Unknown author · Privacy & Security
3 items
Detects ClickFix paste-and-run lures and ghost/AiTM Microsoft token-phishing pages. Extensible detector framework. A cross-browser Manifest V3 extension for Chrome, Edge, Brave, Opera and other Chromium browsers, plus Firefox, that detects two credential/token-theft attack families in the page, in real time, and warns the user: [v1.1.0] — 2026-07-18 Added - Trusted-sites allowlist (false-positive escape hatch). When a warning or the hard-block interstitial appears, you can click **Trust this site** to silence FixClick on that hostname. Trusted hosts produce no finding, no badge, and no overlay. The list is managed from the popup — a new **Trusted sites** section lists every trusted host with a per-host remove button, a **Trust this site** shortcut for the current tab, and **Clear all**. - The allow-list is stored in local browser storage, so it is **sticky across sessions and restarts** but is cleared if you reset the browser's extension / site data. It never leaves your device. ### Changed - Fewer false positives on informational pages. The passive on-page ClickFix heuristic now requires all three signals together — fake "human verification" framing **and** a Run-dialog/terminal/paste instruction **and** actual command-shaped text — instead of accepting the framing or the command alone. Security articles, vendor blogs, and news write-ups that merely *describe* ClickFix (without carrying a live command payload) are no longer flagged. The behavioral clipboard-interception path — which fires when a page actually copies a command to your clipboard — is unchanged.
rating_count is the Chrome Web Store ratings count, not a written-review count.