← All resources
Explainer

Choosing a phishing-protection extension for Chrome

Chrome already blocks known bad sites. If you are adding an extension on top, it is worth knowing exactly what problem you are solving — and what to check before you install anything.

Explainer · 8 min read · By SafeToOpen · August 2025

Search for a phishing-protection extension and you will find dozens, most of them describing themselves in near-identical language. The useful question is not which one has the best marketing copy. It is which gap you are actually trying to close, because Chrome is not starting from nothing.

Start with what Chrome already does

Chrome includes Google Safe Browsing, which checks the sites you visit against a list of pages already reported as dangerous. It is effective, it is free, and it catches a great deal. Enhanced Protection mode, in Chrome’s privacy settings, extends this by sending more data to Google for real-time assessment.

If you have not turned that on, do it before installing anything. It costs nothing and it raises your baseline.

The limitation is structural rather than a flaw: Safe Browsing is strongest against pages that have been seen and reported. A page registered this morning, used for a few hours and abandoned may never accumulate enough reports to be listed at all. Most phishing sites are short-lived by design, precisely because their operators understand this.

The gap worth closing with an extension is the window between a phishing page going live and the wider ecosystem recognising it. If an extension does not address that, it is unlikely to protect you against anything Chrome would have missed.

The categories on offer

Blocklist extensions. These check the address against their own list of known-bad sites. They add value if their list differs from Google’s, and some do. But they share Safe Browsing’s structural limitation: something has to have been reported first.

Reputation and rating extensions. These show a trust score for a site, often based on community ratings and domain age. Useful context, but a brand-new domain has no reputation either way, which is exactly the case where you need an answer.

Live-analysis extensions. These assess the page itself as it loads — its structure, its branding, whether it is asking for credentials, whether it resembles a site it is not. This is the category that can judge a page nobody has reported yet.

Ad and tracker blockers. Worth having, but a different job. They reduce your exposure to malicious advertising; they are not designed to judge whether a login page is genuine.

Five things to check before installing

What permissions does it request? A security extension needs to see pages to assess them, so broad site access is expected. What matters is what the developer says it does with that access. Vague permission descriptions on a security tool are a reason to look elsewhere.

Is there a published privacy policy that is specific? Not “we respect your privacy” but a document that says what is collected, what is transmitted, what is stored and for how long. If browsing history is collected, you should be told plainly.

Who publishes it? An identifiable company with a website, a security contact and documentation is a materially different proposition from an anonymous developer account. For a tool that sees every page you open, that difference matters.

How recently was it updated? Phishing techniques change constantly. An extension last updated two years ago is not tracking anything current.

What do the reviews say over time? Look at recent reviews rather than the average. Extensions occasionally change hands, and behaviour can change with ownership.

Where SafeToOpen sits

We build in the live-analysis category, so that is the comparison we would encourage you to make. SafeToOpen assesses the page as it loads rather than checking it against a list, which is what allows it to flag a sign-in page created this morning. It runs alongside Safe Browsing rather than replacing it, and it explains each warning in plain language rather than simply blocking.

On the questions above: our privacy documentation is published rather than summarised, we are ISO/IEC 27001:2022 certified, and we are a recognised contributor on VirusTotal. Whether that satisfies you is a judgement you should make with the same scepticism you would apply to any extension — including ours.

A reasonable setup

For most people: Chrome’s Enhanced Protection on, one live-analysis extension for the pages nobody has reported yet, and a password manager so a stolen password from one site cannot open another. That combination covers known threats, unknown threats and the consequences of a mistake, which is more than any single tool manages alone.

See it for yourself

SafeToOpen checks links in your browser and inbox in real time — free to start.

See plans →