PhishTriage Firefox

PhishTriage

One-click phishing triage for Gmail, Outlook Web and any page. Reads nothing until you click Analyze.
xHeader
Modify request and response headers. No ads, no malware.

Features & Capabilities

PhishTriage tells you whether the thing in front of you is a phishing attempt. Open the suspicious email, or the login page that feels wrong, and click Analyze. You get a verdict with a risk score, the indicators behind it, and what to do next.

On an ordinary web page the extension holds no standing access. It reads the page under activeTab, which exists only in the moment you click.

One exception, and your browser shows it at install: on Gmail and Outlook Web (mail.google.com, outlook.office.com, outlook.office365.com, outlook.live.com) a content script is present from the start, because that is how the Analyze button reaches the mail toolbar. Nothing else is touched unless you switch on an optional feature below.

From an email it sends the subject; the sender, recipient and reply-to addresses; the body, with quoted threads and signatures stripped; the links; and attachment filenames, not attachment contents. Who a message claims to be from is the strongest single signal there is. From any other page: the title, the visible text, the links, and the full address including path and query.

A verdict argues; an artifact proves. When a web page you analyze comes back Malicious or Suspicious, a screenshot of the visible tab and that page's HTML go up with it, so the site can be reported to its host or registrar. This is the one setting here that starts on: setup shows it, and the switch is in the popup. Nothing is captured on a benign verdict, and nothing on Gmail or Outlook Web, where the screenshot would be of your inbox. Webmail on any other host counts as an ordinary page, and there the picture is of your inbox — the privacy policy names the providers this affects. Both are held in memory for the seconds the scan takes, never written to your disk. Confirmed malicious is kept 12 months, suspicious 30 days, and a capture a reviewer clears is deleted at once.

Background protection checks each site as it loads and shows a full-page warning if it is known bad. Your browser asks permission first; decline, or revoke later. Only the hostname is sent, not the page you are on. Separate switches send full URLs instead, and cache a site for an hour; both off.

File protection (Chrome, Edge, Brave) checks your downloads. A fingerprint goes up with the file's name, its size, and what the on-device check made of it; the file itself only when you ask for that one file, or on every download if you switch on Deep scan every file. Another switch holds files a page builds in your browser and asks before they save, instead of warning after. For an ordinary download the extension fetches the file's address a second time — a browser hands an extension a download's details, not its contents — and that request carries your cookies as the first did.

No third-party analytics, advertising or telemetry. No identity permission: it never asks your browser or your mail provider who you are. Your install is identified by a random id, replaced at registration by one our server issues; it registers once at install, sending that id, your browser name, and an enrolment token if an administrator set one. The feedback buttons under a verdict record your correction on your own device and send nothing.

Sign in from the popup and the portal opens to finish the link. An administrator links the device to your organisation there; the extension never takes a credential. For a fleet, push an enrolment token by managed policy and devices join at install. Policy also pins the backend and sets the monitoring, file-protection, deep-scan and evidence switches for everyone, in either direction, so on a managed device a switch may already be on, or held off.

User Growth & Download Statistics

Manifest V3 Add-on
By:
Culfig OÜ
Daily users:
3 1
Version:
1.0.0 Last updated: 2026-08-22
Version code:
6414829
Creation date:
2026-08-14
Firefox add-on GUID:
phishtriage@phishtriage.com
Firefox add-on numeric ID:
3054181
Weekly download count:
2
Firefox on Android:
No
Risk:
Very high risk impact High risk likelihood
Permissions:
Content scripts matches:
  • mail.google.com
  • outlook.office.com
  • outlook.office365.com
  • outlook.live.com
Size:
144.31KB
Email:
su*****@phishtriage.com
URLs:
Website ,Privacy policy
Full description:
See detailed description
Source:
Firefox Add-ons Store
Data ingested on:
2026-09-09
Compare stats and ranking:

Contact the developer

Chrome-Stats does not own this Firefox add-on. Please use these information below to contact the Firefox add-on developer.
Developed by:
Culfig OÜ
Firefox Add-ons Store
https://addons.mozilla.org/firefox/addon/phishtriage/
Email:
su*****@phishtriage.com
Website:
https://phishtriage.com/support

Is PhishTriage Safe?

Risk impact
Risk impact measures the level of extra permissions an extension has access to. A low risk impact extension cannot do much harms, whereas a high risk impact extension can do a lot of damage like stealing your password, bypassing your security settings, and accessing your personal data. High risk impact extensions are not necessarily malicious. However, if they do turn malicious, they can be very harmful.

PhishTriage requires a lot of sensitive permissions. Exercise caution before installing.

Risk impact analysis details
  • Critical Request access to the following domains: google.com, office.com, office365.com, live.com
  • High ******* ******* **** *** ****** ***** *** ***** ** ******* **** ********* ********* ** * *********** *****
Risk likelihood
Risk likelihood measures the probability that a Firefox add-on may turn malicious. This is determined by the publisher and the Firefox add-on reputation on Firefox Add-ons Store, the amount of time the Firefox add-on has been around, and other signals about the Firefox add-on. Our algorithms are not perfect, and are subject to change as we discover new ways to detect malicious extensions. We recommend that you always exercise caution when installing a Firefox add-on.

PhishTriage is recently added, and hasn't been around long enough for us to gather enough data to accurately assess its risk level.

Risk likelihood analysis details
  • High This extension was recently updated in the past month. New updates may not be stable or safe.
  • High **** ********* *** ******** ****** *** ********** *** *** ** ****** ** *****
  • High **** ********* *** *** **** ****** ********* ********** *** *** ** ****** ** *****
Extension Guard
Extension Guard

Discover every extension in use, analyze risks, and enforce blocking policies with Extension Guard

Secure Your Browser
Upgrade to see full risk analysis details

Best PhishTriage Alternatives

Here are some Firefox add-ons that are similar to PhishTriage: