Is OneLogin for Google Chrome safe?
OneLogin for Google Chrome fetches and executes JavaScript functions from app.onelogin.com on every website the user visits.
The extension retrieves per-site login step definitions from app.onelogin.com/login, each containing serialized JavaScript that it then runs on the current page. Content scripts active on all HTTP and HTTPS pages receive and execute these server-supplied code strings, which have access to the page DOM, credentials, cross-domain cookies, and the extension's own IPC channel. The background service also collects cookies across all domains to make them available to the server-fetched automation steps.
Part of this rating comes from analysis signals we haven't published as detailed findings yet.
Who publishes itOne Identity LLC - 1 other listing from the same operator, none carrying a finding
One Identity LLC - 1 other listing from the same operator, none carrying a finding
What this publisher told the store about itself, and the other listings that told it the same thing.
Same operator - 1 listing
Published under a different store account, but sharing the registered address, contact or declared legal entity this one gave the store.
Shared hosts - 22 hostnames
Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
What it can do
Permissions this extension asks for, as declared in version 4.1.1. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to. The current listed version is 4.2.0, which we have not unpacked yet.
Read and change your data on every site you visit
http://*/*
Read and change your data on every secure site you visit
https://*/*
Store data in your browser
storage
Read and change cookies, including the ones that keep you signed in
cookies
Run its own code inside the pages you visit
scripting
Act on the current tab, but only after you click the extension
activeTab
Block and redirect the requests your browser makes
declarativeNetRequest
Watch every request your browser makes
webRequest
See the address and title of every tab you have open
tabs
See every page you navigate to, as you navigate to it
webNavigation
Where it sends data
Destinations our analysis observed OneLogin contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.
- app.onelogin.com
OneLogin sends data to app.onelogin.com. No other extension we have analysed sends data here.