Is Keywords Everywhere - Keyword Tool safe?

Medium risk

Keywords Everywhere exposes the user's API key to any website via a postMessage handler with no origin check.

The extension injects a bridge script (bridge.js) into every page that listens for postMessage commands without validating the sender's origin. Any website can send the xtkt.getAPIparams command to this handler and receive the user's Keywords Everywhere API key in the response. The key is returned directly from the extension's background service and posted back to the page via window.postMessage with a wildcard target.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

Axeman Technology Solutions LLPv11.55Chrome Web Store
45Risk
Who publishes it

Axeman Technology Solutions LLP - 3 other listings from the same operator, none carrying a finding

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
Axeman Technology Solutions LLP
Declared legal entity
Axeman Technology Solutions LLP
Registered address
502 B Anisha Apartments, Yari Road, Versova, Mumbai, Maharashtra 400061, IN
Registered contact
Akash Mansukhani

Same operator - 3 listings

Published under a different store account, but sharing the registered address, contact or declared legal entity this one gave the store.

Shared hosts - 3 hostnames

Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.

app.keywordkeg.com
Also called by 1 other listing: Keywords Everywhere
links.keywordseverywhere.com
Also called by 1 other listing: Keywords Everywhere
api.keywordseverywhere.com
Also called by 2 other listings, including Keywords Everywhere

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

What it can do

Permissions this extension asks for, as declared in version 11.55. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Read and change your data on every site you visit

    http://*/*

  • Read and change your data on every secure site you visit

    https://*/*

  • Store data in your browser

    storage

  • Act on the current tab, but only after you click the extension

    activeTab

  • Add items to the right-click menu

    contextMenus

  • Run its own code inside the pages you visit

    scripting

Updated 30 September 2026hbapdpeemoojbophdfndmlgdhppljgmp