NUOecurity
Threat Intel

Phishing URL Scanner

AI-scored risk analysis for suspicious links, redirects and payloads.

Phishing URL Scanner
URL
AI-scored
Verdict
Phishing
Risk
70%
  • Homograph characters clean
  • Impersonated brand detected
  • Insecure protocol detected
  • URL shortener clean
Overview

What this plugin does

The Phishing URL Scanner combines lexical heuristics (homograph characters, brand impersonation, suspicious keywords) with reputation lookups to produce a 0–100 risk score. The preview version runs the heuristics client-side; the full scanner also detonates the URL in a sandbox to capture screenshots and final redirect chains.

1. Lexical analysis

The URL is tokenised and checked for Punycode, digit-letter swaps, brand tokens and known phishing keywords.

2. Structural checks

Protocol, subdomain depth, path length, query entropy and known shortener domains are scored.

3. Sandbox detonation

The full scanner loads the URL in an isolated headless browser and records redirects, form fields and screenshots.

Signals we analyse

  • Homograph / Punycode (xn--) characters
  • Brand impersonation tokens (paypa1, m1crosoft, …)
  • Insecure http:// protocol on a login flow
  • URL shorteners hiding the true destination
  • Suspicious keywords: login, verify, secure, update

Common use cases

  • Triage user-reported suspicious emails
  • Automate URL scoring inside SOAR playbooks
  • Prove to a customer why their message was quarantined
Example output

What a full scan returns

This is what the paid, deep-scan version of the plugin produces — a full breakdown you can export as PDF or JSON.

nuosecurity ▸ scan ▸ phishing-url
  • Verdict
    Phishing
    fail
  • Risk score
    88 / 100
    fail
  • Homograph
    digit '1' replacing 'l'
    fail
  • Impersonated brand
    PayPal
    fail
  • Final redirect
    http://credential-harvest.tk/collect
    fail

Frequently asked questions

Do you actually visit the URL?

Only the full scanner does, inside an isolated sandbox. The preview is purely lexical.

How do you avoid false positives?

The AI model weights reputation, WHOIS age and TLS issuance history alongside heuristics.

Can I bulk-scan URLs?

Yes — the API accepts batches of up to 500 URLs per request.

Ready for the full Phishing URL Scanner?

Preview mode uses simulated data. Unlock live results, historical trends, exports and API access.