Zotero ConnectorSecurity Analysis

Chromev5.0.195MV3February 16, 2026 at 03:00 PM
9.3CRITICAL
9.3 CRITICAL

This extension shows critical risk indicators. It requests highly sensitive permissions combined with suspicious code patterns. Proceed with extreme caution.

Based on 14 permissions including high-risk ones, 117 code findings, 5 dangerous combinations.

Dangerous Combinations(5)

CRITICALCookie access + external network

Extension has cookie access and sends data to external servers — potential session token theft.

cookies+external network request
HIGHTab tracking + external communication

Extension tracks open tabs and communicates with external servers — potential browsing surveillance.

tabs+external network request
CRITICALNetwork interception + external communication

Extension intercepts network traffic and sends data externally — potential man-in-the-middle behavior.

webRequest/webRequestBlocking+external network request
CRITICALExtension management + dynamic code execution

Extension manages other extensions and executes dynamic code — behavior consistent with malware dropper.

management+eval/Function/dynamic code
CRITICALAll-sites access + keyboard capture

Extension has access to all sites and captures keyboard input — behavior consistent with a keylogger.

<all_urls>+keylogger_pattern
Permissions
10.0/10
Code
10.0/10
Combinations
10.0/10
Manifest/CSP
3.3/10

Permissions(14 analyzed)

Code Findings(26 patterns, 117 total)

Libraries(5 detected)

5 libraries detected, 1 with known vulnerabilities

Content Security Policy

CSP Present(1 issue)
LOW
object-srcobject-src not restricted

object-src is not set to 'none'. Plugins like Flash can be embedded, which may allow code execution.

Manifest Analysis(1 finding)

MEDIUM
web_accessible_resourcesJS files exposed to web pages

JavaScript files are exposed as web-accessible resources. Matched websites can load and interact with extension scripts.

External Domains(683)

*127.0.0.1611project.orgaccesso.comaccounts.google.comacorn.ioadimo.coadvisorwebsites.comairy.hostaiven.ioalboto.caalces-software.comalcme.oclc.orgall-inkl.comamaze.coamune.orgapi.zotero.orgapigee.comapp.lmpm.comapphud.comatlassian.comaurimasv.github.ioauthentick.netauthgear.comautocode.comavm.deavstack.ioaz.plbeagleboard.orgbinc.jpbinnyva.blogspot.combip.shbitbucket.orgbluebite.comboomla.comboxfuse.combrendly.rsbrondsema.netbrsmedia.combugs.chromium.orgbugzilla.mozilla.orgcanva.comcarrd.cocctld.rucenpac.net.nrcertmgr.orgcityhost.uaclickrising.comcloud.oracle.comcloud.yandex.comclovyr.iocnnic.cncnpy.gdnco-co.nlco.bncodeberg.orgcryptonomic.netcupcake.iocurv-labs.dedangerscience.comdaplie.comdappnode.iodapps.earthdarklang.comdata.semanticweb.orgdatadetect.comddns5.comdeno.comdesec.iodev.viberplay.iodeveloper.adobe.comdevelopers.google.comdig.csail.mit.edudiher.solutionsdiscord.comdns.businessdns.js.orgdns.marnet.net.mkdnstrace.prodocs.citationstyles.orgdocs.googleapis.comdocs.waffleinfo.comdomain.nida.or.krdomain.v.uadomains.fjdomains.in.netdomains.qadomena.pldomreg.merit.edudrs.uadx.doi.orgdy.fidyn.comdynv6.come4you.czeasypanel.ioecgrobotics.orgen-root.orgen.isoc.org.ilen.wikipedia.orgencore.devencounter.euseu.orgeurid.eueurobyte.ruexample.comexample.orgfaitid.orgfastvps.rufb.mefearworksmedia.co.ukfedoraproject.orgfermax.comflashdrive.iofly.ioflynn.ioforums.zotero.orgfrederik-braun.comfreemyip.comgadao.gov.gugetchannels.comgetsprink.comghost.orggiteegitee.comgithub.comgitplac.siglitch.comgoupile.frgroups.google.comgrweb.ics.forth.grgsj.bzhakaran.czhandshake.orghashbang.shhasura.iohb.cldmail.ruhome.plhoster.byhosting.url.com.twhostmaster.uaicmregistry.comieeexplore.ieee.orgincsub.cominfo.cxiopsys.euiserv.deissues.chromium.orgissuetracker.google.comit.comjelastic.comjoinforte.comjotelulu.comjprs.co.jpjprs.jpkapsi.fikevin.vanzonneveld.netking.hostkns-cnki-net-443.webvpn.fafu.edu.cnkrellian.comkuroku.ltdlab.aaronleem.co.zalehelk.comlelux.filifetime.hostinglinode.comlocalcert.devlokalized.nllubman.pllug.org.uklukanet.commayfirst.orgmchost.rumcpe.memediatech.bymedicomhealth.commicrosoft.commicrosoftedge.microsoft.comminion.systemsmintere.commozilla.commozilla.orgmynic.mymyservicemagnet.comnetangels.rungrok.comnic.acnic.aenic.arnic.banic.bjnic.bonic.com.ainic.glnic.gwnic.krdnic.lknic.mgnic.shnic.tnnic.trnodeart.ionogalliance.orgnoip.comnoop.appnorthflank.comnoticeable.ionow-dns.comnucleos.comobservablehq.comomniwe.comopencraft.comopenresearch.comopenshift.redhat.comopensource.orgovhcloud.compagefog.compagexl.compajhome.org.ukpandi.idpantheon.iopaywhirl.compcarrier.capepabo.compeplink.comperspecta.compixolino.compk5.pknic.net.pkplatform.shplatter.devport53.ioporter.runpostman.compotager.orgppcom.frprequalifyme.todayprgmr.comprotocol.aiprotonet.iopsg.compublicsuffix.orgqualifio.comqualityunit.comquip.comqutheory.ioradwebhosting.comrancher.comrawraw.githubusercontent.comreactjs.orgred-gate.comregistro.brregistro.nic.veregistry.africa.comregistry.co.caregistry.co.comregistry.gc.caregistry.gyregistry.inregistry.nic.ssregistry.prorender.comrepl.itrepo.zotero.orgresf.orgresin.ioriseup.netroar.basketballrusnames.rusae.sina.com.cnsalesforce.comsamoanic.wssandcats.ioschokokeks.orgscript.googleapis.comsearchfox.orgsellfy.comshiftcrypto.chshiftedit.netshoper.plshopware.comsie.comskygear.iosmall-tech.orgsnipplr.comsnowplowanalytics.comsonic.sosourcehut.orgstackoverflow.comstaclar.comstatic.landstdlib.comstoripress.comstorj.iosupabase.iosymfony.comsyncloud.orgtabit.cloudtaifun-software.detdra.gov.aeteam.blueteknisk.norid.notelebit.cloudthingdust.comticket.iotld.bytlon.iotools.ietf.orgtorproject.orgtuxfamily.orgtypedream.comuberspace.deulterius.iounderscorejs.orgunibl.orgunicode.orgunited-gameserver.deunitedheroes.netupli.iourown.netus.orgvercel.comvery.lvvnnic.vnvoorloper.comvoxel.shwelcome.museumwhats-th.iswhois.ati.tnwhois.nic.biwiardweb.comwikitech.wikimedia.orgwisp.ggwizardzines.comwpengine.comwww.1gb.uawww.activetrail.bizwww.adobe.comwww.afnic.frwww.airkit.comwww.akamai.comwww.altervista.orgwww.alwaysdata.comwww.amazon.comwww.amnic.netwww.anrt.mawww.appspace.comwww.appudo.comwww.aptible.comwww.aseinet.comwww.asustor.comwww.auda.org.auwww.b-data.iowww.backplane.iowww.balena.iowww.belizenic.bzwww.bermudanic.bmwww.binarylane.comwww.blackbaud.comwww.blatech.netwww.bnnic.bnwww.boutir.comwww.bplaced.netwww.bytemark.co.ukwww.c.lawww.cafjs.comwww.callidomus.comwww.cctld.ncwww.cdn77.comwww.centralnic.comwww.cgdn.org.auwww.channelisles.netwww.clerk.devwww.clever-cloud.comwww.cloud.service.gov.ukwww.cloud66.comwww.cloudaccess.netwww.cloudcontrol.comwww.cloudera.comwww.cloudflare.comwww.cloudns.netwww.cmc.iqwww.co.plwww.com.jmwww.combell.comwww.cosimo.dewww.craynic.comwww.cyon.chwww.danieldent.comwww.dansk.netwww.datawire.iowww.datto.comwww.ddnss.dewww.debian.orgwww.definima.comwww.deta.shwww.digitalocean.comwww.discourse.orgwww.dns.aowww.dns.cvwww.dns.hrwww.dns.jowww.dns.luwww.dns.plwww.dns.ptwww.dnshome.dewww.domain.gr.comwww.domain.huwww.domain.kgwww.domaine.kmwww.domains.phwww.dot.knwww.dot.mpwww.dotarai.comwww.dotmasr.egwww.draytek.comwww.dreamhost.comwww.drobo.comwww.drud.comwww.duckdns.orgwww.dyndns.comwww.dynu.comwww.eapps.comwww.eenet.eewww.enalean.comwww.encoway.dewww.ert.gov.alwww.evennode.comwww.example.comwww.fabrica.devwww.fastly.comwww.fastmail.comwww.fh-muenster.dewww.filegear.comwww.firewebkit.comwww.flap.cloudwww.flexireg.netwww.forgerock.comwww.framer.comwww.freebox.frwww.freedesktop.orgwww.frusky.dewww.funkfeuer.atwww.futureweb.atwww.gehirn.co.jpwww.gentlent.comwww.getopensocial.comwww.globehosting.comwww.gnu.orgwww.gobin.infowww.goip.dewww.google.com.www.googleapis.comwww.gov.ltwww.gov.scotwww.gov.ukwww.government.nlwww.government.pnwww.group53.comwww.gtwww.hepforge.orgwww.heroku.comwww.hkirc.hkwww.hkpc.orgwww.hoplix.comwww.hostbip.comwww.hs-heilbronn.dewww.i-registry.czwww.iana.orgwww.icann.orgwww.icilalune.comwww.ict.gov.qawww.icta.kywww.ie.uawww.iliad.itwww.in-berlin.dewww.info.atwww.info.nawww.information.aerowww.information.nyc.mnwww.interlegis.leg.brwww.iodata.comwww.ipifony.comwww.isnic.iswww.isoc.org.ilwww.isoc.sdwww.jino.ruwww.joyent.comwww.jsfromhell.comwww.kaashosting.nlwww.kakaocorp.comwww.kcce.kpwww.kenic.or.kewww.keyweb.dewww.kiwww.knightpoint.comwww.koobin.comwww.kuleuven.bewww.lcube-webhosting.dewww.leadpages.netwww.linkyard.chwww.liquidnetlimited.comwww.loginline.comwww.mazeplay.comwww.memset.comwww.messerli.chwww.metacentrum.czwww.meteor.comwww.monic.net.mowww.mos.com.npwww.mptc.gov.khwww.msk-ix.ruwww.mynic.mywww.mythic-beasts.comwww.na-nic.com.nawww.nabucasa.comwww.nearlyfreespeech.netwww.netatwork.dewww.netlify.comwww.neupeer.comwww.nic.afwww.nic.agwww.nic.bswww.nic.cdwww.nic.ciwww.nic.clwww.nic.crwww.nic.cywww.nic.dzwww.nic.ecwww.nic.eswww.nic.ghwww.nic.giwww.nic.gmwww.nic.gpwww.nic.hnwww.nic.htwww.nic.imwww.nic.iowww.nic.irwww.nic.itwww.nic.kwwww.nic.kzwww.nic.lcwww.nic.lkwww.nic.lswww.nic.lvwww.nic.lywww.nic.mcwww.nic.mswww.nic.mxwww.nic.net.gewww.nic.net.sawww.nic.net.sgwww.nic.niwww.nic.org.mtwww.nic.org.uywww.nic.pawww.nic.pewww.nic.prwww.nic.priv.atwww.nic.pswww.nic.pywww.nic.scwww.nic.slwww.nic.stwww.nic.tgwww.nic.tjwww.nic.tmwww.nic.ttwww.nic.viwww.nimbushosting.co.ukwww.nira.org.ngwww.norid.nowww.nsupdate.infowww.omnibond.comwww.one.comwww.onefoldmedia.comwww.orange.comwww.ownprovider.comwww.ox.rswww.pagefronthq.comwww.payments.service.gov.ukwww.planet-work.comwww.plesk.comwww.pnina.pswww.potraz.gov.zwwww.privacytools.iowww.pubtls.orgwww.pythonanywhere.comwww.qnap.comwww.quickbackend.comwww.rackmaze.comwww.ravpage.co.ilwww.readthedocs.orgwww.redstarconsultants.comwww.reg.uzwww.register.bgwww.registrar.mwwww.registre.tnwww.registry.co.ugwww.rethinkdb.comwww.revitalised.co.ukwww.ricta.org.rwwww.rit.eduwww.rnids.rswww.rotld.rowww.sakura.ad.jpwww.sbe.dewww.sbnic.net.sbwww.scaleway.comwww.scrysec.comwww.securepoint.dewww.seidat.comwww.sendmsg.co.ilwww.senseering.dewww.shopblocks.comwww.shopify.comwww.shopitcommerce.comwww.sidn.nlwww.sispa.org.szwww.siteleaf.comwww.skyhat.iowww.smallregistry.netwww.smoove.iowww.snowflake.comwww.snt.utwente.nlwww.sourcelair.comwww.spacekit.iowww.speedpartner.dewww.spreadshop.comwww.srcf.netwww.stackhero.iowww.storebase.iowww.sub6.comwww.svnet.org.svwww.synology.comwww.tailscale.comwww.teckids.orgwww.telnic.orgwww.thnic.co.thwww.townnews.comwww.trafficplex.dewww.transip.nlwww.twnic.netwww.twodns.dewww.typeform.comwww.tznic.or.tzwww.udr.hk.comwww.udr.org.ytwww.uem.mzwww.una.cwwww.uog.eduwww.viprinet.comwww.virtual-info.infowww.vnnic.vnwww.vultr.comwww.vunic.vuwww.wdc.comwww.webhare.comwww.webhotelier.netwww.wedeploy.comwww.winternet.nowww.wix.comwww.woltlab.comwww.woodsvalldata.co.ukwww.xnbay.comwww.xs4all.nlwww.y.net.yewww.yola.comwww.za.netwww.zadna.org.zawww.zitcom.dkwww.zotero.orgxenoncloud.netxn--gnstigbestellen-zvb.dexregexp.comyescourse.comyombo.netyunohost.orgzicta.zmzine.bgzotero.org

Indicators of Compromise

582 indicators of compromise found

File Statistics

281
Total Files
106
JS Files
3.2 MB
Total Size

Other Scanned Extensions