Is Join safe?

Low risk

Join dispatches remote-control commands received via push notification through eval() with no signature check.

Join lets you control this device from your other devices (opening URLs, taking screenshots, reading the clipboard, sending SMS, and more) by listening for push messages from Google's GCM/FCM service and its own backend, joinjoaomgcd.appspot.com. When a push message arrives, the extension resolves the requested command class by name using eval() and runs it immediately, without verifying any signature on the message itself — it relies only on the push message having been delivered to this device's registration token.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

joaomgcdv1.9.3Chrome Web Store
20Risk
Who publishes it

KITXOO - 1 other listing from the same operator, none carrying a finding

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
joaomgcd
Declared legal entity
KITXOO
Registered address
Rua Elias Garcia, n17 4A, Amadora 2700-310, PT
Registered contact
KITXOO, UNIPESSOAL LDA

Same store account

1 other listing published from this account, 3k+ users between them, none of them carrying a finding.

Shared hosts - 4 hostnames

Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.

newplace.to.link.twitter.handles.to
Also called by 2 other listings, including FollowUp.cc for Gmail
bis.doc.gov
Also called by 4 other listings, including Fortinet Privileged Access Agent, FortiClient WebFilter
blog.codinghorror.com
Also called by 4 other listings, including FollowUp.cc for Gmail, MEGA
androidpolice.com
Also called by 5 other listings, including Toolbox for Google Play Store™, Rajiko

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

What it can do

Permissions this extension asks for, as declared in version 1.9.3. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Read and change your data on joinjoaomgcd.appspot.com

    https://joinjoaomgcd.appspot.com/

  • Read and change your data on localhost:8080

    http://localhost:8080/

  • Read and change your data on accounts.google.com

    https://accounts.google.com/o/oauth2/v2/auth/

  • Sign you in with your Google account

    identity

  • See the email address of your Google account

    identity.email

  • Keep running in the background while your browser is open

    background

  • Receive push messages from its developer's servers

    gcm

  • Store an unlimited amount of data in your browser

    unlimitedStorage

  • Show you desktop notifications

    notifications

  • See the address and title of every tab you have open

    tabs

  • Read whatever you have copied to your clipboard

    clipboardRead

  • Write to your clipboard

    clipboardWrite

  • Add items to the right-click menu

    contextMenus

  • Read your physical location

    geolocation

  • Speak text aloud

    tts

  • Run hidden pages in the background

    offscreen

Where it sends data

Destinations our analysis observed Join contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.

  • joinjoaomgcd.appspot.com

    Join sends data to joinjoaomgcd.appspot.com. No other extension we have analysed sends data here.

Updated 30 September 2026flejfacjooompmliegamfbpjjdlhokhj