ElHunter
Real-time URL, domain & IP threat analysis via ZeroScan
As of June 2026, ElHunter has 4 users and a 5.00/5 rating from 2 reviews in the Productivity category.
Usersup 300.0 percent+300.0%
4
4
Ratingno change0%
5.00
2 reviews
Reviewsno change0%
2
Version
1.2.0
Manifest V3
90-day change · In the last 90 days this extension 1 version update.
History
8 snapshotsTracking since Apr 1, 2026.
View as table
| Date | Users | Rating | Reviews | Version |
|---|---|---|---|---|
| Apr 1, 2026 | 1 | — | — | 1.1.0 |
| Apr 17, 2026 | 1 | — | — | 1.1.0 |
| Apr 27, 2026 | 1 | — | — | 1.1.0 |
| May 5, 2026 | 3 | 5.00 | 2 | 1.1.0 |
| May 10, 2026 | 4 | 5.00 | 2 | 1.2.0 |
| May 28, 2026 | 3 | 5.00 | 2 | 1.2.0 |
| Jun 4, 2026 | 4 | 5.00 | 2 | 1.2.0 |
| Jun 10, 2026 | 5 | 5.00 | 2 | 1.2.0 |
| Now | 4 | 5.00 | 2 | 1.2.0 |
Changelog
- May 5, 2026description
ElHunter — Threat Intelligence & Phishing Detector ElHunter is a real-time cybersecurity extension that checks every website you visit against VirusTotal and AbuseIPDB threat intelligence databases. If a domain or IP address is flagged as malicious, access is blocked immediately and a detailed threat report is shown — including VirusTotal vendor count, AbuseIPDB abuse confidence score, resolved IP address, hosting country, ISP, and Cloudflare detection. Malicious sites are blocked using Chrome's declarativeNetRequest API before the page loads. On repeat visits, known threats are blocked instantly at the network level — no API call required. ElHunter also detects phishing threats in email. On Gmail, Outlook, Yahoo Mail, and ProtonMail, every link inside an open email is automatically scanned via VirusTotal and AbuseIPDB. Results appear inline at the top of the page. Optionally, the full email can be analyzed by an AI model of your choice to receive a 0–100% phishing probability score with a one-sentence explanation. AI analysis only runs when you explicitly click Analyze — email content is never sent automatically. Country-based rules let you block or monitor traffic from specific countries by server hosting location (IP geolocation) or domain TLD. Each rule can be configured to notify only, block completely, or send a Telegram alert. Scan results are cached locally for 14 days so that revisiting a known site never triggers a redundant API call. No data is collected by ElHunter. API keys are stored locally in your browser and sent only to their respective services. All threat checks run directly from your browser — no proxy, no telemetry, no middleman. ElHunter is open source. Source code and full documentation are available on GitHub: https://github.com/elstati0n/ELHunter
ElHunter — Threat Intelligence & Phishing Detector ElHunter is a real-time cybersecurity extension that checks every website you visit against ZeroScan.az threat intelligence. If a domain, IP address, or URL is flagged as malicious, access is blocked immediately and a detailed threat report is shown — including ZeroScan verdict, category, resolved IP address, hosting country, ISP, and Cloudflare detection. Malicious sites are blocked using Chrome's declarativeNetRequest API before the page loads. On repeat visits, known threats are blocked instantly at the network level — no API call required. ElHunter also detects phishing threats in email. On Gmail, Outlook, Yahoo Mail, and ProtonMail, every link inside an open email is automatically scanned via ZeroScan.az. Results appear inline at the top of the page. Optionally, the full email can be analyzed by an AI model of your choice to receive a 0–100% phishing probability score with a one-sentence explanation. AI analysis only runs when you explicitly click Analyze — email content is never sent automatically. Country-based rules let you block or monitor traffic from specific countries by server hosting location (IP geolocation) or domain TLD. Each rule can be configured to notify only, block completely, or send a Telegram alert. Scan results are cached locally for 14 days so that revisiting a known site never triggers a redundant API call. No data is collected by ElHunter. API keys are stored locally in your browser and sent only to their respective services. All threat checks run directly from your browser — no proxy, no telemetry, no middleman. ElHunter is open source. Source code and full documentation are available on GitHub: https://github.com/elstati0n/ELHunter
- May 5, 2026short_description
Real-time domain & IP threat analysis via VirusTotal and AbuseIPDB
Real-time URL, domain & IP threat analysis via ZeroScan
Permissions & access
- Permissions
- storagetabswebNavigationscriptingnotificationsdeclarativeNetRequest
- Host access
- <all_urls>, https://www.virustotal.com/*, https://api.abuseipdb.com/*, https://dns.google/*, https://cloudflare-dns.com/*, https://networkcalc.com/*, https://ipinfo.io/*, https://api.telegram.org/*, https://api.openai.com/*, https://api.anthropic.com/*, https://generativelanguage.googleapis.com/*, https://api.mistral.ai/*, https://api.groq.com/*, https://openrouter.ai/*
Screenshots
About
ElHunter — Threat Intelligence & Phishing Detector ElHunter is a real-time cybersecurity extension that checks every website you visit against ZeroScan.az threat intelligence. If a domain, IP address, or URL is flagged as malicious, access is blocked immediately and a detailed threat report is shown — including ZeroScan verdict, category, resolved IP address, hosting country, ISP, and Cloudflare detection. Malicious sites are blocked using Chrome's declarativeNetRequest API before the page loads. On repeat visits, known threats are blocked instantly at the network level — no API call required. ElHunter also detects phishing threats in email. On Gmail, Outlook, Yahoo Mail, and ProtonMail, every link inside an open email is automatically scanned via ZeroScan.az. Results appear inline at the top of the page. Optionally, the full email can be analyzed by an AI model of your choice to receive a 0–100% phishing probability score with a one-sentence explanation. AI analysis only runs when you explicitly click Analyze — email content is never sent automatically. Country-based rules let you block or monitor traffic from specific countries by server hosting location (IP geolocation) or domain TLD. Each rule can be configured to notify only, block completely, or send a Telegram alert. Scan results are cached locally for 14 days so that revisiting a known site never triggers a redundant API call. No data is collected by ElHunter. API keys are stored locally in your browser and sent only to their respective services. All threat checks run directly from your browser — no proxy, no telemetry, no middleman. ElHunter is open source. Source code and full documentation are available on GitHub: https://github.com/elstati0n/ELHunter
Technical
- Version
- 1.2.0
- Manifest
- V3
- Size
- 94.25KiB
- Min Chrome
- 88
- Languages
- 1
- Featured
- No
Metadata
- ID
- gpjjgdalldkngdegnfbjcabdehpkpjal
- Developer ID
- u4663a4f9f8e3d74e4de3e54d14cbed9c
- Developer Email
- [email protected]
- Created
- Mar 23, 2026
- Last Updated (Store)
- May 2, 2026
- Last Scraped
- Jun 10, 2026
- Website
- —
- Support URL
- —
Data sourced from the Chrome Web Store · last verified Jun 10, 2026.