Is Google Docs Offline safe?
Google Docs Offline exposes extension presence, version, and permissions to any website via a web-accessible script.
The extension declares page_embed_script.js as web-accessible to all URLs. Any page can load this script to read window globals that reveal the extension is installed, its version number, and its full permissions list. Separately, the extension sends JS error reports and opt-in status (sampled at 1%) to Google's own docs.google.com backend.
Who publishes itGoogle Ireland, Ltd. - 72 other listings from the same operator, none carrying a finding
Google Ireland, Ltd. - 72 other listings from the same operator, none carrying a finding
What this publisher told the store about itself, and the other listings that told it the same thing.
Same store account
3 other listings published from this account, 7.3M+ users between them, none of them carrying a finding.
Same operator - 69 listings
Published under a different store account, but sharing the registered address, contact or declared legal entity this one gave the store.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Where it sends data
Destinations our analysis observed Google Docs Offline contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.
- docs.google.com
Google Docs Offline sends data to docs.google.com. 20 other extensions we have analysed send data here.