IN PROGRESS
Technical summary
NEXUS URL Detonator Sandbox detonates suspicious URLs in isolation, tracing the full redirect chain to the final page with anti-SSRF protection against internal addresses. The plugin extracts DOM features, scores phishing heuristics (0–100) — credential forms, brand impersonation, suspicious TLDs and obfuscation — and classifies the verdict as safe, suspicious or malicious, with history and statistics in the panel.
Executed scope
- Plugin registration in
plugin.php:registerTab('url-detonator', tab.php)with thezapicon (Security category),registerDoc('url-detonator', doc.md)and 8 API actions viaregisterApiAction(detonator_prefix). - Database: MySQL table
detonator_history(target_url, final_url, risk_score, verdict, redirect_count, redirect_chain LONGTEXT, page_title, dom_features LONGTEXT, heuristics_log LONGTEXT, task_id, created_at, withidx_risk_score/idx_verdict/idx_created_atindexes) — created withCREATE TABLE IF NOT EXISTSindetonator_install(); no install.sql. - Centralized configuration in
detonator_settings(viaDB::getConfig):timeout_seconds(3–30, default 8),max_redirects(1–20, default 10),user_agent(Chrome 124) anddomain_whitelist. - Anti-SSRF protection (
detonator_is_private_ip): blockslocalhost,127.0.0.1,::1,0.0.0.0and private/reserved ranges (10/8, 172.16/12, 192.168/16, link-local/metadata) viaFILTER_FLAG_NO_PRIV_RANGE/NO_RES_RANGE. - Redirect tracing (
detonator_trace_redirects): follows up tomax_redirectsHTTP hops (301/302/307/308), records the full chain with steps, detects loops (visited set) and captures the final page HTML. - DOM analysis (
detonator_analyze_dom): extracts title, meta description, forms, iframes, password/email inputs, HTML size and detects brand impersonation (Microsoft, Google, Apple, Banking, Meta, PayPal, Gov) on non-official domains. - Risk heuristics 0–100 (
detonator_calculate_heuristics): 9 scored rules —EXCESSIVE_REDIRECTS(20/30 pts),CROSS_DOMAIN_REDIRECT(10),CREDENTIAL_HARVESTING_FORM(25/35),BRAND_IMPERSONATION(30),INSECURE_HTTP(15/30),RAW_IP_HOST(25),URL_AUTH_AT_SIGN(25),PUNYCODE_HOMOGLYPH(20) andSUSPICIOUS_TLD(15 —.xyz,.top,.click,.tk,.ml,.ga,.cf,.gq,.buzz,.fit,.cc,.live,.icu,.monster). - Verdict by score range: ≥66
MALICIOUS_PHISHING, 31–65SUSPICIOUS, ≤30SAFE, with semantic labels and badges. - Full detonation (
detonator_detonate_url): normalizes the URL (https://prefix), anti-SSRF validation, tracing, analysis, scoring, persistence in history and evidence return (chain, DOM, triggers) with optionaltask_id. - Statistics (
detonator_stats): total, per-verdict counts and average score. History (detonator_history, 1–100 limit) and clear (detonator_history_clear, TRUNCATE). - Fast Responses:
fastr.jsonmanifest with/detonate <url>(instant detonation with verdict and chain in chat) plusdetonator_fastr_suggest. - Intel Hub:
nx_intel_register_enricher('url-detonator', ['url', 'domain'], 'detonator_intel_enrich', 41)— exposes the last verdict/score for the URL or domain. - Interface (
tab.php, 535 lines): 4 tabs — Detonate (URL field, verdict badge, redirect chain and triggers), History, Rules (heuristics explanation) and Settings — with 4 KPIs (Total, Phishing, Suspicious, Safe).
Stack and tools
- PHP 8 backend (no framework) + MySQL (
detonator_history) - cURL for redirect tracing and final HTML capture
- Alpine.js + Tailwind CSS (4 tabs, KPIs, verdict badges and chain visualization)
- Internal Plugin API (PluginManager tabs/docs/actions +
fastr.json+ intel enricher) - NEXUS API Bearer token authentication on API calls
Operational tags
- URL
- Phishing
- Redirect
- Sandbox
- DOM
- Heuristics
- Security
- Threat Intel
- Analysis
- NEXUS Plugin
Operational result
- Isolated detonation: URL analysis without host impact, with controlled timeouts and anti-SSRF protection.
- Actionable verdict: 0–100 score with explained triggers (rule, points, title and description).
- Structured evidence: full redirect chain and DOM features for security reports.
- Phishing detection: credential forms, brand impersonation, suspicious TLDs and obfuscation.
- History and statistics: verdict distribution and average score in the panel.
- Quick access:
/detonate <url>slash command straight from the Fastr terminal.
GitHub progress (issues)
Real-time panel with latest repository issues.
live feed
open issues on GitHubcarregando andamento...
não foi possivel carregar as issues agora. abra no github pelo link acima.
Real results
NEXUS URL Detonator Sandbox detonates suspicious URLs in isolation, tracing the full redirect chain to the final page with anti-SSRF protection against internal addresses. The plugin extracts DOM features, scores phishing heuristics (0–100) — credential forms, brand impersonation, suspicious TLDs and obfuscation — and classifies the verdict as safe, suspicious or malicious, with history and statistics in the panel.
Architecture and organization
- PHP 8
- MySQL
- Alpine.js
- Tailwind CSS
- cURL
- DNS
- Plugin NEXUS
Execution and operations
The project follows reproducible execution flow with technical validation in production-like environments.
Screenshots
Talk about this project
Apply this implementation pattern in your environment and accelerate delivery with technical consistency.