Is Open in GIMP™ photo editor safe?

Medium risk

Open in GIMP fetches and downloads a native-client installer from GitHub Releases without verifying its integrity.

When prompted to install the native client, the extension queries the GitHub Releases API to find the latest asset URL for the user's OS and triggers a download of that ZIP archive. No hash, checksum, or signature is checked against the downloaded file. The native host the extension subsequently connects to handles local command execution, so a tampered installer could result in persistent access to the host system.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

yokris.devv0.2.1Chrome Web Store
45Risk
Who publishes it

yokris.dev - 7 other listings from the same operator, 1 of them carrying a finding

What this publisher told the store about itself, and the other listings that told it the same thing.

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

What it can do

Permissions this extension asks for, as declared in version 0.2.1. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Store data in your browser

    storage

  • Add items to the right-click menu

    contextMenus

  • Start, monitor and manage your downloads

    downloads

  • Talk to a program installed on your computer, outside the browser's sandbox

    nativeMessaging

Where it sends data

Destinations our analysis observed Open in GIMP™ photo editor contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.

  • api.github.com

    Open in GIMP™ photo editor sends data to api.github.com. 11 other extensions we have analysed send data here.

Updated 30 September 2026jgpghknlbaljigdhcjimjnkkjniiipmm