Is ClickFix Block safe?

Low risk

ClickFix Block detects and blocks ClickFix social-engineering prompts on most web pages, and exposes its settings to any page via an open external-messaging channel.

The extension injects a content script into the majority of web pages (with a hardcoded exclusion list for trusted domains) to identify and suppress ClickFix copy-paste attack prompts. When a detection event occurs, the background script forwards the event — including the current page path and parameters — to links.eye.security. Any web page can also query the extension's current state (whether protection is enabled, whether block-all mode is active, and whether the caller's own domain is on the user's allowlist) by sending a message to the extension's open externally_connectable channel.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

Eye Securityv0.0.9.36Chrome Web Store
20Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Data recipients

links.eye.security
Updated 17 September 2026kicmpbbbloliabpbfkfcmflbmlcakeck