SkimShield

Real-time formjacking detection that detects web skimming attacks targeting your payment information.

As of June 2026, SkimShield has 1 users and a 4.00/5 rating from 1 reviews in the Privacy & Security category.

Usersno change0%
1
1
Ratingno change0%
4.00
1 reviews
Reviewsno change0%
1
Version
1.0.1
Manifest V3
90-day change · In the last 90 days this extension 1 version update.

History

6 snapshots

Tracking since May 7, 2026.

6.43.50.5999999999999996May 7, 2026Jun 13, 2026
View as table
DateUsersRatingReviewsVersion
May 7, 20261.0.0
May 11, 20261.0.0
May 17, 202611.0.0
May 23, 202641.0.0
May 30, 202661.0.0
Jun 5, 202641.0.1
Now14.0011.0.1

Permissions & access

Permissions
storagealarmsdeclarativeNetRequesttabs
Host access
<all_urls>

Screenshots

SkimShield screenshot 1SkimShield screenshot 2SkimShield screenshot 3SkimShield screenshot 4

About

SkimShield detects formjacking (web skimming) attacks targeting your payment card data in real time — the kind used in the Magecart breaches that hit British Airways, Ticketmaster, and thousands of online stores.

HOW IT WORKS
When you enter payment details on a checkout page, SkimShield monitors outgoing network requests. If a suspicious script tries to send your card number, CVV, or expiry date to an unknown external server, SkimShield alerts you immediately — and lets you block that domain with one click.

WHAT IT MONITORS
• fetch() and XMLHttpRequest calls
• sendBeacon requests (commonly abused by skimmers)
• Image.src requests (skimmers encode stolen data in image URLs)
• WebSocket connections
• localStorage staging patterns
• Dynamically injected scripts and hidden iframes

SMART HEURISTIC ENGINE
SkimShield uses a multi-signal heuristic engine — not simple keyword matching. It correlates timing, payload content, destination domain, and DOM manipulation patterns to minimize false alarms. 220 recognized domains — including 110+ trusted payment gateways (Stripe, PayPal, Toss Payments, and others), analytics services, and monitoring tools — are pre-classified so legitimate traffic is never flagged.

ADJUSTABLE ALERT LEVEL
• Level 1 (Minimal): Only confirmed dangerous requests
• Level 2 (Default): Dangerous + strong attack signals
• Level 3 (Maximum): All suspicious activity

100% LOCAL — ZERO DATA COLLECTION
All analysis runs entirely in your browser. SkimShield never sends your browsing data, form inputs, or any personal information to any server. There is no account, no sign-up, and no telemetry.

OPEN & TRANSPARENT
SkimShield is built on open web standards (Chrome Manifest V3). No obfuscated code. No hidden behavior.

Technical

Version
1.0.1
Manifest
V3
Size
102KiB
Min Chrome
111
Languages
1
Featured
No

Metadata

ID
jajlfkkppfgbinemeglbmmhaeheffgid
Developer ID
u1723173a0599ff3f3c3760636d46be83
Developer Email
[email protected]
Created
May 6, 2026
Last Updated (Store)
May 25, 2026
Last Scraped
Jun 13, 2026
Website
Support URL

Data sourced from the Chrome Web Store · last verified Jun 13, 2026.