Is Mailvelope safe?
Mailvelope includes a hardcoded Google OAuth2 client_secret in its extension bundle, exposing the credential to anyone who unpacks the file.
The extension's background bundle includes a plaintext Google OAuth2 client_secret used during authorization-code and token-refresh flows with oauth2.googleapis.com. Because the secret is distributed inside the installable package, anyone who unpacks the XPI can extract it and send OAuth2 requests that appear to Google as if they originated from the Mailvelope application. No user data is forwarded to third-party servers by this mechanism, but the exposed credential undermines Google's ability to distinguish legitimate Mailvelope clients from unauthorized ones.
Who publishes itMailvelope GmbH - no other listings under this identity, 2 shared hostnames
Mailvelope GmbH - no other listings under this identity, 2 shared hostnames
What this publisher told the store about itself, and the other listings that told it the same thing.
Shared hosts - 2 hostnames
Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
What it can do
Permissions this extension asks for, as declared in version 6.2.0. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Read and change your data on every site you visit
*://*/*
Schedule its own background tasks
alarms
Sign you in with your Google account
identity
Run its own code inside the pages you visit
scripting
Store data in your browser
storage
See the address and title of every tab you have open
tabs
See every page you navigate to, as you navigate to it
webNavigation
Where it sends data
Destinations our analysis observed Mailvelope contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.
- oauth2.googleapis.com
Mailvelope sends data to oauth2.googleapis.com. 13 other extensions we have analysed send data here.