Repository navigation
Releases: amruth112/fraudurl-detector
Releases · amruth112/fraudurl-detector
Release list
fraudurl v1.0.1
Packaging release: the first version on PyPI. The code, the models and every result are the same as in 1.0.0.
- Install from PyPI:
pip install fraudurl. - PyPI project page: at release time the README is rewritten so its images and links work on pypi.org
(experiments/build_pypi_readme.py); CI checks the rendered page on every change. - Same files everywhere: PyPI gets the exact wheel and sdist attached to the GitHub release, checked
against itsSHA256SUMS, and uploads use PyPI trusted publishing (no stored passwords or tokens). - Documentation: a step-by-step guide on the website, clearer wording on what is detected (phishing
only), and the accuracy range across all four test sets (ROC-AUC 0.91–0.98). - Package metadata: keywords for PyPI search.
Install: pip install fraudurl==1.0.1, or download fraudurl_standalone.py below (Python 3.9+, nothing else needed). Verify downloads against SHA256SUMS.
fraudurl v1.0.0: fast, offline phishing URL detector
fraudurl 1.0.0: the first public release of a fast, offline phishing URL detector for Python.
Check one URL, or a whole CSV of links, for phishing. Every row gets:
- a verdict:
FRAUD,REVIEWorLEGITIMATE, - a calibrated probability,
- up to three plain-English reasons.
It never visits the websites. Website: https://amruth112.github.io/fraudurl-detector/ · Guide: check a list of URLs for phishing
Get it
- Single file: download
fraudurl_standalone.pybelow and runpython fraudurl_standalone.py urls.csv.- It needs Python 3.9+ and nothing else.
- Verify it against
SHA256SUMS.
- Package:
pip install git+https://github.com/amruth112/fraudurl-detector, then runfraudurl urls.csv.
Highlights
- URL features and model: 83 URL features, a 400-tree gradient-boosted model scored in pure Python, and Platt-calibrated probabilities.
- Tested on new domains: on domains never seen in training, ROC-AUC is 0.91–0.98 across four test sets from 2020–2026, and 0.3–1.8% of legitimate URLs are called FRAUD. When phishing is rare in your traffic, use
--base-rate. - Scale: it checked 1,000,000 URLs in 6 min 20 s on a 4-core desktop, with flat memory.
- Optional lookups: DNS and domain registration lookups for uncertain URLs (
--enrich-review). - Your own lists: allow/block lists (
--allow-list,--block-list). - Pipelines: JSON output for scripted use (
--url,--format json). - Tested on: Windows and Linux with Python 3.9–3.14, and macOS with Python 3.10–3.14.
See CHANGELOG.md, the model card and the engineering report.