Is Password Boss safe?
Password Boss reads form field values on all web pages and forwards them to the local Password Boss desktop app via native messaging.
The extension's content script runs on every HTTP and HTTPS page, collecting form inputs including usernames, passwords, credit card numbers, and addresses, then relaying them to the background script. The background script forwards this data to the Password Boss desktop app via the native messaging host 'passwordboss.browseroverlay.chrome', or falls back to an unauthenticated localhost WebSocket at ws://127.0.0.1:52242/ if native messaging is unavailable. All data transfer stays on the local machine; no data is sent to remote servers.
Part of this rating comes from analysis signals we haven't published as detailed findings yet.
Who publishes itCyberFOX LLC - 1 other listing from the same operator, none carrying a finding
CyberFOX LLC - 1 other listing from the same operator, none carrying a finding
What this publisher told the store about itself, and the other listings that told it the same thing.
Same store account
1 other listing published from this account, 5k+ users between them, none of them carrying a finding.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
What it can do
Permissions this extension asks for, as declared in version 5.5.5138. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Read and change your data on every site you visit
<all_urls> and 1 more
Read and change your data on every secure site you visit
https://*/*
See the address and title of every tab you have open
tabs
Act on the current tab, but only after you click the extension
activeTab
See, disable and uninstall your other extensions, including your security ones
management
Talk to a program installed on your computer, outside the browser's sandbox
nativeMessaging
See every page you navigate to, as you navigate to it
webNavigation
Add items to the right-click menu
contextMenus
Where it sends data
Destinations our analysis observed Password Boss contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.
- 127.0.0.1:52242 (local WebSocket fallback)
Password Boss sends data to 127.0.0.1:52242 (local WebSocket fallback). Named as a recipient in this extension's own analysis.
- passwordboss.browseroverlay.chrome (local native host)
Password Boss sends data to passwordboss.browseroverlay.chrome (local native host). Named as a recipient in this extension's own analysis.