Is Yodeck Web Player Extension safe?
Medium risk
Yodeck's official digital signage companion extension that removes CSP and X-Frame-Options headers globally for all URLs, injects scripts into all open tabs, and transmits screenshots to remote URLs supplied by the Yodeck web player. The broad scope of header stripping and script injection extends beyond yodeck.com domains, and there is a residual development artifact pointing to localhost:8000 for cookie configuration.
45Risk
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.