Is GateKeeper Password Manager safe?

Clean risk

GateKeeper Password Manager communicates with a localhost credential API over HTTP when HTTPS is unavailable, sending session tokens in the URL.

The extension connects to a native helper running on localhost port 12190 to read, create, and decrypt credentials. If the HTTPS probe fails, all subsequent calls fall back to plain HTTP with the session token appended as a query parameter. This exposes the token to any local process that can observe loopback traffic.

Untethered Labs, Inc.v2.3.2Chrome Web Store
0Risk
Who publishes it

Untethered Labs, Inc. - no other listings under this identity

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
Untethered Labs, Inc.
Declared legal entity
Untethered Labs, Inc.
Registered address
5000 College Ave, College Park, MD 20740, US
Registered contact
Untethered Developer

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Where it sends data

Destinations our analysis observed GateKeeper contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.

  • localhost:12190

    GateKeeper sends data to localhost:12190. Named as a recipient in this extension's own analysis.

Updated 30 September 2026hpabmnfgopbnljhfamjcpmcfaehclgci