Is PingOne-Extension safe?
PingOne-Extension injects autofill scripts into all pages and accepts postMessages without origin validation to trigger form fills.
The extension runs on every website and uses postMessage listeners to coordinate its SSO autofill workflow across frames. Both the init.js content script and the injected extension.js handle inbound messages without checking the sender's origin, meaning any same-page script or cross-frame message can trigger script injection or instruct the autofill engine to fill form fields with attacker-supplied values and selectors. The autofill machinery (simulateEnterInputValue) processes field selectors and values directly from the message payload.
Part of this rating comes from analysis signals we haven't published as detailed findings yet.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.