Is GateKeeper Password Manager safe?
GateKeeper Password Manager communicates with a localhost credential API over HTTP when HTTPS is unavailable, sending session tokens in the URL.
The extension connects to a native helper running on localhost port 12190 to read, create, and decrypt credentials. If the HTTPS probe fails, all subsequent calls fall back to plain HTTP with the session token appended as a query parameter. This exposes the token to any local process that can observe loopback traffic.
Who publishes itUntethered Labs, Inc. - no other listings under this identity
Untethered Labs, Inc. - no other listings under this identity
What this publisher told the store about itself, and the other listings that told it the same thing.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Where it sends data
Destinations our analysis observed GateKeeper contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.
- localhost:12190
GateKeeper sends data to localhost:12190. Named as a recipient in this extension's own analysis.