Is Headline Studio by CoSchedule safe?
Headline Studio by CoSchedule accepts postMessage commands from any ngrok.io tunnel, allowing manipulation of CMS title fields and stored credentials.
The extension injects content scripts on all pages to provide a headline analysis sidebar. Its postMessage handlers in hub.bundle.js and spoke.bundle.js accept messages from any origin matching 'ngrok.io' or '.ngrok.io', rather than restricting to CoSchedule's own domains. Through the SAVE_AUTH_STATE message type, any ngrok tunnel can overwrite the CoSchedule userId and authToken stored in chrome.storage.local; through UPDATE_STATE, it can rewrite headline text fields on CMS editing pages.
Part of this rating comes from analysis signals we haven't published as detailed findings yet.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.