Is MultiPassword — Password manager safe?

Medium risk

MultiPassword broadcasts vault credentials to any page via wildcard postMessage and exposes its vault API to multipassword.com subdomains.

When autofilling, MultiPassword iframes call parent.postMessage with full vault items — including encrypted credential fields — using a wildcard origin ('*'), so any script running on the same page can intercept them. Separately, the extension registers an external Chrome port listener that accepts connections from any subdomain of multipassword.com and routes them through the same internal handler as trusted popup connections, giving that connection the ability to call privileged methods such as unlockAppInsecure and getItems.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

MultiPasswordv0.99.55Chrome Web Store
45Risk
Who publishes it

MultiPassword - no other listings under this identity

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
MultiPassword

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

SeverityLOW
ClassUNWANTED
TypeUnexpected
CWECWE-200
SourceAI SANDBOX

Extension Disables Chrome Autofill on Every Startup Without User Notification

Each Chrome start with MultiPassword installed automatically disables four privacy settings: autofill, credit card autofill, address autofill, and built-in password saving.

This happens before any interaction, with no prompt or notice.

01EvidenceCAUSE EFFECT
What actually happens
You did this

Chrome launches, or the MultiPassword extension service worker restarts.

No user interaction with the extension is required.

The extension did this

MultiPassword disables Chrome's built-in autofill for forms, credit cards, addresses, and password saving, without asking.

The change takes effect immediately and persists until Chrome's settings are manually restored.

02EvidenceCODE COMPARE
The code that does this

The autofill-disable code, shipped source

What it actually does
disableAutofill() and its setter
// Called unconditionally from app.start() on every service worker startup.
// Maps over four chrome.privacy.services keys and sets each to false
// if the extension currently controls that setting.
disableAutofill() {
  [
    'autofillEnabled',
    'autofillCreditCardEnabled',
    'autofillAddressEnabled',
    'passwordSavingEnabled',
  ].forEach(settingKey => disablePrivacySetting(settingKey));
}

function disablePrivacySetting(key) {
  const setting = chrome.privacy.services[key];
  if (!setting) return;
  setting.get({}, (details) => {
    if (details.levelOfControl === 'controllable_by_this_extension') {
      setting.set({ value: false });
    }
  });
}
Startup chain showing the unconditional call site
async start() {
  // ... other startup tasks ...
  await this.migrateLocalStorage();
  this.showPromoPage().catch(log);
  this.bindTabScriptInjectorEvents();
  this.disableAutofill();              // <-- no guard, no user prompt
  this.attachAnalyticsEventHandlers().catch(log);
  this.modifyContextMenu().catch(log);
  this.tryUnlockInsecure().catch(log);
  this.updateIcon().catch(log);
  this.addHotkeysHandler();
  await this.showCabinetPage();
}
03EvidenceFIELD TABLE
Chrome settings disabled on every startup:
FieldValueWhy it matters
General autofill
chrome.privacy.services.autofillEnabled → falseChrome's suggestion of previously entered form data on any site.
Credit card autofill
chrome.privacy.services.autofillCreditCardEnabled → falseChrome's saved payment card suggestions on checkout pages.
Address autofill
chrome.privacy.services.autofillAddressEnabled → falseChrome's saved address suggestions on shipping and billing forms.
Chrome password saving
chrome.privacy.services.passwordSavingEnabled → falseChrome's offer to save new passwords entered on any site.

What it can do

Permissions this extension asks for, as declared in version 0.99.12. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to. The current listed version is 0.99.55, which we have not unpacked yet.

  • Read and change your data on every secure site you visit

    https://*/*

  • Read and change your data on every site you visit

    http://*/*

  • Store an unlimited amount of data in your browser

    unlimitedStorage

  • Change your browser's privacy and security settings

    privacy

  • Act on the current tab, but only after you click the extension

    activeTab

  • Clear your browsing history, cache and cookies

    browsingData

  • Write to your clipboard

    clipboardWrite

  • Add items to the right-click menu

    contextMenus

  • Run its own code inside the pages you visit

    scripting

  • Store data in your browser

    storage

  • See the address and title of every tab you have open

    tabs

  • Run hidden pages in the background

    offscreen

  • Watch every request your browser makes

    webRequest

Where it sends data

Destinations our analysis observed MultiPassword contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.

  • api.multipassword.com

    MultiPassword sends data to api.multipassword.com. No other extension we have analysed sends data here.

  • my.multipassword.com

    MultiPassword sends data to my.multipassword.com. No other extension we have analysed sends data here.

  • ws.multipassword.com

    MultiPassword sends data to ws.multipassword.com. No other extension we have analysed sends data here.

Updated 30 September 2026cnlhokffphohmfcddnibpohmkdfafdli