Is Editor for Docs, Sheets & Slides safe?
Editor for Docs, Sheets & Slides is medium risk. Editor for Docs, Sheets & Slides adds click handlers to Google Docs, Sheets, Slides, and Drive links on every website. Clicking one opens an HTTP google-edit.com pageLink URL with the clicked file URL in the link parameter.
Who publishes itkonimatoan - 1 other listing from the same operator, 1 of them carrying a finding
konimatoan - 1 other listing from the same operator, 1 of them carrying a finding
What this publisher told the store about itself, and the other listings that told it the same thing.
Same store account
1 other listing published from this account, 100k+ users between them. 1 of them carries a finding.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
Google file links open through google-edit.com
Editor for Docs, Sheets & Slides adds click handlers to Google Docs, Sheets, Slides, and Drive links on every website.
Clicking one opens an HTTP google-edit.com pageLink URL with the clicked file URL in the link parameter.
You click a Google file link on any webpage.
The code matches Docs, Sheets, Slides, and Drive links.
The extension prevents the normal click and opens the link through google-edit.com.
The clicked Google file URL is encoded into the outbound pageLink URL.
| Field | Value | Why it matters | |
|---|---|---|---|
Clicked Google file URL | https://docs.google.com/document/d/1S4mJt9Bqv6P2rHc8YxL0nZeUaKf3DiG7Qw5p/edit (illustrative) | This can identify the specific document, spreadsheet, presentation, or Drive item you chose to open. | |
Receiving site | google-edit.com | The clicked file link is routed through this external site before the popup opens. | |
Link categories | docs.google.com, sheets.google.com, slides.google.com, drive.google.com | The extension applies this behavior to Google document, spreadsheet, presentation, and Drive links. |
The shipped code that tags Google links and opens the popup
prepareSingleLink(e) {
e.addEventListener("click", this.handleDocLink), e.classList.add("openInApp-mtz")
}handleDocLink(e) {
let t;
if (e.preventDefault(), e.target.href) t = `http://google-edit.com/pageLink/?link=${encodeURIComponent(e.target.href)}`;
else {
const n = e.target.closest(".openInApp-mtz").href;
t = `http://google-edit.com/pageLink/?link=${encodeURIComponent(n)}`
}
chrome.runtime.sendMessage({
action: "create-window-popup",
data: {
url: t,
isPrepared: !0
}
})
}checkLinkHref(e) {
const t = /docs.google.com/.test(e),
n = /drive.google.com/.test(e),
i = /sheets.google.com/.test(e),
s = /slides.google.com/.test(e);
return !!(t || n || i || s)
}y = async ({
url: e,
isPrepared: t
}) => {
const {
windows: i,
currentLayout: o
} = await a.service.get(), d = null == i ? void 0 : i.findIndex((({
url: t
}) => t === e));
if (-1 !== d) return void await chrome.windows.update(i[d].id, {
focused: !0
});
const n = t ? e : `http://google-edit.com/pageLink/?link=${encodeURIComponent(e)}`,
s = await w((null == i ? void 0 : i.length) ?? 0, o),
r = await chrome.windows.create({
type: "popup",
url: n,
...s
});
return await a.service.set({
windows: [...i, {
id: r.id,
url: e
}]
}), e
}- google-edit.com
Receives the pageLink navigation whose link parameter contains the clicked Google file URL.
What it can do
Permissions this extension asks for, as declared in version 1.1.10. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to. The current listed version is unknown, which we have not unpacked yet.
Store data in your browser
storage
Read information about your displays
system.display