Is Multiversity LockDown Browser safe?

Medium risk

Multiversity LockDown Browser transmits student name, username, and exam identifiers to a proctoring server and disables all other extensions during exam sessions.

During exam startup, the extension sends student PII — including first name, last name, username, course, and exam identifiers — to smc-service-cloud.respondus2.com, encrypted with a session secret derived from a hardcoded Blowfish ECB key shipped in the extension's code. It also calls chrome.management.setEnabled to disable every installed extension not on an allowlist, re-disabling any that are re-enabled during the exam. When a session begins, it additionally erases all browser form autofill data with no time-scoping, removing entries from all sites and all time.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

Respondus Incv0.4.00.09Chrome Web Store
45Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Data recipients

smc-service-cloud.respondus2.com
Updated 17 September 2026lndhfecljgbkdgkjaappkgkppiihdbff