Is Open in IE safe?

Medium risk

Open in IE downloads a native client binary from GitHub without checksum or signature verification.

When a user initiates the native client installation, the extension fetches the latest release metadata from the GitHub API and downloads a platform-specific zip file using whatever URL the release assets provide. No hash or signature is checked before the user runs the downloaded binary. Whoever controls the GitHub repository or its release assets can substitute any executable at that URL.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

rynu.smithv0.3.3Chrome Web Store
45Risk
Who publishes it

rynu.smith - 6 other listings from the same operator, 2 of them carrying a finding

What this publisher told the store about itself, and the other listings that told it the same thing.

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

What it can do

Permissions this extension asks for, as declared in version 0.3.3. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • See the address and title of every tab you have open

    tabs

  • Store data in your browser

    storage

  • Add items to the right-click menu

    contextMenus

  • Talk to a program installed on your computer, outside the browser's sandbox

    nativeMessaging

Where it sends data

Destinations our analysis observed Open in IE contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.

  • api.github.com

    Open in IE sends data to api.github.com. 11 other extensions we have analysed send data here.

Updated 30 September 2026looohpideggedchhpphemdmppnmdkgfd