# PatchPulse — Anti-Phishing

> Anti-phishing protection: warns you before you enter a site that imitates an official one. Typos, deceptive characters, fake sub-domains and look-alike domains.

Canonical page: [https://chrome-stats.com/d/patchpulse-anti-phishing](https://chrome-stats.com/d/patchpulse-anti-phishing)

## Overview

- **ID:** `patchpulse-anti-phishing`
- **Platform:** Firefox
- **Type:** Firefox add-on
- **Status:** Available
- **Publisher:** PatchPulse
- **Category:** privacy-security
- **Daily users:** 1
- **Rating:** 5.00 / 5 (1 ratings)
- **Version:** 1.6.1
- **Last updated:** 2026-07-08
- **First published:** 2026-06-07
- **Size:** 87 KB
- **Data as of:** 2026-09-08
- **Store listing:** [Firefox Add-ons Store](https://addons.mozilla.org/firefox/addon/patchpulse-anti-phishing/)
- **Website:** [https://patchpulse.org/extension.php](https://patchpulse.org/extension.php)
- **Privacy policy:** [https://addons.mozilla.org/firefox/addon/patchpulse-anti-phishing/privacy/](https://addons.mozilla.org/firefox/addon/patchpulse-anti-phishing/privacy/)

## Description

PatchPulse warns you before you open a website whose address is a look-alike of one you trust. The trick behind most phishing attacks.

Unlike blocklists (which only know sites already reported), PatchPulse compares the address you're visiting against a list of official domains and flags the dangerous ones by similarity — even brand-new fakes.

What it catches
- Typos and look-alikes: <a href="https://prod.outgoing.prod.webservices.mozgcp.net/v1/5c6f4534e258c3b691471bf861ebbfe2b5a8ef234d216adc344987ae0586aed8/http%3A//rnicrosoft.com" rel="nofollow">rnicrosoft.com</a> (rn→m), <a href="https://prod.outgoing.prod.webservices.mozgcp.net/v1/59e3980f1936787bbd8217e716a4bc3c2b0caa83dd06677ecc1849dc5dc1c4e7/http%3A//paypa1.com" rel="nofollow">paypa1.com</a> (1→l), <a href="https://prod.outgoing.prod.webservices.mozgcp.net/v1/f9e3ff5df3b6c360bbf64b5cdd867d4d06564c0989ded33e0bbad1dd5424024d/http%3A//gogle.com" rel="nofollow">gogle.com</a>, <a href="https://prod.outgoing.prod.webservices.mozgcp.net/v1/ef648b330ccd08c73413751e5954f2ce19e06c443a6266b34b54b017bc44a82f/http%3A//googel.com" rel="nofollow">googel.com</a> (swapped letters)
- Hyphen tricks: <a href="https://prod.outgoing.prod.webservices.mozgcp.net/v1/aa77360a6c7332a42ad77f459c8ab88b64196e2a7a5bd0436a9e06806243c7c1/http%3A//pay-pal.com" rel="nofollow">pay-pal.com</a>, <a href="https://prod.outgoing.prod.webservices.mozgcp.net/v1/50890f748a90de3f83d49b0ebeb20232b0d9a0674d0e7f14d6f0a0ac563c3955/http%3A//paypal.com-secure.ru" rel="nofollow">paypal.com-secure.ru</a>
- Deceptive Unicode characters (e.g. Cyrillic letters that imitate Latin ones)
- The official domain used as a sub-domain of an attacker's site: <a href="https://prod.outgoing.prod.webservices.mozgcp.net/v1/746b75436e00356a411bf983e46ec1d65565908508c91a1a882f77342619768f/http%3A//paypal.com.evil-login.ru" rel="nofollow">paypal.com.evil-login.ru</a>
- Brand names combined with phishing words like login, verify or support: <a href="https://prod.outgoing.prod.webservices.mozgcp.net/v1/9cecdf234219a43ee953c3aecdd7b5597f2973b15a2363c178946ebc251ae292/http%3A//paypal-login.com" rel="nofollow">paypal-login.com</a>, <a href="https://prod.outgoing.prod.webservices.mozgcp.net/v1/4c0ac63103a5943a236aab9ce04d9b208d658da01335cc2e410691df8b0b63cc/http%3A//applesupport.com" rel="nofollow">applesupport.com</a>
- Official names on abuse-prone domain endings: <a href="https://prod.outgoing.prod.webservices.mozgcp.net/v1/8b22c26ee54deac0422fee70103983687f8b4aa68f1c1887cd320e84f63a8d2f/http%3A//paypal.tk" rel="nofollow">paypal.tk</a>, <a href="https://prod.outgoing.prod.webservices.mozgcp.net/v1/0c2eb4ffb8818e2f92cc8194fe09bc986982bc7d63b08d1471ae6d804d61a286/http%3A//paypal.co" rel="nofollow">paypal.co</a>

172 well-known domains are protected out of the box: banks, payments, email, crypto, shopping, shipping and institutions — international and Italian.

Private by design
Everything runs locally in your browser. No browsing history is ever sent to any server.

Make it yours
Add your own important sites (your bank, local services, niche brands) and protect them too, not just the big names. If a warning is a false alarm, one click adds the site to your trusted list.

Free and open source.

## Rankings

- #76,277 — Overall

## Permissions and access

### Permissions

- `webNavigation`
- `tabs`
- `storage`

## Safety

- **Risk impact:** Moderate risk impact
- **Risk likelihood:** Moderate risk likelihood

### Analysis details

- Grants access to browser tabs, which can be used to track user browsing habits and history, presenting a privacy concern.
- This extension has low user count. Unpopular extensions may not be stable or safe.

> Some risk analysis details are omitted from this free response. [Upgrade to view the full analysis](https://chrome-stats.com/pricing).

## Similar extensions and apps

- [PhishEye - Anti Phishing](https://chrome-stats.com/d/phisheye-anti-phishing) — 4 users
- [SecurityShrimp APEX](https://chrome-stats.com/d/securityshrimp-apex) — 1 users
- [AntiPhish - Phishing Site Checker](https://chrome-stats.com/d/antiphish-phishing-site-check) — 6 users
- [AntiPhish - Phishing Detector](https://chrome-stats.com/d/antiphish-phishing-detector) — 2 users
- [Phishing Protection](https://chrome-stats.com/d/phishing-protection) — 1 users
- [PhishGuard](https://chrome-stats.com/d/phishguard432) — 1 users
- [Visilant](https://chrome-stats.com/d/visilant) — 8 users, 5.00 / 5
- [Phishy.pro - Phishing | Malware Scanner](https://chrome-stats.com/d/phishy-phishing-malware-scan) — 93 users, 2.00 / 5
- [Real Time Phishing Scan](https://chrome-stats.com/d/real-time-phishing-scan) — 1 users
- [Phishing Site Checker](https://chrome-stats.com/d/phishing-site-checker) — 3 users
- [Phishing Detector](https://chrome-stats.com/d/phishing-detectorrr)
- [OverPhish: Phishing Domain Blocker](https://chrome-stats.com/d/overphish) — 1 users

---

Source: [Chrome-Stats](https://chrome-stats.com/d/patchpulse-anti-phishing)
