Permanent clipboardSecurity Analysis

Chromev3.2.1MV3April 3, 2026 at 10:17 PM
Potentially unsafe

This extension shows concerning patterns that may indicate risky behavior. Proceed with caution.

6.2HIGH
6.2 HIGHRaw: 7.8

This extension shows significant risk signals. Review the findings below carefully before installing or continuing to use it.

Based on 12 permissions including high-risk ones, 33 code findings, 3 dangerous combinations.

Trust Signals(4.0/10)

Users
60K
Rating
4.6(285 reviews)
Status
Featured

Dangerous Combinations(3)

MEDIUMTab tracking API + external communication

Extension uses tab tracking APIs (onUpdated/query) and communicates with external servers — potential browsing surveillance.

tabs+tabs API usage + external network
CRITICALClipboard read + external communication

Extension reads clipboard and communicates externally — potential credential or crypto address theft.

clipboardRead+external network request
CRITICALAll-sites access + keyboard capture

Extension has access to all sites and captures keyboard input — behavior consistent with a keylogger.

<all_urls>+keylogger_pattern
Permissions
7.5/10
Code
10.0/10
Combinations
10.0/10
Manifest/CSP
0.6/10

Permissions(12 analyzed)

Code Findings(16 patterns, 33 total)

Content Security Policy

CSP Present(1 issue)
LOW
object-srcobject-src not restricted

object-src is not set to 'none'. Plugins like Flash can be embedded, which may allow code execution.

Manifest Analysis(0 findings)

Resolved from __MSG_* i18n placeholders:

Name: Permanent clipboard

Description: Keep your most-used replies, templates, and notes one click away. Insert anywhere from the popup or right-click menu.

No manifest-level concerns found.

External Domains(9)

${abartosz.imbit.lybugs.webkit.orglocalhostmui.compermanent-clipboard-backend-296881762649.us-central1.run.appsecuretoken.google.comstackoverflow.com

Indicators of Compromise

151 indicators of compromise found

File Statistics

59
Total Files
5
JS Files
8.9 MB
Total Size

Other Scanned Extensions