Is PhishWall safe?
PhishWall sends the full URL of every page visited to a locally-installed security client on port 8888.
On each page navigation and tab switch, PhishWall POSTs a base64-encoded payload containing the current URL, cookie data, and tab information to http://127.0.0.1:8888/pw/auth/ — a locally-running PhishWall client application. The extension also modifies the User-Agent header for a set of Japanese banking sites, appending a 'SBPW/1.0' token or prepending 'SE04 ' to identify the browser session to those sites.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
What it can do
Permissions this extension asks for, as declared in version 6.4.2.1. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Read and change your data on every site you visit
<all_urls>
Read and change your data on 127.0.0.1
http://127.0.0.1/
Block and redirect the requests your browser makes
declarativeNetRequest
Watch every request your browser makes
webRequest
Store data in your browser
storage
Where it sends data
Destinations our analysis observed PhishWall contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.
- 127.0.0.1:8888
PhishWall sends data to 127.0.0.1:8888. No other extension we have analysed sends data here.