Cover image for project: NEXUS URL Detonator Sandbox IN PROGRESS

Technical summary

NEXUS URL Detonator Sandbox detonates suspicious URLs in isolation, tracing the full redirect chain to the final page with anti-SSRF protection against internal addresses. The plugin extracts DOM features, scores phishing heuristics (0–100) — credential forms, brand impersonation, suspicious TLDs and obfuscation — and classifies the verdict as safe, suspicious or malicious, with history and statistics in the panel.

Executed scope

  • Plugin registration in plugin.php: registerTab('url-detonator', tab.php) with the zap icon (Security category), registerDoc('url-detonator', doc.md) and 8 API actions via registerApiAction (detonator_ prefix).
  • Database: MySQL table detonator_history (target_url, final_url, risk_score, verdict, redirect_count, redirect_chain LONGTEXT, page_title, dom_features LONGTEXT, heuristics_log LONGTEXT, task_id, created_at, with idx_risk_score/idx_verdict/idx_created_at indexes) — created with CREATE TABLE IF NOT EXISTS in detonator_install(); no install.sql.
  • Centralized configuration in detonator_settings (via DB::getConfig): timeout_seconds (3–30, default 8), max_redirects (1–20, default 10), user_agent (Chrome 124) and domain_whitelist.
  • Anti-SSRF protection (detonator_is_private_ip): blocks localhost, 127.0.0.1, ::1, 0.0.0.0 and private/reserved ranges (10/8, 172.16/12, 192.168/16, link-local/metadata) via FILTER_FLAG_NO_PRIV_RANGE/NO_RES_RANGE.
  • Redirect tracing (detonator_trace_redirects): follows up to max_redirects HTTP hops (301/302/307/308), records the full chain with steps, detects loops (visited set) and captures the final page HTML.
  • DOM analysis (detonator_analyze_dom): extracts title, meta description, forms, iframes, password/email inputs, HTML size and detects brand impersonation (Microsoft, Google, Apple, Banking, Meta, PayPal, Gov) on non-official domains.
  • Risk heuristics 0–100 (detonator_calculate_heuristics): 9 scored rules — EXCESSIVE_REDIRECTS (20/30 pts), CROSS_DOMAIN_REDIRECT (10), CREDENTIAL_HARVESTING_FORM (25/35), BRAND_IMPERSONATION (30), INSECURE_HTTP (15/30), RAW_IP_HOST (25), URL_AUTH_AT_SIGN (25), PUNYCODE_HOMOGLYPH (20) and SUSPICIOUS_TLD (15 — .xyz, .top, .click, .tk, .ml, .ga, .cf, .gq, .buzz, .fit, .cc, .live, .icu, .monster).
  • Verdict by score range: ≥66 MALICIOUS_PHISHING, 31–65 SUSPICIOUS, ≤30 SAFE, with semantic labels and badges.
  • Full detonation (detonator_detonate_url): normalizes the URL (https:// prefix), anti-SSRF validation, tracing, analysis, scoring, persistence in history and evidence return (chain, DOM, triggers) with optional task_id.
  • Statistics (detonator_stats): total, per-verdict counts and average score. History (detonator_history, 1–100 limit) and clear (detonator_history_clear, TRUNCATE).
  • Fast Responses: fastr.json manifest with /detonate <url> (instant detonation with verdict and chain in chat) plus detonator_fastr_suggest.
  • Intel Hub: nx_intel_register_enricher('url-detonator', ['url', 'domain'], 'detonator_intel_enrich', 41) — exposes the last verdict/score for the URL or domain.
  • Interface (tab.php, 535 lines): 4 tabs — Detonate (URL field, verdict badge, redirect chain and triggers), History, Rules (heuristics explanation) and Settings — with 4 KPIs (Total, Phishing, Suspicious, Safe).

Stack and tools

  • PHP 8 backend (no framework) + MySQL (detonator_history)
  • cURL for redirect tracing and final HTML capture
  • Alpine.js + Tailwind CSS (4 tabs, KPIs, verdict badges and chain visualization)
  • Internal Plugin API (PluginManager tabs/docs/actions + fastr.json + intel enricher)
  • NEXUS API Bearer token authentication on API calls

Operational tags

  • URL
  • Phishing
  • Redirect
  • Sandbox
  • DOM
  • Heuristics
  • Security
  • Threat Intel
  • Analysis
  • NEXUS Plugin

Operational result

  • Isolated detonation: URL analysis without host impact, with controlled timeouts and anti-SSRF protection.
  • Actionable verdict: 0–100 score with explained triggers (rule, points, title and description).
  • Structured evidence: full redirect chain and DOM features for security reports.
  • Phishing detection: credential forms, brand impersonation, suspicious TLDs and obfuscation.
  • History and statistics: verdict distribution and average score in the panel.
  • Quick access: /detonate <url> slash command straight from the Fastr terminal.

GitHub progress (issues)

Real-time panel with latest repository issues.

abertas (amostra): -- fechadas (amostra): -- base: -- ultimas issues

carregando andamento...

Real results

NEXUS URL Detonator Sandbox detonates suspicious URLs in isolation, tracing the full redirect chain to the final page with anti-SSRF protection against internal addresses. The plugin extracts DOM features, scores phishing heuristics (0–100) — credential forms, brand impersonation, suspicious TLDs and obfuscation — and classifies the verdict as safe, suspicious or malicious, with history and statistics in the panel.

Architecture and organization

Execution and operations

The project follows reproducible execution flow with technical validation in production-like environments.

Screenshots

Talk about this project

Apply this implementation pattern in your environment and accelerate delivery with technical consistency.