Is Elfster's Wish It! safe?

Low risk

Elfster's Wish It! prefills its wishlist form from a browser message sent by any web page, with no check on who sent it.

The extension's wishlist-add popup listens for window messages and loads the product title, price, and images straight into the add-to-wishlist form without checking which page sent the message, so any website the user visits can inject fake product data as if it had been scraped from a real page. Separately, the extension's Elfster and OurWishesRegistry sign-in flows accept a message as authentic whenever the sender's origin merely contains the text "elfster.com" or "ourwishesregistry.com" rather than matching it exactly, a check a look-alike domain can also satisfy to supply a forged sign-in session.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

Elfsterv4.0.23Chrome Web Store
15Risk
Who publishes it

Elfster, Inc. - no other listings under this identity

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
Elfster
Declared legal entity
Elfster, Inc.
Registered address
989 Tahoe Blvd #93, Incline Village, NV 89451, US
Registered contact
Developer Account

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

What it can do

Permissions this extension asks for, as declared in version 4.0.20. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to. The current listed version is 4.0.23, which we have not unpacked yet.

  • Read and change your data on auth.elfster.com

    *://auth.elfster.com/*

  • Read and change your data on www.elfster.com

    *://www.elfster.com/*

  • Act on the current tab, but only after you click the extension

    activeTab

  • Run its own code inside the pages you visit

    scripting

  • Store data in your browser

    storage

Updated 30 September 2026fhjanlpjlfhhbhbnjohflphmfccbhmoi