IN PROGRESS
Technical summary
NEXUS Google Safe Browsing checks URLs against Google threat lists (malware, phishing and unwanted software) with a 24 h local cache and automatic enrichment through the Intelligence Hub. It ships single queries, bulk checks, history and alerts from the panel or the /safebrowsing slash command.
Executed scope
- Plugin registration (
registerTab('safebrowsing','Safe Browsing','globe-lock',tab.php,'Threat Intel')+registerDoc) andsb_install()creating thesafebrowsing_cachetable (MD5 url_hash as PK, SAFE/MALICIOUS status, threat_type/platform_type/threat_entry_type, checked_at with indexes on status and checked_at). - 11 API actions:
safebrowsing_stats(totals + API status),safebrowsing_query(single check clearing cache),safebrowsing_bulk(batch),safebrowsing_check_task(scans URLs in the task description/comments),safebrowsing_history(paginated),safebrowsing_alerts(recent malicious),safebrowsing_purge(clears expired cache),safebrowsing_settings/settings_save(key + auto-enrich) andsafebrowsing_delete(removes a URL from cache). - Google Safe Browsing API v4 integration (
threatMatches:find): threatTypes MALWARE, SOCIAL_ENGINEERING, UNWANTED_SOFTWARE and POTENTIALLY_HARMFUL_APPLICATION; key configured in the panel with recommended IP restriction (free tier ~10,000 queries/day, reduced by the cache). - 24 h TTL local cache:
sb_normalize_url()addshttps://to schemeless domains,sb_check_urls()only calls the API on expired cache andsb_is_whitelisted()skips safe domains (localhost, Google, GitHub, Cloudflare and ecosystem domains). - Enrichment (Intelligence Hub):
nx_intel_register_enricher('safebrowsing', ['url'], 'sb_intel_enrich', 40)publishes signals totask.intel/comment.intel(auto_enrich default true); legacy task/comment read filters disabled. sb_purgecronjob (tick, 24 h throttle) removing cache with checked_at > 30 days; allowlistedcli.phpruns the same purge via NEXUS Cronjobs.- Fast Responses:
fastr.jsonmanifest with/safebrowsing <URL or domain>(required arg, domain normalized withhttps://),safebrowsing_queryaction. - UI (
tab.php, 576 lines, AlpinegsbApp()): API Online/Offline badge, 4 stat cards (Total Cache, Safe, Malicious, Today) and 5 tabs — Scanner, Check Task, History, Alerts and Settings.
Stack and tools
- PHP 8 backend (no framework) + MySQL 8 (
safebrowsing_cache) - Google Safe Browsing API v4 (
threatMatches:find) with 24 h local cache - Alpine.js + Tailwind CSS (
tab.php+ ownassets/icons.svg) - Internal Plugin API (PluginManager tabs/actions +
cronjob.json+fastr.json+ enricher)
Operational tags
- Google Safe Browsing
- URLs
- Malware
- Phishing
- Threat Intel
- Cache
- Enrichment
- NEXUS Plugin
Operational result
- URL threat intel: single or batch checks against Google malware, phishing, unwanted software and potentially harmful applications.
- 24 h cache:
safebrowsing_cachekeyed by URL hash reduces API usage (free tier ~10,000/day) and answers instantly on re-checks. - Automatic enrichment: URLs found in tasks/comments get security signals via the Intelligence Hub with no manual action.
- Panel and slash: 5 tabs with scanner, task checking, paginated history, alerts and settings;
/safebrowsingworks straight from the editor. - Cache hygiene: cron purge (30 days, 24 h throttle) plus manual action/CLI keeps the table lean.
- Domain whitelist: own infrastructure and trusted services are skipped, reducing noise and API usage.
GitHub progress (issues)
Real-time panel with latest repository issues.
live feed
open issues on GitHubcarregando andamento...
não foi possivel carregar as issues agora. abra no github pelo link acima.
Real results
Checks URLs against Google threat lists (malware, phishing and unwanted software) with a 24 h local cache and automatic enrichment through the Intelligence Hub; includes single queries, bulk checks, history and alerts from the panel or the /safebrowsing slash command.
Architecture and organization
- PHP 8
- MySQL 8
- Google Safe Browsing API v4
- Alpine.js
- Tailwind CSS
- Plugin NEXUS
Execution and operations
The project follows reproducible execution flow with technical validation in production-like environments.
Screenshots
Talk about this project
Apply this implementation pattern in your environment and accelerate delivery with technical consistency.