Is Enpass Password Manager safe?

Clean risk

Enpass Password Manager captures form credentials and WebAuthn calls on all pages and forwards them to the local Enpass desktop app via WebSocket.

Content scripts running on every HTTP and HTTPS page intercept username, email, and password values at form submission and route them through the background script to the Enpass desktop app over a local WebSocket connection (ws://127.0.0.1:10391–10410). The extension also overrides the browser's native WebAuthn API so that passkey creation and authentication requests are proxied through the same local channel to the desktop app rather than handled by the browser directly. No data is sent to external servers; all communication stays on the local machine between the extension and the installed Enpass application.

enpass.iov6.11.17Chrome Web Store
0Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Updated 17 September 2026kmcfomidfpdkfieipokbalgegidffkal