A complete, self-contained Phishing & Malicious URL Analyzer built with pure Python (backend) + JavaScript (frontend).
No API keys required. Fully explainable risk scoring based on lexical, structural, DNS, SSL, WHOIS, and content heuristics.
- Real-time URL analysis
- Explainable risk score (0–100) with detailed reasons
- Lexical features: length, entropy, keywords, brand impersonation, IP hosts, risky TLDs
- DNS resolution check
- SSL certificate validation & expiry
- WHOIS domain age & registrar
- HTTP content analysis (login forms, redirects, iframes, suspicious keywords)
- Modern dark UI with live results
- Zero external blacklist dependency (works offline for most checks)
cd phishing-analyzer
python -m venv venv
source venv/bin/activate # Windows: venv\Scripts\activate
pip install -r requirements.txt
cd backend
python app.pyOpen http://localhost:5000 in your browser.
curl -X POST http://localhost:5000/api/analyze \
-H "Content-Type: application/json" \
-d '{"url": "https://example-suspicious.xyz/login"}'phishing-analyzer/
├── backend/
│ ├── app.py # Flask server
│ └── analyzer.py # Core detection engine
├── frontend/
│ └── index.html # Single-page UI
├── requirements.txt
└── README.md
The engine assigns weighted points for:
| Signal | Typical Points |
|---|---|
| IP address as hostname | +25 |
| @ symbol obfuscation | +20 |
| Brand name in subdomain | +18 |
| Domain age < 7 days | +25 |
| Domain age < 30 days | +18 |
| High-risk TLD | +15 |
| No HTTPS / invalid cert | +12–20 |
| High hostname entropy (DGA) | +8–12 |
| Suspicious keywords | +3 each |
| Multiple redirects | +3 each |
| Login form on risky URL | +12 |
| … and more |
Score ≥ 70 → Critical
Score ≥ 45 → High
Score ≥ 25 → Medium
Score ≥ 10 → Low
Below 10 → Safe
This tool is for educational and defensive security research only.
It does not replace commercial threat intelligence feeds or professional security tools.
False positives/negatives are possible. Always use judgment.
MIT — free to use, modify, and share.