Skip to content

Latest commit

 

History

184 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

WardenOne

One extension. Every defence.

The all-in-one privacy, security & anti-scam extension for Chromium browsers

License: GPLv3 Manifest V3 Latest release Protections No telemetry Report a bug

⚠️ Someone is using WardenOne's name to hand out malware

Please read this if you downloaded WardenOne from anywhere other than this repository.

On 9 August 2026 I found a copy of this project republished under someone else's account, with the download links pointed at their own website. The file that site gives you is not WardenOne. It is not a browser extension at all — it is a Windows program (exbin.exe) bundled with an obfuscated script hidden in a file named certs.txt, started by a .bat file.

Antivirus vendors classify it as a trojan loader and browser credential stealer — Kaspersky as HEUR:Backdoor.Win32.StealC.gen, ESET as Lua/SmartLoader.C, and VirusTotal labels the family matanbuchus. VirusTotal report. The site distributing it is ajpc6338.github.io, and I have reported it to GitHub and Google Safe Browsing.

If you ran that file, please assume your browser data was taken. Change the passwords for anything you were signed into — email first — turn on two-factor authentication where you can, sign out of all sessions on your important accounts so stolen cookies stop working, and run a full scan with your antivirus.

WardenOne is only ever published here, at github.com/iri-dev/WardenOne. It is a browser extension. It has never been offered as an .exe, an installer, or a setup program, and it never will be. If something using this name asks you to run a program, it isn't mine.

I'm sorry this happened to anyone. It's the exact opposite of what I built this for. 💜

Welcome to WardenOne

One master switch. 80+ protections. No account, no telemetry — everything runs on your device.

WardenOne folds a whole stack of security tools into a single extension: ad and tracker blocking, anti-fingerprinting, phishing and scam defence, credential- and payment-theft protection, download scanning, IP-leak protection, media / device permission control, and memory management. Every feature is individually toggleable, and none of it phones home.

Tip

Found a bug or have an idea? Open an issue » — a guided form walks you through it in about 30 seconds. Bug reports and feature requests are always welcome.


The name

The One says it: one extension, one unified defence system, one guardian standing between you and every online threat. Instead of a dozen tools that half-cooperate, WardenOne brings every layer of protection together behind a single switch — one system, not a bag of features.

Why WardenOne

Staying safe online usually means bolting together half a dozen extensions — uBlock Origin, a fingerprint blocker, a popup blocker, a download scanner, a password-field guard, a tab suspender — and hoping they cooperate. WardenOne does all of that, plus the phishing, scam, and credential-theft protection most blockers leave out — behind one switch, with fine-grained control over every piece.

WardenOne control panel

The control panel — every protection in one place, with a live per-site security scan.

Features

Ad & content blocking — AdShield

  • General — EasyList / uBlock-style filtering (network + cosmetic + anti-adblock scriptlets).
  • YouTube — removes pre-roll and mid-roll video ads by pruning the ad schedule out of the player data; no black screen, no skip button.
  • Twitch — replaces stitched pre-roll and mid-roll ads with another local, Twitch-signed clean stream, keeps its HLS sequence continuous across the swap, and declines display/PiP ads before their creatives load. No third-party proxy is used; if Twitch offers no clean session, playback fails open instead of freezing or looping behind a cover.
  • Sponsored results & AI answers — strips sponsored Google / Brave results and their ad-click wrappers, and can hide Google / Brave AI answer panels.
  • Mark answer-scraper results (optional) — dims and labels results from sites that rank by republishing other people's answers, with a one-click Show anyway. It never removes them: ad blocking fails visibly, but a search filter that silently drops the one result you needed fails invisibly, and you'd never know it happened. The list auto-updates and can be extended without a new release.
  • Google: plain web results only (optional) — switches Google into its own "Web" mode: ten blue links, no AI overview, no enriched panels. It removes the clutter at the source rather than hiding it after paint, so nothing flashes in first and no selector can go stale when Google reshuffles its markup. Your Images, Videos and News tabs still work.

Anti-tracking & privacy

  • Hard-block trackers and analytics (Google Analytics, DoubleClick, Facebook Pixel…).
  • Do Not Track & Global Privacy Control opt-out signals.
  • Third-party cookie blocking, plus optional wipe-on-close and no persistent cookies.
  • First-party tracker catching (analytics proxied through a site's own domain), a local, on-device tracker learner, referrer trimming, and De-AMP.
  • Link hygiene — strip utm_ / fbclid params on copy, unwrap tracking redirects (l.php, /url, Reddit out).
  • Click-to-load social embeds, supercookie clearing, and auto-reject cookie banners (never clicks Accept).

Anti-fingerprinting

  • Per-session randomised canvas / WebGL / audio / hardware-hint noise.
  • Detection of canvas / audio / WebGL / font / device probing, plus blocking of known fingerprinting scripts.

Script control — Script Shield

  • Block scripts everywhere (lockdown) or per-site, NoScript-style, with a trusted-site allowlist and a fingerprinting-script filter.

Popups, redirects & overlays

  • Block forced popups / popunders (timer-based window.open, hidden ad tabs).
  • Strict ad-popup shield, on by default, for "download + ad tab" installer tricks without hijacking player controls or sign-ins.
  • Remove in-page overlays — fake notification bells, subscribe walls, adblock nags, cookie / continue walls, download gates — with an Undo chip.
  • Auto-skip download-ad gates, block gestureless redirects, detect CPA redirect chains, and stop <meta refresh> bounces.

Phishing & scam protection

  • Look-alike / homograph blocking — full-screen block on g00gle-style typos, wrong-TLD, and homographs.
  • Login-page age check — warns when a password form sits on a brand-new domain (RDAP, no API key).
  • Behavioral risk detection — flags brand-new sites that phone home or act like scams even when they're on no blocklist.
  • ClickFix command-paste guard, a tech-support-scam / browser-locker neutraliser, fake-update lure detection, a script-drift guard, risky-site mode, anti-clickjacking, and warnings on redirecting & shortened links.

Family & content safety

  • Adult-site guard — an optional "18+ — are you sure?" screen on unwanted adult-site arrivals, so a mistyped address or a sneaky redirect never drops you (or a kid on the family computer) straight onto explicit content.
  • Catches the unlisted ones — a heuristic flags adult sites that aren't on any blocklist yet, not just the known names.
  • Adult redirect blocking — stops gestureless hops that fling you to an 18+ page with no click, backed by an adult-warning list that auto-updates daily.
  • Force SafeSearch (optional, off by default) — locks the Google, Bing, DuckDuckGo, Brave Search and Yahoo search engines into SafeSearch, and YouTube into Restricted Mode. The adult gate only fires when you arrive somewhere, and explicit images and video render inside the results page itself, where there's no arrival to catch — this closes that gap. Off by default because it changes what search will show you.

Credential, payment & clipboard protection

  • Form-skimmer / Magecart detection — blocks scripts reading password / card fields and exfiltrating them off-site.
  • Payment-card guard on scammy, brand-new, or look-alike checkouts.
  • Session-token protection, continuous token watch, keylogger detection, and honeytoken decoys.
  • Clipboard-hijack protection (crypto-address swap), paste protection (password / API key / seed phrase), an OAuth-grant guard, and Have I Been Pwned breach checks.

Download protection — Download Shield

  • No-account A–F download grading from the URL, source, filename, file type, Chrome signals, and blocklists — known-bad blocked outright, risky ones held for a review you can cancel.
  • Optional domain-age checks (RDAP / WhoisXML) and a VirusTotal URL scanner.

Network & IP protection

  • WebRTC IP-leak guard, IP-grabber beacon blocking, logger-domain warnings (Grabify, IPLogger), Force HTTPS, and bad-certificate blocking.
  • Intranet / router protection — public web pages can't silently reach your local admin panels (router, NAS, dev servers), shutting down DNS-rebinding-style local-network attacks.

Media & device control

  • Media Shield — block camera, microphone, screen-capture, and hidden background media.
  • Location-request blocking, a permission-chain guard, and a per-site permission scanner (allow / block / ask for camera, mic, notifications, location).

Site data, session & extension control

  • Forget Me & Logins — one toggle for "never let sites remember me": wipe a site's cookies and storage when you leave, so nothing keeps you logged in or recognises you next visit (allowlisted sites are kept), plus a one-click "forget this site now".
  • Emergency Logout, a Privacy Cleaner (selective wipe), a live per-site Session Security grade (A–F: connection, JWT exposure, token storage, cookie security), and an extension watchdog that flags installed extensions gaining risky permissions in an update.
  • Startup security check — on browser launch, scans restored tabs and recently-installed extensions for risky signs.
  • Settings backup — export every toggle to a file and import it back on a reinstall or a new machine. Nothing syncs to a server and there's no account, so this is the only way you don't rebuild 140-odd settings by hand. API keys are never written to the file, and an imported file can't inject one.
  • On-demand site tools — check a domain's age (RDAP), look it up against Have I Been Pwned, scan where a site stores login tokens, or review every installed extension's permissions.

Cryptojacking

  • Block drive-by mining — mining-as-a-service scripts (the ones that quietly spend your CPU and battery on someone else's coins) are blocked outright, and pages are stopped from opening a stratum WebSocket to a mining pool.
  • Mining pools themselves stay reachable if you go there — they're only blocked as a third-party connection, so a site can't mine through one behind your back while your own pool dashboard keeps working.
  • Deep detection (optional, off by default) — for the case blocking can't see: a miner a site hosts on its own origin. Reads the code of the background workers a page starts and stops the ones running mining routines, including the replacements a miner spawns when you kill it. Only the mining worker is stopped, so the rest of the site keeps working, and an allowlisted site is reported but never touched. It won't spot a miner with its code obfuscated away.
  • Honest scope: heavy CPU use on its own is not treated as mining. A video export, a WASM build, and a miner all peg your cores identically, so WardenOne only says "cryptominer" when it can actually see mining code.

Threat blocklist

  • Hard-block known malicious sites from vetted threat feeds, auto-updated daily (tens of thousands of domains, millions across the feeds).

Performance

  • Memory Shield — sleep inactive tabs (Gentle → Balanced → Aggressive → Emergency) with never-sleep rules for pinned / audio / form / login tabs; free RAM on demand, find duplicate or zombie tabs.
  • Resource Saver — block autoplay media, throttle background tabs, lazy-load images, and stop prefetch / preload.

Comfort & extras

  • EyeShield — a per-site display tuner with Normal / Light / Dark / Ultra (OLED-black) modes, plus brightness, contrast, saturation, warmth, and grayscale sliders, remembered per site.
  • Twitch Local Rewind — scrub back through a live stream, or jump straight to the moment you joined.
  • Update Guardian — nudges you when your browser is behind on security patches.

More than a settings page

WardenOne ships real interfaces, not just toggles.

Local Activity Center
Local Activity Center
A private, on-device log of everything blocked, learned, and allowed. Nothing leaves your machine.
Dangerous Site Blocked
On-page block screens
Clear interstitials for dangerous sites, unexpected redirects, and bad certificates — each explaining why, with no quiet bypass.
Network / DNS guide
Network / DNS guide
Extend protection past the browser to every device on your network.
Permissions, explained
Permissions, explained
A plain-English ledger of every permission WardenOne uses and where its reach stops.

Set it up your way

On first run, pick Recommended (the safe default) or Maximum privacy — which also turns on the hardened set: active anti-fingerprinting, first-party tracker blocking, breach & password checks, clipboard guard, and referrer / AMP trimming. Choose Normal notifications or Silent mode, where protection stays fully on but popups and badges stay hidden. Every one of the 80+ features is individually toggleable, and any site can be allowlisted from the popup in one click.

Install

From a release (no clone needed):

  1. Download the latest WardenOne-vX.Y.Z.zip from the current release and unzip it.
  2. Open chrome://extensions and enable Developer mode (top-right).
  3. Click Load unpacked and select the folder you just unzipped — the one with manifest.json directly inside it.

From source: clone this repository and load the project folder the same way.

Works in Chrome, Brave, Edge, and other Chromium browsers.

Privacy

Everything runs locally in your browser. There's no remote proxy, no account, and no telemetry — your browsing is never sent to a server we run. The optional lookups you switch on yourself (download domain age, VirusTotal, breach checks) send only the minimum: a source domain, a link you paste, or a hashed query — never your full history. Login tokens and passwords are never stored or transmitted.

How I work

What's here is the version I'm confident enough to put in front of people — finished, checked, and running on real sites.

My local copy is where the mess lives: new ideas, half-built features, betas, and things I'm still trying to break. It's often further along in raw code, but that doesn't make it the better version. It's a workshop, not a release. This gets worked on constantly, and it isn't going anywhere.

I build in VS Code with the extension loaded, and I'll happily sit with one thing for hours — edit, reload, hard-refresh, watch what the page actually does, go again. Almost none of that is worth a commit on its own, so I push once something is finished and I'm actually sure about it. The history goes quiet and then several commits land at once, which is usually just one long session finally ending. Probably more of those at 2am than is strictly sensible.

Everything goes through node tools/check-maintainability.js first. And when something turns out to be wrong on a real site, I'd rather leave the revert sitting in the history than tidy it away.

Feedback & bug reports

Found a site WardenOne breaks, or have an idea? Open an issue — there are quick templates for bug reports and feature requests. For bugs, the site URL and which toggle is involved are the most useful details.

Official source

Website: iri-dev.github.io/WardenOne — the official site for the project.

WardenOne is published only from github.com/iri-dev/WardenOne. Releases come from that repository and nowhere else. It is a browser extension — it is never an .exe, an installer or a setup program. See the notice at the top of this page: a copy of this project has been used to distribute malware under its name. Releases come from that repository's Releases page and nowhere else.

If you were sent here from another site, or offered a WardenOne download hosted somewhere other than the link above, that build was not produced by this project. WardenOne holds broad permissions by design — every one of them explained in permissions.html — and a copy from an unverified source has all of them and none of the accountability. Check where your download came from before installing it.

Copyright (C) 2026 iri. Licensed under the GNU GPL v3 or later; see LICENSE, NOTICE and CREDITS.md. Redistributing a modified copy is welcome — GPLv3 section 5(a) asks that you mark it as changed and keep the notices intact.

License

GNU General Public License v3 — see LICENSE.

WardenOne builds on the open-source blocking community. Sources are credited in CREDITS.md: AdGuard (YouTube rules), EasyList / EasyPrivacy (tracker rules), and TwitchAdSolutions, scamorza/TwitchAdBlock, GosuDRM/TTV-AB, and uBlock Origin uAssets (Twitch blocking).

About

One extension. Every defence. - the all-in-one privacy, security & anti-scam extension for Chromium browsers (MV3). 80+ on-device protections: ad & tracker blocking, anti-fingerprinting, phishing/scam & credential-theft defence, download scanning, IP-leak protection, plus YouTube & Twitch tools. No account, no telemetry. GPLv3.

Topics

Resources

Stars

7 stars

Watchers

4 watching

Forks

Releases

Packages

Contributors

Languages