Is PhishWall safe?

Clean risk

PhishWall sends the full URL of every page visited to a locally-installed security client on port 8888.

On each page navigation and tab switch, PhishWall POSTs a base64-encoded payload containing the current URL, cookie data, and tab information to http://127.0.0.1:8888/pw/auth/ — a locally-running PhishWall client application. The extension also modifies the User-Agent header for a set of Japanese banking sites, appending a 'SBPW/1.0' token or prepending 'SE04 ' to identify the browser session to those sites.

PhishWall Supportv6.4.2.1Chrome Web Store
0Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

What it can do

Permissions this extension asks for, as declared in version 6.4.2.1. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Read and change your data on every site you visit

    <all_urls>

  • Read and change your data on 127.0.0.1

    http://127.0.0.1/

  • Block and redirect the requests your browser makes

    declarativeNetRequest

  • Watch every request your browser makes

    webRequest

  • Store data in your browser

    storage

Where it sends data

Destinations our analysis observed PhishWall contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.

  • 127.0.0.1:8888

    PhishWall sends data to 127.0.0.1:8888. No other extension we have analysed sends data here.

Updated 30 September 2026alohbabbpkchbmiihojaffcfnbkmgpdo