Is Open incognito tab safe?

Medium risk

Open incognito tab sends feedback messages and the active tab URL to Telegram.

When a user submits feedback from the popup, the extension appends the current tab URL to the message and posts both to api.telegram.org through a hardcoded bot. It also injects a widget into every page that can open the current page in an incognito window and, when history clearing is enabled, remove that site's history entry. Because the widget is inserted into pages without requiring trusted clicks, page scripts can trigger the same action.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

cswprodevv2.8.3Chrome Web Store
45Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

What it can do

Permissions this extension asks for, as declared in version 2.0.1. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to. The current listed version is 2.8.3, which we have not unpacked yet.

  • Read and change your data on every site you visit

    http://*/*

  • Read and change your data on every secure site you visit

    https://*/*

  • Add items to the right-click menu

    contextMenus

  • Read and change your full browsing history

    history

  • Store data in your browser

    storage

Where it sends data

Destinations our analysis observed Open incognito tab contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.

  • api.telegram.org

    Open incognito tab sends data to api.telegram.org. 6 other extensions we have analysed send data here.

Updated 30 September 2026ebgmlfdcgihhfheckfdmhnmedjigogmm