🎣

BAIT

v2.0

Silently poisoning phishers. Protecting the ones you love.

Smarter detection

Score-based engine combines URL heuristics (typosquats, punycode, suspicious TLDs, IP hosts), form heuristics (passwords on HTTP, cross-domain form actions), brand-mention/domain mismatch, urgency language, countdown timers, and backend-fed domain age + Google Safe Browsing hits. Sensitivity slider in the popup.

Gentle warning banner

Slim red banner injected at the top of flagged pages. 'Leave site' navigates away, 'I trust this site' adds the origin to a whitelist so BAIT skips it next time. Hard-block mode also available.

Richer poisoning

Identity generator includes full address, DOB, fake SSN (invalid range), Luhn-valid test card numbers, IBAN, BTC wallet, and a fake OTP. Realistic per-character typing with occasional typos & backspaces. Multi-pass submits keep regenerating identities to pollute the scammer's DB.

New backend endpoints

/api/check-domain (TLS-cert-derived age + optional Safe Browsing), /api/stats (live counters), /api/history (last 50 alerts), /api/whitelist (sync across devices). Backed by SQLite — no new pip deps.

Popup upgrades

Stats wired to real data. Recent alerts list. Trusted sites list. Banner mode & sensitivity controls. Backend URL field so you can point it at localhost or your hosted Flask app.

Background service worker

Pre-fetches domain intel on every navigation and caches it. Today's blocked-scam count appears as a red badge on the toolbar icon. Desktop notification when an alert fires.