Is Elfster's Wish It! safe?
Elfster's Wish It! prefills its wishlist form from a browser message sent by any web page, with no check on who sent it.
The extension's wishlist-add popup listens for window messages and loads the product title, price, and images straight into the add-to-wishlist form without checking which page sent the message, so any website the user visits can inject fake product data as if it had been scraped from a real page. Separately, the extension's Elfster and OurWishesRegistry sign-in flows accept a message as authentic whenever the sender's origin merely contains the text "elfster.com" or "ourwishesregistry.com" rather than matching it exactly, a check a look-alike domain can also satisfy to supply a forged sign-in session.
Part of this rating comes from analysis signals we haven't published as detailed findings yet.
Who publishes itElfster, Inc. - no other listings under this identity
Elfster, Inc. - no other listings under this identity
What this publisher told the store about itself, and the other listings that told it the same thing.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
What it can do
Permissions this extension asks for, as declared in version 4.0.20. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to. The current listed version is 4.0.23, which we have not unpacked yet.
Read and change your data on auth.elfster.com
*://auth.elfster.com/*
Read and change your data on www.elfster.com
*://www.elfster.com/*
Act on the current tab, but only after you click the extension
activeTab
Run its own code inside the pages you visit
scripting
Store data in your browser
storage