Is perc.pass - Password Manager safe?

Low risk

perc.pass accepts postMessages from any webpage with no origin check, prefilling a save-password prompt with attacker-chosen credentials.

A content script that perc.pass injects on every page listens for window postMessage events of type PLASMO_SAVE_CREDENTIALS_RELAY without verifying who sent them. Any webpage can send this message with its own choice of login, password, URL, and title, which the extension relays into its "Save this password?" dialog once the vault is unlocked. This means a page can stage a password-save prompt pre-filled with values it controls rather than values the user actually typed.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

Perceptus Sp. z o.o.v3.5.0Chrome Web Store
20Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Updated 20 September 2026fablafiiajabphdliflbomjdlccedonj