Cover image for project: NEXUS Google Safe Browsing IN PROGRESS

Technical summary

NEXUS Google Safe Browsing checks URLs against Google threat lists (malware, phishing and unwanted software) with a 24 h local cache and automatic enrichment through the Intelligence Hub. It ships single queries, bulk checks, history and alerts from the panel or the /safebrowsing slash command.

Executed scope

  • Plugin registration (registerTab('safebrowsing','Safe Browsing','globe-lock',tab.php,'Threat Intel') + registerDoc) and sb_install() creating the safebrowsing_cache table (MD5 url_hash as PK, SAFE/MALICIOUS status, threat_type/platform_type/threat_entry_type, checked_at with indexes on status and checked_at).
  • 11 API actions: safebrowsing_stats (totals + API status), safebrowsing_query (single check clearing cache), safebrowsing_bulk (batch), safebrowsing_check_task (scans URLs in the task description/comments), safebrowsing_history (paginated), safebrowsing_alerts (recent malicious), safebrowsing_purge (clears expired cache), safebrowsing_settings/settings_save (key + auto-enrich) and safebrowsing_delete (removes a URL from cache).
  • Google Safe Browsing API v4 integration (threatMatches:find): threatTypes MALWARE, SOCIAL_ENGINEERING, UNWANTED_SOFTWARE and POTENTIALLY_HARMFUL_APPLICATION; key configured in the panel with recommended IP restriction (free tier ~10,000 queries/day, reduced by the cache).
  • 24 h TTL local cache: sb_normalize_url() adds https:// to schemeless domains, sb_check_urls() only calls the API on expired cache and sb_is_whitelisted() skips safe domains (localhost, Google, GitHub, Cloudflare and ecosystem domains).
  • Enrichment (Intelligence Hub): nx_intel_register_enricher('safebrowsing', ['url'], 'sb_intel_enrich', 40) publishes signals to task.intel/comment.intel (auto_enrich default true); legacy task/comment read filters disabled.
  • sb_purge cronjob (tick, 24 h throttle) removing cache with checked_at > 30 days; allowlisted cli.php runs the same purge via NEXUS Cronjobs.
  • Fast Responses: fastr.json manifest with /safebrowsing <URL or domain> (required arg, domain normalized with https://), safebrowsing_query action.
  • UI (tab.php, 576 lines, Alpine gsbApp()): API Online/Offline badge, 4 stat cards (Total Cache, Safe, Malicious, Today) and 5 tabs — Scanner, Check Task, History, Alerts and Settings.

Stack and tools

  • PHP 8 backend (no framework) + MySQL 8 (safebrowsing_cache)
  • Google Safe Browsing API v4 (threatMatches:find) with 24 h local cache
  • Alpine.js + Tailwind CSS (tab.php + own assets/icons.svg)
  • Internal Plugin API (PluginManager tabs/actions + cronjob.json + fastr.json + enricher)

Operational tags

  • Google Safe Browsing
  • URLs
  • Malware
  • Phishing
  • Threat Intel
  • Cache
  • Enrichment
  • NEXUS Plugin

Operational result

  • URL threat intel: single or batch checks against Google malware, phishing, unwanted software and potentially harmful applications.
  • 24 h cache: safebrowsing_cache keyed by URL hash reduces API usage (free tier ~10,000/day) and answers instantly on re-checks.
  • Automatic enrichment: URLs found in tasks/comments get security signals via the Intelligence Hub with no manual action.
  • Panel and slash: 5 tabs with scanner, task checking, paginated history, alerts and settings; /safebrowsing works straight from the editor.
  • Cache hygiene: cron purge (30 days, 24 h throttle) plus manual action/CLI keeps the table lean.
  • Domain whitelist: own infrastructure and trusted services are skipped, reducing noise and API usage.

GitHub progress (issues)

Real-time panel with latest repository issues.

abertas (amostra): -- fechadas (amostra): -- base: -- ultimas issues

carregando andamento...

Real results

Checks URLs against Google threat lists (malware, phishing and unwanted software) with a 24 h local cache and automatic enrichment through the Intelligence Hub; includes single queries, bulk checks, history and alerts from the panel or the /safebrowsing slash command.

Architecture and organization

Execution and operations

The project follows reproducible execution flow with technical validation in production-like environments.

Screenshots

Talk about this project

Apply this implementation pattern in your environment and accelerate delivery with technical consistency.