alert.
-
Content Cutting or Copying: Although less common in phishing attacks, this trigger was added after viewing YouTube video demonstrating a phishing exploit involving clipboard manipulation (reCAPTCHA Phish).
Note: File downloads aren't listed as dangerous interactions because humans typically detect suspicious downloads easily, and handling virus-infected files is best left to antivirus software. Visilant addresses a specific gap not covered by traditional antiviruses.
Visilant is open-source and operates locally within your browser:
-
There is no server behind Visilant, no account and no telemetry. Every analysis described above – visit counts, structural markers, resemblance to sites you know – runs in your browser against data you already have.
-
Your visit records never leave the device. The counts, the dates and the imported history are kept in the browser's local storage, which nothing syncs and nothing uploads.
-
Your settings are kept in the browser's sync storage, the same place any extension keeps its preferences. If you have browser sync switched on, your browser copies them to your other browsers through your browser account – Mozilla's or Google's, not ours. That includes the lists you type into the settings: the sites the link check is limited to, the sites left out of the anti-tampering watch, and any list address of your own. Switch browser sync off and they stay on this machine.
-
Nothing is requested on your behalf without you asking for it. The following optional features can cause a network request:
- External lookups offer links to third-party services. They are ordinary links, not integrations – Visilant sends nothing, and no service learns anything unless you choose to open it. Whichever one you open will, like any site you visit, see the domain you asked about and your IP address.
- Shortened link resolution requests the shortened link itself to find out where it leads. On its default setting this happens only when you press the button in the tooltip. You can turn it off entirely, or set it to resolve on its own – on that setting the request goes out as soon as the check appears, without a press, which is the trade the setting is for.
- Reading a QR code from a picture on a page downloads that picture, because the code is in the image and the image is on the site's server. It happens only when you pick Visilant from the long-press menu on it. A picture you drop on the check page or paste into it is never downloaded – it is already on your device.
-
Remote lists (URL shorteners, public email services, disposable mail domains) come with a maintained source filled in, and each is fetched only when you press Update in the settings. Clearing a field turns that source off, and any URL of your own can go in its place. Nothing is fetched on a schedule or in the background.
-
The extension requests only the permissions necessary for proper operation:
Required permissions:
- Tabs: To detect the current website you're visiting and update the extension icon with visit count.
- Storage: To keep your visit history on this device and your settings where the browser keeps preferences, which is the sync storage described above.
- ActiveTab: To interact with the currently active tab when you click the extension icon.
- Notifications: To display system alerts when anti-tampering protection detects malicious interference.
- Context Menus: To add right-click actions for links, selected text and QR-code images where the browser supports them.
- Host permissions (
*://*/*): To inject content scripts that monitor keyboard and clipboard interactions and analyze links on all websites. - Browser history: To read your existing history once and turn it into per-hostname visit counts. An empty profile treats every site as unfamiliar, so without that first pass the extension warns about everything and reads as broken. It is decided once per profile: a fresh install imports, an update does so only if the profile holds no counts yet, and neither is repeated afterwards. The history is read in the browser and never leaves it. Only a visit count, a first and last date and a number of active days are kept per hostname, with no page addresses, no titles and no search terms. You can re-run or wipe the import yourself in the settings, under Your data.
Firefox for Android has no history API. There the import cannot run at all, and the settings page says so instead of offering a button that would do nothing.
You do not have to take our word for what the store installed. Every release can be rebuilt from this repository, byte for byte:
nix build github:ikskoder/visilant/v3.2.0#firefox
sha256sum result/*.xpi # compare with SHA256SUMS on the releasescripts/verify.sh <downloaded.xpi> goes one step further and compares the copy
your browser actually installed with a fresh build, file by file. Release
archives also carry a Sigstore-signed provenance attestation tying them to the
commit and workflow that built them, and anyone can rerun the build in a fork
through the reproduce workflow.
Node, pnpm and every dependency are pinned through flake.lock and
pnpm-lock.yaml, and the archive is packed with fixed timestamps and sorted
entries, which is what makes two builds identical. Full instructions are in
REPRODUCE.md.
While Visilant enhances awareness of "unfamiliar" websites, its limitations include:
-
Not a Malware Blocker: Visilant doesn’t detect or block malicious code, downloads, or trackers. It helps you assess addresses and familiarity, but it is not a replacement for an antivirus.
-
Relies on User Action: Most protection is advisory: you must notice and act on the warnings. The optional paste guard delays a paste for review, but it does not decide whether a site is legitimate.
-
False Positives and Negatives: Legitimate sites with low visit counts may trigger warnings (false positives), while phishing sites visited repeatedly may go unflagged (false negatives).
-
Compromised Trusted Sites: If attackers gain control of a legitimate domain you've previously visited, Visilant won't detect it as suspicious since your visit history marks it as "familiar." However, at that point, you're likely facing a much larger security breach – such as a domain hijack or server compromise – where Visilant's lack of protection is the least of your concerns.
-
Partial Cross-Device Sync: While your configuration settings are synced across devices (if you're logged into your browser), your visit history is stored locally to accommodate its size. This means a site marked as "familiar" on one computer will still be treated as "unfamiliar" on another until you visit it enough times there. Installing Visilant on that machine imports its history for you, which is what closes most of the gap – except on Firefox for Android, which does not let extensions read its history, so a phone starts from nothing and learns as you browse.
-
Script Injection Limitations: To detect input and clipboard interactions and analyse links, Visilant injects content scripts into visited pages. Anti-tampering protection can report attempts to remove or hide its in-page UI, but a hostile page can still interfere with page-level code. Keep the extension icon in sight as an additional safeguard – pinned to the toolbar on desktop, or under Extensions in the menu on Firefox for Android.
Understanding these limitations is crucial for Visilant's effective use.
Visilant is open source, and contributions are welcome, with some considerations:
- The developer's current workload may delay review of issues or pull requests.
- Please check existing issues before creating new ones.
- Pull requests adding third-party libraries should have strong justification.
- The developer reserves the right to reject pull requests deemed unsafe or misaligned with project goals.