Is MultiPassword — Password manager safe?
MultiPassword broadcasts vault credentials to any page via wildcard postMessage and exposes its vault API to multipassword.com subdomains.
When autofilling, MultiPassword iframes call parent.postMessage with full vault items — including encrypted credential fields — using a wildcard origin ('*'), so any script running on the same page can intercept them. Separately, the extension registers an external Chrome port listener that accepts connections from any subdomain of multipassword.com and routes them through the same internal handler as trusted popup connections, giving that connection the ability to call privileged methods such as unlockAppInsecure and getItems.
Part of this rating comes from analysis signals we haven't published as detailed findings yet.
Who publishes itMultiPassword - no other listings under this identity
MultiPassword - no other listings under this identity
What this publisher told the store about itself, and the other listings that told it the same thing.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
Extension Disables Chrome Autofill on Every Startup Without User Notification
Each Chrome start with MultiPassword installed automatically disables four privacy settings: autofill, credit card autofill, address autofill, and built-in password saving.
This happens before any interaction, with no prompt or notice.
Chrome launches, or the MultiPassword extension service worker restarts.
No user interaction with the extension is required.
MultiPassword disables Chrome's built-in autofill for forms, credit cards, addresses, and password saving, without asking.
The change takes effect immediately and persists until Chrome's settings are manually restored.
The autofill-disable code, shipped source
// Called unconditionally from app.start() on every service worker startup.
// Maps over four chrome.privacy.services keys and sets each to false
// if the extension currently controls that setting.
disableAutofill() {
[
'autofillEnabled',
'autofillCreditCardEnabled',
'autofillAddressEnabled',
'passwordSavingEnabled',
].forEach(settingKey => disablePrivacySetting(settingKey));
}
function disablePrivacySetting(key) {
const setting = chrome.privacy.services[key];
if (!setting) return;
setting.get({}, (details) => {
if (details.levelOfControl === 'controllable_by_this_extension') {
setting.set({ value: false });
}
});
}async start() {
// ... other startup tasks ...
await this.migrateLocalStorage();
this.showPromoPage().catch(log);
this.bindTabScriptInjectorEvents();
this.disableAutofill(); // <-- no guard, no user prompt
this.attachAnalyticsEventHandlers().catch(log);
this.modifyContextMenu().catch(log);
this.tryUnlockInsecure().catch(log);
this.updateIcon().catch(log);
this.addHotkeysHandler();
await this.showCabinetPage();
}| Field | Value | Why it matters | |
|---|---|---|---|
General autofill | chrome.privacy.services.autofillEnabled → false | Chrome's suggestion of previously entered form data on any site. | |
Credit card autofill | chrome.privacy.services.autofillCreditCardEnabled → false | Chrome's saved payment card suggestions on checkout pages. | |
Address autofill | chrome.privacy.services.autofillAddressEnabled → false | Chrome's saved address suggestions on shipping and billing forms. | |
Chrome password saving | chrome.privacy.services.passwordSavingEnabled → false | Chrome's offer to save new passwords entered on any site. |
What it can do
Permissions this extension asks for, as declared in version 0.99.12. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to. The current listed version is 0.99.55, which we have not unpacked yet.
Read and change your data on every secure site you visit
https://*/*
Read and change your data on every site you visit
http://*/*
Store an unlimited amount of data in your browser
unlimitedStorage
Change your browser's privacy and security settings
privacy
Act on the current tab, but only after you click the extension
activeTab
Clear your browsing history, cache and cookies
browsingData
Write to your clipboard
clipboardWrite
Add items to the right-click menu
contextMenus
Run its own code inside the pages you visit
scripting
Store data in your browser
storage
See the address and title of every tab you have open
tabs
Run hidden pages in the background
offscreen
Watch every request your browser makes
webRequest
Where it sends data
Destinations our analysis observed MultiPassword contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.
- api.multipassword.com
MultiPassword sends data to api.multipassword.com. No other extension we have analysed sends data here.
- my.multipassword.com
MultiPassword sends data to my.multipassword.com. No other extension we have analysed sends data here.
- ws.multipassword.com
MultiPassword sends data to ws.multipassword.com. No other extension we have analysed sends data here.