Is Popup Blocker (strict) safe?
Popup Blocker (strict)'s notification page accepts messages from any site, letting it be tricked into redirecting your tab to an attacker's URL.
The extension's popup-notification page is web-accessible to every site and listens for postMessage without checking who sent it, so any embedding page can post a fake 'blocked popup' entry pointing at a URL of its choosing. Clicking the notification's Redirect or Background buttons (or, if auto-actions are enabled, without any click at all) sends that attacker-supplied URL to the extension's background worker, which navigates the current tab or opens a new tab to it with no further validation beyond it starting with http/ftp. No data leaves the browser; the impact is unwanted tab navigation, useful for redirect or phishing chains.
Part of this rating comes from analysis signals we haven't published as detailed findings yet.
Who publishes ityokris.dev - 7 other listings from the same operator, 1 of them carrying a finding
yokris.dev - 7 other listings from the same operator, 1 of them carrying a finding
What this publisher told the store about itself, and the other listings that told it the same thing.
Same store account
7 other listings published from this account, 799k+ users between them. 1 of them carries a finding.
Shared hosts - 1 hostname
Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
What it can do
Permissions this extension asks for, as declared in version 0.9.1. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Read and change your data on every site you visit
<all_urls>
Store data in your browser
storage
Run its own code inside the pages you visit
scripting