Hey Indie Hackers! đź‘‹ I'm Udit, founder of PhishX.
I wanted to share what I've been building and the story behind why we decided to tackle the phishing problem from a completely different angle.
Most phishing protection tools and browser extensions rely heavily on static, third-party blacklists (like Google Safe Browsing or proprietary threat feeds). While these are great for known threats, there is a massive time gap:
When a zero-day phishing link is generated, it often takes hours or days to be reported, verified, and added to a blacklist.
In that window, thousands of users get compromised.
On top of that, many existing tools require sending your entire browsing history or sensitive URL data to third-party servers, compromising user privacy.
I built PhishX to give developers, security teams, and everyday users a zero-latency, AI-powered phishing analysis engine.
Instead of waiting for a URL to show up on a database, PhishX actively analyzes links in real-time using machine learning and behavioral heuristics to detect zero-day threats the moment they appear—without snooping on or selling user data.
Key Highlights:
Real-Time AI Detection: Spotting credential harvesting, brand impersonation, and deceptive routing dynamically.
Privacy-First Architecture: Built from the ground up so you don't have to trade your data privacy for cyber protection.
Developer & Community Friendly: Featuring community intelligence logs, automated diagnostic health checks, and a sleek glassmorphic UI.
We just rolled out our latest platform updates, including full multi-browser optimization (from desktop Brave & Firefox down to mobile WebViews) and an executive admin oversight dashboard.
I am sharing this here because I’d love to get feedback from fellow developers and makers:
How do you currently handle link safety or threat detection in your workflows/teams?
If you try out the scanner or dashboard, what UI/UX or feature improvements would make this a "no-brainer" tool for you?
Check out the website, give it a spin, and let me know what you think in the comments below! I'll be hanging out all day to answer any technical questions about our architecture or detection models. Cheers! 🚀
The interesting challenge with AI security tools is earning trust when the threat model is constantly changing.
Curious how you’re validating PhishX against new phishing techniques, rather than just known attack patterns?
Thank you, that’s a great question!
We validate PhishX against zero-day threats by focusing on math and behavior, not just reputation. Our ML engine analyzes the deep lexical structure of a URL (like entropy and character anomalies) because even brand-new phishing links share structural tells. We pair this with live DOM scanning to detect credential harvesting on the fly. We aren't just checking if a link is known to be bad—we’re analyzing if it’s acting bad right now.
Thanks for the explanation. I'd like to spend a little time with PhishX first, then compare a few thoughts with you. What's the best email to reach you on?
Hi Aryan, absolutely. Take all the time you need to test out the platform! Indie Hackers doesn't let me post links or emails here yet, but you can find my direct contact info (and my portfolio) in the 'Meet the Creator' section on the PhishX website. Looking forward to hearing your thoughts!
Thanks! I’ve just sent it over email.
Looking forward to hearing your thoughts whenever you have a chance.