This extension shows concerning patterns that may indicate risky behavior. Proceed with caution.
This extension shows significant risk signals. Review the findings below carefully before installing or continuing to use it.
Based on 9 permissions including high-risk ones, 193 code findings, 1 dangerous combination.
Extension has access to all sites and captures keyboard input — behavior consistent with a keylogger.
2 libraries detected
This extension does not define a Content Security Policy. A CSP helps prevent XSS and code injection attacks.
JavaScript files are accessible to ALL websites. Any page can load and interact with these scripts, enabling web→extension attacks.
Web-accessible resources use <all_urls> or wildcard patterns, exposing resources to every website.
Content script matches <all_urls>, executing on every website the user visits.
Content script runs at document_start in ALL frames on ALL URLs. This gives the extension deep access to every page load, including iframes.
13850 indicators of compromise found