Is perc.pass - Password Manager safe?
perc.pass accepts postMessages from any webpage with no origin check, prefilling a save-password prompt with attacker-chosen credentials.
A content script that perc.pass injects on every page listens for window postMessage events of type PLASMO_SAVE_CREDENTIALS_RELAY without verifying who sent them. Any webpage can send this message with its own choice of login, password, URL, and title, which the extension relays into its "Save this password?" dialog once the vault is unlocked. This means a page can stage a password-save prompt pre-filled with values it controls rather than values the user actually typed.
Part of this rating comes from analysis signals we haven't published as detailed findings yet.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.