Hx0 DateGuard by asaotomo
Local sensitive information and phishing email identification tool, supporting page/API scanning, input leak prevention, rule management, and report export.
5 Users5 Users
Extension Metadata
Screenshots
About this extension
Local sensitive information and phishing email identification tool, supporting page/API scanning, input leak prevention, rule management, and report export.
Hx0 DataGuard is a local security assistant tool running in the browser, designed for daily office work, development testing, and authorized security self-inspection scenarios.
It helps you scan for sensitive information and API paths in web pages, detect leak risks in advance when inputting content into AI, forms, or chat boxes, and perform offline phishing risk analysis on webmail or local EML emails.
Page scanning, input detection, and email analysis are completed locally on your device by default, with no uploading of page content or email body.
Page Sensitive Information Detection
One-click scan of the current web page's DOM, inline scripts, external JavaScript, and page comments to identify potentially exposed sensitive data, such as:
Scan results are centrally displayed in the browser sidebar, providing hit locations and context for easy manual review.
API Path Discovery
Extract API paths, webhooks, intranet addresses, management interfaces, and other interface clues from web pages and external scripts to help developers and security personnel quickly map the front-end attack surface.
With proper authorization, further probing can be performed on discovered paths, and results are uniformly organized into scan reports.
Input Leak Prevention
Real-time detection of input or pasted content in chat boxes, AI dialog boxes, office systems, and regular web forms to identify potential sensitive information before sending.
Supports:
Adapted for common AI and office scenarios, while covering most regular web input fields. Login pages typically do not participate in input monitoring.
Phishing Email Identification
Fully offline analysis of opened webmail, downloaded EML files, or manually imported local EML emails.
Can assist in checking:
Analysis results provide a risk score, main basis, link and attachment information, IOC classification, and handling suggestions.
The email risk score is for auxiliary analysis only and does not represent the probability of malice. Webmail is limited by page structure; if more complete results are needed, it is recommended to prioritize importing the original EML file.
Rule Center
Built-in approximately 130 sensitive information detection rules, and supports:
Report Export
Scan and analysis results can be exported as:
Facilitating security self-inspection, issue archiving, internal reporting, and development remediation follow-up.
Local First and Privacy Protection
Hx0 DataGuard adopts a local-first processing approach:
No account registration required to start using.
Applicable Scenarios
Usage Instructions
This tool is only for authorized testing, security self-inspection, and auxiliary analysis, and cannot replace formal penetration testing, code auditing, email security gateways, or compliance certification.
Scanning and analysis results may contain false positives or false negatives. Please conduct manual review combined with business context, raw data, and official channels.
New users can get 1-day VIP experience upon first installation to fully experience all features.
Hx0 DataGuard is a local security assistant tool running in the browser, designed for daily office work, development testing, and authorized security self-inspection scenarios.
It helps you scan for sensitive information and API paths in web pages, detect leak risks in advance when inputting content into AI, forms, or chat boxes, and perform offline phishing risk analysis on webmail or local EML emails.
Page scanning, input detection, and email analysis are completed locally on your device by default, with no uploading of page content or email body.
Page Sensitive Information Detection
One-click scan of the current web page's DOM, inline scripts, external JavaScript, and page comments to identify potentially exposed sensitive data, such as:
- API Keys, Tokens, keys, and connection information
- Personal sensitive information such as phone numbers and ID numbers
- Test accounts, internal addresses, and debugging information
- Other sensitive content matching detection rules
Scan results are centrally displayed in the browser sidebar, providing hit locations and context for easy manual review.
API Path Discovery
Extract API paths, webhooks, intranet addresses, management interfaces, and other interface clues from web pages and external scripts to help developers and security personnel quickly map the front-end attack surface.
With proper authorization, further probing can be performed on discovered paths, and results are uniformly organized into scan reports.
Input Leak Prevention
Real-time detection of input or pasted content in chat boxes, AI dialog boxes, office systems, and regular web forms to identify potential sensitive information before sending.
Supports:
- Input and Send Monitoring: Reminders when typing pauses, with re-detection upon clicking send
- Clipboard Paste Monitoring: Detect sensitive content before pasting, can be enabled separately
- Alert or Block: Depending on rule settings, either alert only or directly block sending
- Detection Intensity Settings: Supports light alert, standard, and strong block modes
- Site Whitelist and Do Not Disturb: Reduce unnecessary prompts for trusted sites
Adapted for common AI and office scenarios, while covering most regular web input fields. Login pages typically do not participate in input monitoring.
Phishing Email Identification
Fully offline analysis of opened webmail, downloaded EML files, or manually imported local EML emails.
Can assist in checking:
- Sender identity and email authentication information
- Displayed links and actual redirect addresses
- Spoofed domains and social engineering tactics
- Email attachments, MIME structure, and delivery chain
- Tracking pixels, suspicious links, and other risk indicators
Analysis results provide a risk score, main basis, link and attachment information, IOC classification, and handling suggestions.
The email risk score is for auxiliary analysis only and does not represent the probability of malice. Webmail is limited by page structure; if more complete results are needed, it is recommended to prioritize importing the original EML file.
Rule Center
Built-in approximately 130 sensitive information detection rules, and supports:
- Enable or disable rules by category
- Custom detection rules
- Set alerts or blocks individually
- Import and export rule configurations
- Adjust detection scope based on team or business scenarios
Report Export
Scan and analysis results can be exported as:
- HTML
- Markdown
- JSON
Facilitating security self-inspection, issue archiving, internal reporting, and development remediation follow-up.
Local First and Privacy Protection
Hx0 DataGuard adopts a local-first processing approach:
- Page and script scanning are executed locally
- Input content is detected locally in the browser
- Email body and attachment information are analyzed locally
- Scan records and reports are saved on the current device by default
- No cloud AI is called to analyze emails
- No uploading of page content or email body
No account registration required to start using.
Applicable Scenarios
- Check sensitive information before pasting logs, configurations, or business data into AI
- Check if pages expose keys, interfaces, and test data before development joint debugging or launch
- Map API paths in web pages and scripts within the scope of authorization
- Extract risk evidence offline when receiving suspicious emails
- Export scan results and hand them over to development, operations, or security teams for review
Usage Instructions
This tool is only for authorized testing, security self-inspection, and auxiliary analysis, and cannot replace formal penetration testing, code auditing, email security gateways, or compliance certification.
Scanning and analysis results may contain false positives or false negatives. Please conduct manual review combined with business context, raw data, and official channels.
New users can get 1-day VIP experience upon first installation to fully experience all features.
Rated 5 by 1 reviewer
Permissions and data
Required permissions:
- Download files and read and modify the browser’s download history
- Access browser tabs
- Access your data for all websites
Optional permissions:
- Access your data for all websites
Data collection:
- The developer says this extension doesn't require data collection.
Optional data collection, according to the developer:
- Technical and interaction data
More information
- Add-on Links
- Version
- 1.0.7
- Size
- 710.01 KB
- Last updated
- 2 months ago (Jul 27, 2026)
- Related Categories
- License
- Mozilla Public License 2.0
- Privacy Policy
- Read the privacy policy for this add-on
- Version History
- Add to collection