Is QuickForm - Autofill & Form Filler safe?
QuickForm Record Mode stores typed form values, including password inputs, in extension storage.
When Detect Mode is enabled, QuickForm's content script runs on all sites and listens for input and change events on form fields and editable content. It saves captured values into the extension's profiles storage without excluding password fields or other sensitive inputs.
Who publishes itquickform.pro - no other listings under this identity
quickform.pro - no other listings under this identity
What this publisher told the store about itself, and the other listings that told it the same thing.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
QuickForm's own onboarding page turns on its page recorder for you
QuickForm's welcome page turns on a page recorder for you, not the Options switch.
We observed it record and upload text typed on an unrelated site.
- Severity
- Medium unwanted
- Type
- Unexpected
- CWE
- CWE-359
- Source
- Dynamic sandbox
You install QuickForm Pro and its onboarding page opens automatically in a new tab.
The page is quickform.pro/welcome, served and scripted by the vendor.
That page sends the extension a message that turns on the 'Help improve QuickForm' recorder for you.
This happens without you visiting Options or touching that toggle, which defaults to off.
- Typed form field textgrowth marketing intern (illustrative)
Text you type into any non-password field on any site can be captured and uploaded.
- Password field text**************
A password box is detected and its value is masked with asterisks before it leaves your device.
- Page DOM content<input id="search" value="laptop stand"> (illustrative)
Structural snapshots of the page you're viewing, including visible text and attributes.
- Canvas/WebGL imageimage/webp snapshot, ~4 KB per redraw (illustrative)
A compressed webp image of any canvas or WebGL drawing on the page is captured.
- Page URLhttps://www.amazon.com/s?k=laptop+stand
The full address of the page you're on is attached to every batch of captured data.
A planted marker value typed into a third-party site's search box was found in the decompressed body alongside that page's DOM attributes, confirming capture of content from sites unrelated to QuickForm.
- Content-Type
- application/octet-stream
Unconditional MAIN-world recorder registration and password-only masking
Registers the recorder on every page at install
static/background/index.js "8ZbMf": [function(e) { var t = e("@parcel/transformer-js/src/esmodule-helpers.js"), r = e("url:../../../contents/quickpro-worker-page"), s = t.interopDefault(r); chrome.scripting.registerContentScripts([{ id: "contentsQuickproWorkerPage", js: [s.default.split("/").pop().split("?")[0]], matches: ["<all_urls>"], runAt: "document_start", world: "MAIN", allFrames: !1 }]).catch(() => {}) }, { "url:../../../contents/quickpro-worker-page": "l3cEY", "@parcel/transformer-js/src/esmodule-helpers.js": "hbR2Q" }],Detects password fields and masks only those values
quickpro-worker-page.bdc225f8.jsfunction z(t) { let e = t.type; return t.hasAttribute(P) || t.hasAttribute("data-data-is-password") ? "password" : e ? q(e) : null}function F({ element: t, o5: e, tagName: r, type: n, value: i, p0: s}) { let o = i || "", a = n && q(n); return (e[r.toLowerCase()] || a && e[a]) && (o = s ? s(o, t) : "*".repeat(o.length)), o}- www.quickform.pro
Vendor's own session-recording endpoint; receives DOM, canvas snapshots and typed form data from every site visited while the recording preference is on.