Is EndNote Click safe?

Low risk

EndNote Click validates postMessage origins via substring match, allowing spoofed domains to relay commands to its PDF and export handlers.

The extension's content script on kopernio.com and click.endnote.com listens for postMessages and validates the sender's origin using a substring match rather than strict equality. An origin containing 'https://click.endnote.com' as a substring (e.g. 'https://click.endnote.com.attacker.com') passes this check and can relay messages to background handlers including BgUploadPdf, BgSmartRisExport, and BgDownloadPdf. Exploitation requires the user to visit a crafted page while the extension is active.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

EndNote Clickv3.5.0Chrome Web Store
20Risk
Who publishes it

Clarivate - 1 other listing from the same operator, none carrying a finding

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
EndNote Click
Declared legal entity
Clarivate
Registered address
70 Saint Mary Axe, London EC3A8BE, GB
Registered contact
EndNote Click

Same operator - 1 listing

Published under a different store account, but sharing the registered address, contact or declared legal entity this one gave the store.

Shared hosts - 1 hostname

Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.

gateway.webofknowledge.com
Also called by 5 other listings, including HKUL Search Assistant

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

What it can do

Permissions this extension asks for, as declared in version 3.5.0. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Read and change your data on every site you visit

    <all_urls>

  • Store data in your browser

    storage

  • See every page you navigate to, as you navigate to it

    webNavigation

  • Block and redirect the requests your browser makes

    declarativeNetRequest

declarativeNetRequestWithHostAccess
Updated 30 September 2026fjgncogppolhfdpijihbpfmeohpaadpc