Is QuickForm - Autofill & Form Filler safe?

Medium risk

QuickForm Record Mode stores typed form values, including password inputs, in extension storage.

When Detect Mode is enabled, QuickForm's content script runs on all sites and listens for input and change events on form fields and editable content. It saves captured values into the extension's profiles storage without excluding password fields or other sensitive inputs.

quickform.prov1.17.4Chrome Web Store
45Risk
Who publishes it

quickform.pro - no other listings under this identity

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
quickform.pro

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

QuickForm's own onboarding page turns on its page recorder for you

QuickForm's welcome page turns on a page recorder for you, not the Options switch.

We observed it record and upload text typed on an unrelated site.

Severity
Medium unwanted
Type
Unexpected
CWE
CWE-359
Source
Dynamic sandbox
What actually happens
You did this

You install QuickForm Pro and its onboarding page opens automatically in a new tab.

The page is quickform.pro/welcome, served and scripted by the vendor.

The extension did this

That page sends the extension a message that turns on the 'Help improve QuickForm' recorder for you.

This happens without you visiting Options or touching that toggle, which defaults to off.

What the recorder captures on every site
  • Typed form field text
    growth marketing intern (illustrative)

    Text you type into any non-password field on any site can be captured and uploaded.

  • Password field text
    **************

    A password box is detected and its value is masked with asterisks before it leaves your device.

  • Page DOM content
    <input id="search" value="laptop stand"> (illustrative)

    Structural snapshots of the page you're viewing, including visible text and attributes.

  • Canvas/WebGL image
    image/webp snapshot, ~4 KB per redraw (illustrative)

    A compressed webp image of any canvas or WebGL drawing on the page is captured.

  • Page URL
    https://www.amazon.com/s?k=laptop+stand

    The full address of the page you're on is attached to every batch of captured data.

Captured request
POSThttps://www.quickform.pro/forms/trail

A planted marker value typed into a third-party site's search box was found in the decompressed body alongside that page's DOM attributes, confirming capture of content from sites unrelated to QuickForm.

Headers
Content-Type
application/octet-stream
The code that does this

Unconditional MAIN-world recorder registration and password-only masking

Readable version

Registers the recorder on every page at install

static/background/index.js
  "8ZbMf": [function(e) {    var t = e("@parcel/transformer-js/src/esmodule-helpers.js"),      r = e("url:../../../contents/quickpro-worker-page"),      s = t.interopDefault(r);    chrome.scripting.registerContentScripts([{      id: "contentsQuickproWorkerPage",      js: [s.default.split("/").pop().split("?")[0]],      matches: ["<all_urls>"],      runAt: "document_start",      world: "MAIN",      allFrames: !1    }]).catch(() => {})  }, {    "url:../../../contents/quickpro-worker-page": "l3cEY",    "@parcel/transformer-js/src/esmodule-helpers.js": "hbR2Q"  }],

Detects password fields and masks only those values

quickpro-worker-page.bdc225f8.js
function z(t) {  let e = t.type;  return t.hasAttribute(P) || t.hasAttribute("data-data-is-password") ? "password" : e ? q(e) : null}function F({  element: t,  o5: e,  tagName: r,  type: n,  value: i,  p0: s}) {  let o = i || "",    a = n && q(n);  return (e[r.toLowerCase()] || a && e[a]) && (o = s ? s(o, t) : "*".repeat(o.length)), o}
Where the captured data goes
    • www.quickform.pro

    Vendor's own session-recording endpoint; receives DOM, canvas snapshots and typed form data from every site visited while the recording preference is on.

Updated 30 September 2026hmbnbbbknglecphfogchkhpdjiodfclh