Is Evernote Web Clipper safe?
Low risk
Evernote Web Clipper embeds a hardcoded HMAC secret in its bundle and accepts UI-trigger messages from any web origin.
The extension's content script listens for postMessage events on every page without validating the sender's origin, allowing any website script to open the clipper UI. The extension also hardcodes an HMAC secret key used to sign requests to its analytics endpoint, meaning anyone who inspects the bundle can forge signed analytics events. Both issues affect the extension running in its normal, installed state.
Part of this rating comes from analysis signals we haven't published as detailed findings yet.
20Risk
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Data recipients
cec.svc.evernote.com