Is Laitis Browser Extension safe?

Low risk

Laitis Browser Extension relays commands from a local native app to inject scripts, proxy HTTP requests, and read content from any web page.

The extension opens a persistent connection to the native messaging host com.laitis.browser.nativemessaging.chrome and exposes a set of actions the local app can invoke at any time. These include executing arbitrary JavaScript injected into the active tab, making credentialed HTTP requests to any URL and returning the response, and reading the current tab URL, selected text, or element content. A separate content script also silently overrides a form value on the Yandex developer portal whenever the user clicks a specific button.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

Mikolaitisv4.1Chrome Web Store
20Risk
Who publishes it

Mikolaitis - no other listings under this identity, 1 shared hostname

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
Mikolaitis

Shared hosts - 1 hostname

Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.

developer.tech.yandex.ru
Also called by 2 other listings, including VORON Extension

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

What it can do

Permissions this extension asks for, as declared in version 4.1. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • See the address and title of every tab you have open

    tabs

  • Act on the current tab, but only after you click the extension

    activeTab

  • Add items to the right-click menu

    contextMenus

  • Read information about your displays

    system.display

  • Talk to a program installed on your computer, outside the browser's sandbox

    nativeMessaging

  • Keep running in the background while your browser is open

    background

Where it sends data

Destinations our analysis observed Laitis contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.

  • com.laitis.browser.nativemessaging.chrome

    Laitis sends data to com.laitis.browser.nativemessaging.chrome. No other extension we have analysed sends data here.

Updated 30 September 2026kkfnfemdemphdadfolkmoimpeibeiadc