Is Laitis Browser Extension safe?
Laitis Browser Extension relays commands from a local native app to inject scripts, proxy HTTP requests, and read content from any web page.
The extension opens a persistent connection to the native messaging host com.laitis.browser.nativemessaging.chrome and exposes a set of actions the local app can invoke at any time. These include executing arbitrary JavaScript injected into the active tab, making credentialed HTTP requests to any URL and returning the response, and reading the current tab URL, selected text, or element content. A separate content script also silently overrides a form value on the Yandex developer portal whenever the user clicks a specific button.
Part of this rating comes from analysis signals we haven't published as detailed findings yet.
Who publishes itMikolaitis - no other listings under this identity, 1 shared hostname
Mikolaitis - no other listings under this identity, 1 shared hostname
What this publisher told the store about itself, and the other listings that told it the same thing.
Shared hosts - 1 hostname
Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
What it can do
Permissions this extension asks for, as declared in version 4.1. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
See the address and title of every tab you have open
tabs
Act on the current tab, but only after you click the extension
activeTab
Add items to the right-click menu
contextMenus
Read information about your displays
system.display
Talk to a program installed on your computer, outside the browser's sandbox
nativeMessaging
Keep running in the background while your browser is open
background
Where it sends data
Destinations our analysis observed Laitis contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.
- com.laitis.browser.nativemessaging.chrome
Laitis sends data to com.laitis.browser.nativemessaging.chrome. No other extension we have analysed sends data here.