Is Redux DevTools safe?

Medium risk

Redux DevTools exposes full Redux application state and action dispatch to any other installed Chrome extension.

The extension sets externally_connectable to allow connections from all extension IDs ('*'). Any installed extension that connects with a port name beginning with 'monitor' receives every Redux state update (actions, computed states, and partial states) from all monitored web apps via the background script's message relay. The same open message handler also accepts arbitrary Redux actions from external extensions and forwards DISPATCH commands back into monitored web application tabs, with no sender ID allowlist or authentication check.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

Redux DevToolsv3.2.10Chrome Web Store
45Risk
Who publishes it

Redux DevTools - no other listings under this identity

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
Redux DevTools

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

What it can do

Permissions this extension asks for, as declared in version 3.2.10. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Read files on your computer that you open in the browser

    file:///*

  • Read and change your data on every site you visit

    http://*/*

  • Read and change your data on every secure site you visit

    https://*/*

  • Show you desktop notifications

    notifications

  • Add items to the right-click menu

    contextMenus

  • Store data in your browser

    storage

Updated 30 September 2026lmhkpmbekcpmknklioeibfkpmmfibljd