Skip to main content
PPPhishPondPhishing Tradecraft Intelligence

Attack · Detection · Validation

CampaignTradecraftInfrastructureDetectionResearchRadarNewsroomAboutSubscribe
CampaignTradecraftInfrastructureDetectionResearchRadarNewsroomAboutSubscribe

Research Desk

PhishPond

Phishing tradecraft research desk covering campaign analysis, adversary infrastructure, detection engineering, and validation workflows.

High signal for security teams who need tradecraft, not recycled filler.

Navigate

  • Home
  • Newsroom
  • Research
  • Subscribe

Signals

  • editorial@phishpond.dev
  • Research Mission & Ethics
  • Intel Brief
  • RSS Feed
  • Submit Research Tip
© 2026 PhishPond. Authorized security research use only.

GitHub RadarBlue team tool

iri-dev/WardenOne

One extension. Every defence. - the all-in-one privacy, security & anti-scam extension for Chromium browsers (MV3). 106 on-device protections: ad & tracker blocking, anti-fingerprinting, phishing/scam & credential-theft defence, cookie-wall lifting, download scanning, IP-leak protection, plus YouTube & Twitch tools. No account, no telemetry. GPLv3. Primary language: JavaScript. 8 stars.

JavaScript8 stars0 forkspushed Sep 10, 2026GPL-3.0

Project links:Open GitHub projectBack to radar

README Preview

Fetched from GitHub

<div align="center">

<img src="icons/icon128.png" alt="WardenOne shield" width="112">

WardenOne

<p><strong>One extension. Every defence.</strong></p>

Local-first protection against scams, credential theft, malicious downloads, trackers, fingerprinting, pop-ups and forced redirects—plus security for browser extensions and the network beneath them.

![License: GPLv3](LICENSE) ![Manifest V3](manifest.json) ![Download latest build](https://github.com/iri-dev/WardenOne/releases/download/latest-build/WardenOne-latest.zip) Image: Protections Image: No telemetry ![Open source](LICENSE) ![Report a bug](https://github.com/iri-dev/WardenOne/issues/new/choose)

</div>

### No account. No telemetry. No WardenOne tracking. No remote browsing proxy.
No WardenOne backend · Entirely open source · Local-first by design
WardenOne has no account service, analytics pipeline or developer-operated browsing server.
Your browsing and security data stay on your device. Only when you choose a clearly labelled
external check does the minimum needed leave your device, and the check tells you exactly what it sends.
[!WARNING]
Official builds only. WardenOne is a browser extension, never an .exe, installer or setup program. Download it only from github.com/iri-dev/WardenOne. If you received another copy, read the impersonation incident notice.
## One master switch. 106 protections.
103 individually controllable · 3 watch-only
Background Reports, Hardware & File Access and Browser Capabilities are watch-only:
they record important activity without blocking or changing the page, so deliberately have no
individual switch.

WardenOne works across the network, page, session, download, storage and extension layers—and shows you the evidence behind the decisions it makes.

Inspect it for yourself: Privacy policy · Permissions explained · Security policy · Source · Licence

<p align="center"> <a href="docs/screenshots/01-popup-master-switch.webp"> <img src="docs/screenshots/01-popup-overview.webp" alt="WardenOne's main control surface with the master switch, protection health and protection search" width="620"> </a> </p> <p align="center"><em>One master switch, live protection health and a searchable route to every control. Select any product image for its full view.</em></p>

Quick install

  1. Download WardenOne-latest.zip and unzip it somewhere you intend to keep it.
  2. Open chrome://extensions and enable Developer mode in the top-right.
  3. Select Load unpacked, then choose the unzipped folder containing manifest.json.

First run

Choose Recommended for WardenOne's compatibility-conscious defaults, or Maximum Privacy for a more aggressive set that enables extra fingerprinting, first-party tracking, breach, clipboard, referrer and link protections. Maximum Privacy can change how some sites behave; every included protection can be changed later.

Choose Normal notifications or Silent mode. Silent mode keeps protection running but hides routine pop-ups and badges. The Notification Centre remains available when you want to review or change individual notices.

<p align="center"> <a href="docs/screenshots/11-onboarding-protection.webp"> <img src="docs/screenshots/11-onboarding-protection.webp" alt="WardenOne onboarding explains its default protection and the available threat-intelligence feeds" width="900"> </a> </p> <p align="center"><em>First run introduces the protection, its privacy boundary and the choices you can change later.</em></p>

<details> <summary><strong>See the complete first-run journey</strong></summary>

<p align="center"> <a href="docs/screenshots/11-onboarding-welcome.webp"><img src="docs/screenshots/11-onboarding-welcome.webp" alt="Welcome to WardenOne, with no account and no telemetry" width="440"></a> <a href="docs/screenshots/11-onboarding-explore.webp"><img src="docs/screenshots/11-onboarding-explore.webp" alt="The final onboarding step linking WardenOne's controls, local activity, permissions and network guide" width="440"></a> </p>

</details>

<details> <summary><strong>Updating an unpacked installation</strong></summary>

The rolling ZIP is rebuilt after every passing update to main, but an unpacked extension does not update itself from GitHub.

  1. Export a settings backup from WardenOne before a major update.
  2. Download and unzip the newest build.
  3. Keep your installed WardenOne folder at the same path and replace its contents with the new build.
  4. Open chrome://extensions and press Reload on WardenOne.

Keeping the folder path matters: without a fixed manifest key, Chromium may treat a different unpacked path as a different extension, and its local settings will not automatically follow.

</details>

Compatibility: Chrome, Brave, Edge, Opera and other Chromium-based browsers. <sub>Minimum supported Chromium version: 121.</sub>

Why WardenOne exists

Staying safer online usually means bolting together an ad blocker, anti-tracker, fingerprinting tool, pop-up blocker, download scanner, script controller and tab manager—then hoping they agree. WardenOne brings those layers into one system and adds the phishing, credential-theft, extension-security and verification tools ordinary content blockers leave out.

Three ideas shape the whole product:

  • Evidence before reassurance. “Nothing found” is never rewritten as “safe”.
  • Visible failure. Unsupported rules, missing components and uncertain verdicts are shown rather than silently ignored.
  • Narrow recovery. Pause one site, disable one protection there, undo one firewall decision or trace one rule before resorting to a global switch.

Unknown does not mean safe.

WardenOne deliberately refuses to turn missing evidence into reassurance.

A file with no structural warning is not called harmless. An extension absent from the local catalogue is not called trusted. A search result with no reputation match gets no green tick. A privacy check that cannot actually be measured is marked untestable.

The safest answer WardenOne can give is sometimes “I don't know”.

Why the name WardenOne?

Warden is the role: standing watch over the browser and stepping in when the evidence says something is wrong. It is meant to protect without pretending to know more than it does.

One is the architecture. WardenOne is not an ad blocker sitting beside an unrelated phishing tool, privacy tool, download scanner and extension checker. Those systems share context, evidence and controls. A suspicious redirect can inform a scam warning. A download can use the reputation of the page that started it. A broken site can be traced through the same activity and filtering system that made the decision.

So One means one coordinated defence system across the browser's security and privacy layers. It does not mean one extension can stop every online threat. No browser extension can promise that.

<p align="center"> <img src="docs/divider-wardenone.svg" alt="" width="100%"> </p>

Security

Scams do not all look like malware. Some steal credentials. Some impersonate the browser. Some abuse permissions, redirects, clipboard access or the assumptions people already make. WardenOne covers those surfaces separately because they fail in different ways.

Threat Blocklist

Known malicious, phishing and scam destinations are stopped at the browser's network layer before their pages load. WardenOne ships built-in rules and can fetch fresh vetted feeds each day; tens of thousands of domains are available locally and the upstream feeds cover millions.

A failed update keeps the last working copy rather than creating a gap. The update request asks for a public list file; it does not contain your history or the page you are visiting.

Phishing & Look-Alike Protection

WardenOne blocks g00gle-style substitutions, wrong-TLD brand impersonation and international homographs that render like a familiar name. Brand text, password forms, destination ownership and other context are combined so an innocent mention of a company is not enough to condemn a page.

The optional login-page age check adds a different signal: a password form on a domain registered very recently. It sends only that domain—not its path, page contents or anything you typed—to RDAP when enabled, then caches the answer locally.

Find it: WardenOne → Advanced detection.

Insecure Sign-in Guard

The warning appears when you focus a password field on an unencrypted page, before anything has been typed. It also catches the subtler version: a page itself uses HTTPS but its form posts the password to plain HTTP. Router and other deliberate local-network logins are left alone, and the warning offers the secure version when one exists.

Browser-in-the-Browser Protection

You click Sign in with Microsoft. A convincing Microsoft window appears, with a title bar, address bar and close button. Except no browser window ever opened—the site drew the entire thing inside its own page and owns the password form inside it.

WardenOne warns on the combination that matters: a window-shaped interface claiming a domain the page does not own and somewhere to enter credentials. Ordinary login modals are not treated as fake windows merely for being modal; online IDEs, design tools and normal media surfaces are excluded.

<details> <summary><strong>How detection stays narrower than “this looks like a window”</strong></summary>

The shape alone is weak evidence. WardenOne looks for browser furniture, foreign-domain text, credential entry and the relationship between the displayed identity and the real top-level site. It does not trust a screenshot or a single CSS class. That makes the detector less theatrical and far more useful: a mock browser used in documentation stays quiet, while a fake identity window asking for a password has several signals at once.

</details>

Full-screen Address Guard

Full screen removes the real address bar. A hostile page can then paint its own at the top and ask for a password while the one reliable identity signal is gone. WardenOne warns when a full-screen page draws a domain it does not own alongside sensitive input and offers to leave full screen. Video, games, slideshows and maps are deliberately exempt unless the spoofing evidence is present.

ClickFix & Command Paste Guard

ClickFix scams turn the victim into the malware launcher: “prove you are human”, press Win+R, paste a command, or open DevTools and type what the page prepared. WardenOne recognises the instruction sequence, blocks suspicious programmatic clipboard writes, warns on dangerous copied selections and raises the severity when the instruction and command evidence occur together.

Fake instruction → prepared command → clipboard intervention → clear warning → redacted local event

It does not and cannot read Chrome's own DevTools interface. The protection runs on the page and the clipboard actions the page initiates; it intervenes before the pasted command leaves that context.

<p align="center"> <a href="docs/screenshots/14-clickfix-warning.webp"> <img src="docs/screenshots/14-clickfix-warning.webp" alt="WardenOne warns over a fake verification page that a rea