OpenAI 2026 hackathon

PhishLens

PhishLens stops phishing before submission, with transparent evidence users can understand and trust.

Team of 3 · 0 likes · 0 comments

Archive position — measured, not model output

0 likes on Devpost

2,264 of the 7,856 archived projects have more likes, and 5,592 share exactly 0 — so this project's #5,927 place in the like-ranked listing is a tie-break inside that group, not a ranking.

Projects (log scale)

1
10
100
1k
10k
05,592
11,758
2285
3–4132
5–975
10+14

Likes on Devpost. ▲ marks this project's group.

Show the figures
LikesProjectsShare of archive
05,59271.2%
11,75822.4%
22853.6%
3–41321.7%
5–9751.0%
10+140.2%
Devpost like counts for all 7,856 archived projects, captured when this archive was built.

Executive Summary

What the company appears to be

PhishLens is a browser extension built as part of a hackathon project, designed to detect phishing and malware in real time. It evaluates URLs and web forms for signs of phishing, provides a transparent risk score, and explains the evidence behind it. The tool aims to make phishing protection understandable and actionable.

What changed

The project is a self-reported prototype developed for a hackathon. No commercial product or customer base exists beyond its development phase. There is no evidence of prior traction, revenue, or market adoption.

Single most important open question

Is there any evidence that PhishLens has moved beyond the prototype stage, or whether it will be released publicly as a browser extension?

Back to contents

What The Product Actually Is

The description states:

  • PhishLens is a browser extension (Manifest V3) built with TypeScript, using content scripts to extract page and form evidence.
  • It uses local threat data and optional server-side threat-intelligence indexes.
  • It includes deterministic scoring engine that produces a risk level from 0 to 100.
  • The tool integrates with AWS backend, and uses Codex powered by GPT-5.6 for development assistance.
  • It can interrupt risky form submissions before credentials are sent, and mark suspicious links.

Inference The product is a proof-of-concept browser extension built in a hackathon setting, with no commercial deployment or user base yet.

Back to contents

Positioning & Claim Evolution

The description states:

  • PhishLens aims to make phishing protection understandable, transparent, and actionable.
  • It provides transparent evidence users can understand and trust, distinguishing it from tools that simply warn without explanation.
  • The tool is designed to intervene before submission, preventing credential leaks.

Inference The positioning is centered on explainability and user trust, with a focus on prevention over detection. It does not claim to be a full-fledged security platform or enterprise-grade solution.

Back to contents

Target Customer & ICP

The description states:

  • PhishLens targets both everyday users and developers, as phishing affects both groups.
  • It is built for cybersecurity engineering students, suggesting an early-stage, educational or experimental audience.

Inference There is no clear ICP defined beyond a general audience of individuals concerned with cybersecurity. No specific persona or segment is identified.

Back to contents

Business Model & Pricing Evidence

The description states:

  • PhishLens is intended to be released as a free browser extension.
  • The team plans to prepare it for public release, but no pricing model or monetization strategy is described.

Inference No evidence of a business model or pricing structure exists beyond the stated intention to make it free. No revenue streams, subscriptions, or paid features are mentioned.

Back to contents

Technical & Delivery Signals

The description states:

  • Built as a Manifest V3 browser extension, using TypeScript and content scripts.
  • Uses deterministic scoring engine with local threat data and optional server-side threat intelligence.
  • Backend runs on AWS, integrates with OpenPhish, Phishtank, URLhaus, and uses Codex for development.
  • Includes graceful fallbacks when AI services are unavailable.

Inference The technical stack is consistent with a browser extension project, but no evidence of production deployment or scalability is provided.

Back to contents

Traction & Maturity Signals

The description states:

  • PhishLens was built for the OpenAI 2026 hackathon.
  • It includes proactive link protection, intervention before submission, and integration with threat-intelligence datasets.
  • The team reviewed and verified the code and security behavior.

Inference There is no evidence of user adoption, customer feedback, or product-market fit beyond the hackathon prototype. No metrics, usage data, or real-world testing are provided.

Back to contents

Competitive Context

The description states:

  • PhishLens aims to improve upon existing phishing tools that provide warnings without explaining the evidence.
  • It is designed to be privacy-conscious, unlike some competitors that may collect user data.

Inference No specific competitors are named or analyzed. The tool positions itself as a more transparent alternative, but no competitive analysis or market differentiation is detailed.

Back to contents

Key Risks & Red Flags

The description states:

  • PhishLens is a hackathon project, not yet released to the public.
  • It uses Codex powered by GPT-5.6 for development, which may raise concerns about dependency on external AI services.
  • The tool is designed to intervene before submission, which could be seen as overly aggressive or disruptive in some contexts.

Inference The lack of public release, real-world testing, and commercial viability are key risks. Dependency on AI tools for development may also raise questions about scalability and control.

Back to contents

Diligence Questions To Ask The Founders

  1. Has PhishLens been released publicly as a browser extension yet?
  2. What is the plan for monetization or long-term sustainability beyond the free model?
  3. How does the tool handle false positives, and what is its accuracy rate in real-world scenarios?
  4. Are there any plans to expand beyond the browser extension (e.g., enterprise tools, mobile support)?
  5. Has the team conducted any user testing or feedback sessions with target users?

Back to contents

Investment/Partnership Verdict

The description states:

  • PhishLens is a hackathon project and not yet commercially deployed.
  • The team intends to prepare it for public release, but no evidence of traction, revenue, or customer base exists.

Inference There is no basis for investment or partnership at this stage. The project is in an early prototype phase with no verified commercial activity or market validation.

Back to contents

Source

Submitted to the OpenAI 2026 hackathon on Devpost. Project home on DevPost.

The analysis above was generated by a language model from the project's own one-line description. It is not independent research and contains no verified traction, revenue or customer data.