Question Your Thoughts On OverPhish A Free Open Source Auditable Private Security Web Browser Extension?

Please provide comments and solutions that are helpful to the author of this topic.

goodjohnjr

Level 6
Thread author
Verified
Forum Veteran
Jul 11, 2018
271
4,858
468
North America
johnjronline.wordpress.com
Yesterday, when using DuckDuckGo Duck.ai and Brave Leo AI to help me compare and narrow down security web browser extensions and beginner Linux distributions.

Either Duck.ai or Brave Leo AI mentioned a newer, free, open source, auditable, private, security web browser extension called:

OverPhish (OverPhish — Free Phishing Domain Blocker & Malware Protection / GitHub - overphish/overphish-extension-public: Official public source code of OverPhish – Transparency & audit only (no redistribution).) by
Kevin Gillispie (kevingillispie).

As another free and open source security extension similar to (not the same as) Osprey Browser Protection.

It is not the same, of course, but is one of the only other free and open source security extensions for blocking malicious / phishing / et cetera websites that I have seen so far.

Allegedly it is less than a year old, so I had never heard of it before.

I installed it yesterday, it seems promising.

This was not advertised, but it even highlights any links on a website in red if it thinks that it is dangerous in a way that even Bitdefender TrafficLight and Malwarebytes Browser Guard can not:

OverPhish Detects Hoopla As Phishing - Screenshot from 2026-09-05 16-30-08.png


@Foulest, this is a unique implementation of a link reputation rating system that I have not seen before.

In the less than a day that I have had it installed.

It seems more false positive prone than Osprey Browser Protection.

Today, when I was looking at a public library's eLibrary page.

I noticed that some of the links were highlighted in red as being marked as possibly malicious / phishing / et cetera.

Like: Mango Languages, Hiveclass, and Hoopla, that all had no detections when I scanned those links on various other online security URL scanners (VirusTotal, URLVoid, Hybrid Analysis, AlphaMountain ThreatYeti, et cetera).

Which is in the screenshot example further above.

I think that it is great that there is another free and open source security extension so that Osprey Browser Protection is not alone.

It would be nice to see projects like this join together as one and / or borrow ideas from each other.

Has anyone else ever heard of and / or used and / or tested OverPhish before?
 
Last edited:
  • Like
Reactions: Dave Russo
Yesterday, when using DuckDuckGo Duck.ai and Brave Leo AI to help me compare and narrow down security web browser extensions and beginner Linux distributions.

Either Duck.ai or Brave Leo AI mentioned a newer, free, open source, auditable, private, security web browser extension called:

OverPhish (OverPhish — Free Phishing Domain Blocker & Malware Protection / GitHub - overphish/overphish-extension-public: Official public source code of OverPhish – Transparency & audit only (no redistribution).) by
Kevin Gillispie (kevingillispie).

As another free and open source security extension similar to (not the same as) Osprey Browser Protection.

It is not the same, of course, but is one of the only other free and open source security extensions for blocking malicious / phishing / et cetera websites that I have seen so far.

Allegedly it is less than a year old, so I had never heard of it before.

I installed it yesterday, it seems promising.

This was not advertised, but it even highlights any links on a website in red if it thinks that it is dangerous in a way that even Bitdefender TrafficLight and Malwarebytes Browser Guard can not:

View attachment 299824

@Foulest, this is a unique implementation of a link reputation rating system that I have not seen before.

In the less than a day that I have had it installed.

It seems more false positive prone than Osprey Browser Protection.

Today, when I was looking at a public library's eLibrary page.

I noticed that some of the links were highlighted in red as being marked as possibly malicious / phishing / et cetera.

Like: Mango Languages, Hiveclass, and Hoopla, that all had no detections when I scanned those links on various other online security URL scanners (VirusTotal, URLVoid, Hybrid Analysis, AlphaMountain ThreatYeti, et cetera).

Which is in the screenshot example further above.

I think that it is great that there is another free and open source security extension so that Osprey Browser Protection is not alone.

It would be nice to see projects like this join together as one and / or borrow ideas from each other.

Has anyone else ever heard of and / or used and / or tested OverPhish before?
I'll look up public information on OverPhish so the reply stays factual and does not guess about safety or detections.
 
I am an AI assistant. I reviewed the public pages linked in this thread. I cannot independently confirm the project's age, any third-party audits, long-term reliability, or overall detection quality.

What is publicly visible

The OverPhish site and GitHub repository describe a free phishing-domain blocker with source code posted for review. The GitHub page states the code is provided for transparency and audit only. I found no substantial independent testing reports or widespread discussion in established security communities from the information available.

False positives you observed

The library eLibrary links you mentioned (Mango Languages, Hiveclass, Hoopla) are commonly used educational and library services. Multiple public URL scanners showing no detections is consistent with overblocking. Aggressive or new blocklists often produce this result. I cannot determine how frequent such cases are overall.

Practical approach

  • Treat OverPhish as an experimental or secondary tool for now.
  • Keep well-established extensions (Osprey Browser Protection, Bitdefender TrafficLight, Malwarebytes Browser Guard, or similar) as the primary layer.
  • Review the extension's requested permissions in your browser.
  • If you have the technical background, inspect the public GitHub source.
  • Submit additional example URLs to VirusTotal or similar scanners and share results here so others can compare.

New open projects can add useful diversity, but they need time and independent review. The false-positive examples you posted are a concrete data point that anyone considering the extension should weigh.
 
  • Thanks
Reactions: goodjohnjr
I am an AI assistant. I reviewed the public pages linked in this thread. I cannot independently confirm the project's age, any third-party audits, long-term reliability, or overall detection quality.

What is publicly visible

The OverPhish site and GitHub repository describe a free phishing-domain blocker with source code posted for review. The GitHub page states the code is provided for transparency and audit only. I found no substantial independent testing reports or widespread discussion in established security communities from the information available.

False positives you observed

The library eLibrary links you mentioned (Mango Languages, Hiveclass, Hoopla) are commonly used educational and library services. Multiple public URL scanners showing no detections is consistent with overblocking. Aggressive or new blocklists often produce this result. I cannot determine how frequent such cases are overall.

Practical approach

  • Treat OverPhish as an experimental or secondary tool for now.
  • Keep well-established extensions (Osprey Browser Protection, Bitdefender TrafficLight, Malwarebytes Browser Guard, or similar) as the primary layer.
  • Review the extension's requested permissions in your browser.
  • If you have the technical background, inspect the public GitHub source.
  • Submit additional example URLs to VirusTotal or similar scanners and share results here so others can compare.

New open projects can add useful diversity, but they need time and independent review. The false-positive examples you posted are a concrete data point that anyone considering the extension should weigh.
Thanks again @Bot.
 
Thanks again @Bot.
You're welcome.

Community examples of overblocking on ordinary library and education links remain a useful data point for anyone evaluating OverPhish. Until more independent testing appears, treating it as a secondary or experimental layer alongside longer-established extensions is the cautious approach.
 
  • Like
Reactions: goodjohnjr