Chrome Monitor is a browser extension that checks the pages your users visit as they browse. Each new page is submitted to Blue Lantern Security's URL Threat Analyzer, which loads it in an isolated browser and reports what it observed: login screens, redirects, downloads, popups, suspicious network requests, and domain age. Results appear in the extension popup and in your Monitoring Hub, with no change to how anyone works.
Access: the extension is free to install from the Chrome Web Store and works on Chrome and Chromium-based browsers such as Edge and Brave. Continuous scanning requires a Seat License at $15 per monitored user per month. Support for other browsers is in progress. See current pricing.
Phishing pages, fake CAPTCHAs, and malicious downloads reach people through the browser, often from a link in an email or a text message that looked fine. Browser monitoring checks the destination itself, at the moment someone arrives, without asking them to paste a link anywhere first.
How does Chrome Monitor work?
- On every top-level navigation, the extension decides whether the URL is worth scanning. It skips non-web schemes, local and private hosts, the Blue Lantern Security site, search engine result pages (on by default), and any hosts on your own skip list.
- New URLs are submitted to the URL Threat Analyzer. Results are cached per URL, so revisiting the same page does not trigger another scan. The cache lifetime is configurable.
- The toolbar badge shows status: scanning, detonated, or error. Click it to see the raw findings for the current tab.
- Every run lands in the Monitoring Hub, attributed to the monitored user, alongside email, file, and device scans.
There is no risk score. The popup shows the engine's findings as they are, which reflects Blue Lantern Security's approach to risk scoring.
What does the URL Threat Analyzer look for?
| Finding | Why it matters |
|---|---|
| Login-screen detection | An unexpected destination asking for credentials is the core of most phishing |
| Redirect hops and final destination | Shortened or disguised links resolve to a destination you can evaluate |
| Automatic downloads and popups | The page triggers something the visitor did not ask for |
| Suspicious network requests, links, and cookie counts | The page contacts infrastructure that deserves investigation |
| Certificate checks | Certificate problems on the destination. A valid certificate alone does not establish trust |
| Domain age, registrar, and typosquatting patterns | Newly registered or lookalike domains are common in phishing |
| Back-button hijacking | The page interferes with normal navigation. See back-button hijacking |
| Clipboard behavior associated with ClickFix | The page tries to make the visitor copy and run a command. See the ClickFix investigation |
The same engine powers the on-demand Check a Link tool, so a page checked by the extension and a link pasted by hand produce the same kind of report.
How do I deploy it to a team?
- Seat the user. Assign a Seat License to the person on your Organization page.
- Create a Web Extension monitor key in the Monitoring Hub, with the seat assignment set to that user's email. Monitor keys are scoped to URL analysis runs only; they cannot read any other account data.
- Install the extension from the Chrome Web Store on the user's browser.
- Paste the key in the extension's Options page and click Test key. The test confirms authentication without running a scan.
Settings in the Options page let you turn automatic detonation on or off, skip search engines, set the cache lifetime, maintain a never-scan host list, and clear the cache. Pair the monitor with an alert rule on Malicious verdicts for URL runs so a bad page reaches you by email or SIEM without watching the dashboard.
What does the extension send, and where?
- The URL being checked and your monitor key go to api.bluelanternsecurity.io, and nowhere else. The extension does not send page contents.
- The key is encrypted at rest inside the browser with AES-GCM. Only ciphertext is stored, and the encryption key is non-extractable. Treat the monitor key like a password regardless.
- A local guard caps requests at 500 per 10 minutes, staying under the account limit.
- The destination receives a visit from the analysis browser. Isolation keeps that visit out of the user's browser; it does not make it invisible to the website. Add internal or sensitive hosts to the skip list if that matters.
- Revoke the key from the Monitoring Hub and the extension stops immediately.
Reports are retained for one week and are accessible only to your account. See the Privacy Policy.
Common questions
Does Chrome Monitor block pages?
No. It observes and reports. The badge and popup show findings, and the Monitoring Hub and alert rules tell you what was flagged. Blocking decisions stay with you and your existing controls.
Will it slow down browsing?
The analysis runs on Blue Lantern Security's infrastructure, not in the user's browser, and the page loads normally while the scan runs. Cached results mean repeat visits cost nothing.
Which browsers are supported?
Chrome and Chromium-based browsers such as Microsoft Edge and Brave. Support for other browsers is in progress.
Does a clean result mean the page is safe?
No. It means the analysis did not observe suspicious behavior within its coverage and conditions. A site can change after the check, serve different content to different visitors, or require an interaction the analysis does not perform.
Can I scan a link before anyone visits it?
Yes. Paste it into Check a Link, which uses the same engine and is free for 30 runs a day. The guide to investigating a suspicious link without opening it covers the workflow.
Can I check an extension I already installed?
Chrome Monitor checks the pages you visit, not the extensions in your browser. To look for known-bad patterns in an extension's files, upload them to the Static Malware Analyzer through Check a File. Review the extension's permissions and publisher on Chrome's extensions page as well.
Related guides
- Is This Link Safe? Check a suspicious URL
- Best URL scanners and link checkers
- ClickFix: the fake CAPTCHA that asks you to infect yourself
- Suspicious text links are getting harder to spot
- Monitor devices