Chrome Monitor
The Blue Lantern Security URL Checker is a Chrome extension that automatically checks the URLs you visit through the URL Threat Analyzer and flags suspicious pages. It is our continuous browsing protection for monitored users: no manual submissions, no workflow change.
Get it: Install from the Chrome Web Store. It also works on Chromium-based browsers such as Edge and Brave.
How It Works
- On every top-level navigation, the extension's background worker decides whether the URL is worth scanning. It skips non-web schemes, local and private hosts, the Blue Lantern site, search engine result pages (on by default), and any hosts on your custom skip-list.
- If the URL hasn't been scanned recently, it is submitted to the URL Threat Analyzer. Results are cached per URL, so revisiting the same page doesn't re-scan (or re-bill) it.
- The toolbar badge shows status only:
…scanning,✓detonated,×error. Click the icon to see the raw engine findings for the current tab: SSL checks, login screens, popups, downloads, suspicious network/link/cookie counts, redirect hops, and domain age.
There is no risk scoring — the popup shows the engine's raw findings as-is, and every run also appears in your Monitoring Hub attributed to the key's submitter.
Setup
Step 1 — Install the extension
Add it from the Chrome Web Store.
Step 2 — Create a key
Create a Web Extension monitor key from the Monitoring Hub. Monitor keys are scoped to URL analysis runs only — they cannot read any other account data.
Seat coverage: the extension requires a Seat License. Set the monitor's submitter to the exact email of a seated (monitored) member of your organization and its scans are covered by that seat.
A generic API key also works for solo use on a seat-licensed account.
Step 3 — Add the key in Options
- Click the extension icon in the Chrome toolbar, then the gear icon to open Options.
- Paste your key and click Test key. The test confirms authentication without running a scan.
Step 4 — Browse
That's it. Watch the badge as you navigate, click it for the current page's findings, and review the full history in the Monitoring Hub.
Settings
All settings live in the extension's Options page:
- Enable / disable automatic detonation.
- Skip search engines — on by default, avoids spending scans on result pages.
- Cache TTL (hours) — how long a URL's result is reused before re-detonating.
- Never scan these hosts — your own skip-list, one hostname per line.
- Clear cache — drop all cached results.
Security & Privacy
- Your key is encrypted at rest (AES-GCM) inside the browser; only ciphertext is stored in extension storage, and the encryption key is non-extractable. Treat the key like a password regardless.
- The key and scanned URLs are sent solely to
api.bluelanternsecurity.io. - A local guard caps requests at 500 per 10 minutes, staying under the account API limit.
Troubleshooting
| Issue | Solution |
|---|---|
| Badge never changes | Check that automatic detonation is enabled in Options and the key passes Test key. |
| A site isn't being scanned | It may match a skip rule (local/private host, search engine, or your skip-list) or be served from cache — lower the cache TTL or clear the cache to force a re-scan. |
| Runs are refused or not covered by a seat | The key's submitter must exactly match a seated member's email — check the monitor in the Monitoring Hub and your Organization members list. |
| 401 / 402 / 403 errors | The key may be revoked, or the account has no active Seat License — re-test the key in Options. |