Is Evernote Web Clipper safe?
Evernote Web Clipper accepts postMessage commands from any web page without verifying the sender's origin.
The extension's content script registers a message listener on every http, https, and ftp page it runs on. Any web page can send a postMessage with the value 'invokeClipper' to open the Evernote clipper overlay, or 'closeClipper' to dismiss it, without any origin check. No user data is transmitted to third parties as part of this behavior.
Part of this rating comes from analysis signals we haven't published as detailed findings yet.
Who publishes itEvernote Corporation - 1 other listing from the same operator, none carrying a finding
Evernote Corporation - 1 other listing from the same operator, none carrying a finding
What this publisher told the store about itself, and the other listings that told it the same thing.
Same store account
1 other listing published from this account, 1.0M+ users between them, none of them carrying a finding.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
What it can do
Permissions this extension asks for, as declared in version 7.40.0. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to. The current listed version is 7.41.1, which we have not unpacked yet.
Read and change your data on every site you visit
<all_urls>
Act on the current tab, but only after you click the extension
activeTab
See the address and title of every tab you have open
tabs
Read and change cookies, including the ones that keep you signed in
cookies
Add items to the right-click menu
contextMenus
Store data in your browser
storage
Show you desktop notifications
notifications
Run its own code inside the pages you visit
scripting