Is RightInbox: Email Reminders, Tracking, Notes safe?
RightInbox connects Gmail pages to RightInbox and Mailshake services for reminders, tracking, templates, and notes.
The stored analysis describes RightInbox as a Gmail productivity extension for scheduling email, reminders, tracking, templates, and notes. It communicates with RightInbox and Mailshake service endpoints while those Gmail features run. No confirmed critical or high findings were recorded for this extension in the available analysis.
Who publishes itVoilaNorbert LLC - no other listings under this identity, 1 shared hostname
VoilaNorbert LLC - no other listings under this identity, 1 shared hostname
What this publisher told the store about itself, and the other listings that told it the same thing.
Shared hosts - 1 hostname
Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
Gmail page details are sent to a Stripe m-frame
Opening Gmail with RightInbox installed runs bundled Stripe.js and creates a 1x1 Stripe iframe.
Its URL fragment carries the Gmail URL, page title, referrer, and Stripe IDs; one captured URL had the inbox URL, title, and merchant ID.
You open Gmail while RightInbox is installed.
The extension manifest injects its Gmail script on mail.google.com and inbox.google.com pages.
The extension creates a Stripe iframe whose URL includes details from that Gmail page.
The source sets the iframe to 1x1 pixels and appends it to the page body.
| Field | Value | Why it matters | |
|---|---|---|---|
Gmail page URL | https://mail.google.com/mail/u/0/#inbox | Shows which Gmail view you had open, such as the inbox or another mailbox page. | |
Gmail page title | Inbox (199) - lennyyeeman@gmail.com - Gmail | Can reveal account and mailbox context from the Gmail tab title. | |
Referrer | https://mail.google.com/ | Shows the page that led into the current Gmail page when the browser provides one. | |
Stripe merchant ID | 7cb2f3d8-6a11-4cf0-9a21-4fd3c0d75901 | Gives the Stripe frame a browser identifier that can be reused across page loads on this host. | |
Stripe session ID | 2e14b7a9-8c33-44db-b312-fc978a2264ef | Links activity within a short browsing session on the Gmail host. |
Bundled Stripe.js builds the Gmail-to-Stripe m-frame
c = {
referrer: document.referrer,
title: document.title,
url: q,
muid: a.utils.getMerchantID(),
sid: a.utils.getSessionID(),
preview: i && !f
}, null != l && (c.metaReferrerPolicy = l), e = "#", c) r = c[m], e += m + "=" + encodeURIComponent(r) + "&";
(h = document.createElement("iframe")).src = "https://js.stripe.com/v2/m/outer.html" + en = window.location.href, setInterval(function() {
var d, c = window.location.href;
if (c !== n) {
try {
d = JSON.stringify({
action: "ping",
sid: a.utils.getSessionID(),
muid: a.utils.getMerchantID(),
referrer: n,
url: c,
title: document.title
}), h.contentWindow.postMessage(d, "*")
} catch (e) {
0
}
return n = c
}
}, 5e3)
return p = function(b, c) {
b = JSON.stringify({
action: "track",
sid: a.utils.getSessionID(),
muid: a.utils.getMerchantID(),
url: window.location.href,
source: b,
data: c
});
return h.contentWindow.postMessage(b, "*")
}, g = [], o = new Date, d = function() {
var a;
try {
return a = new Date, g.push(a - o), 10 === g.length && (p("mouse-timings-10", g), document.removeEventListener("mousemove", d)), o = a
} catch (c) {
0
}
}, document.addEventListener("mousemove", d)
}, "function" == typeof window.addEventListener && window.addEventListener("load", b), setTimeout(b, 5e3)b.generateID = function() {
return "xxxxxxxx-xxxx-4xxx-yxxx-xxxxxxxxxxxx".replace(/[xy]/g, function(a) {
var b = 16 * Math.random() | 0;
return ("x" === a ? b : 3 & b | 8).toString(16)
})
}, b.setCookie = function(a, b, c) {
var e, f;
return null == c && (c = {}), e = new Date, f = c.expiresIn || 31536e6, e.setTime(e.getTime() + f), null == c.path && (c.path = "/"), b = (b + "").replace(/[^!#-+\--:<-\[\]-~]/g, encodeURIComponent), f = encodeURIComponent(a) + "=" + b + ";expires=" + e.toGMTString() + ";path=" + c.path, c.domain && (f += ";domain=" + c.domain), document.cookie = f
}, b.getCookie = function(a) {
for (var d, e, b, c = document.cookie.split("; "), g = 0, h = c.length; g < h; g++)
if (d = (b = c[g]).indexOf("="), e = decodeURIComponent(b.substr(0, d)), b = decodeURIComponent(b.substr(d + 1)), e === a) return b;
return null
}, b.getMerchantID = function() {
var b;
try {
return b = this.getCookie("__stripe_mid") || this.generateID(), this.setCookie("__stripe_mid", b, {
domain: "." + document.location.hostname
}), b
} catch (c) {
return "NA"
}
}, b.getStripeID = function() {
try {
return Stripe.__sid || "NA"
} catch (b) {
return "NA"
}
}, b.getSessionID = function() {
var b, c;
try {
return b = this.getCookie("__stripe_sid") || this.generateID(), c = {
domain: "." + document.location.hostname,
expiresIn: 18e5
}, this.setCookie("__stripe_sid", b, c), b
} catch (d) {
return "NA"
}
}- js.stripe.com
The bundled Stripe code sets the iframe source to this host and appends Gmail page fields in the URL fragment.
- m.stripe.network
Dynamic analysis observed the resulting Stripe m-frame on this host with Gmail title, URL, and merchant identifier fields.
What it can do
Permissions this extension asks for, as declared in version 11.0.2. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Read and change your data on rightinbox.com
https://*.rightinbox.com/
Where it sends data
Destinations our analysis observed RightInbox: Email Reminders, Tracking, Notes contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.
- app.rightinbox.com
RightInbox: Email Reminders, Tracking, Notes sends data to app.rightinbox.com. One other extension we have analysed sends data here.
- app.mailshake.com
RightInbox: Email Reminders, Tracking, Notes sends data to app.mailshake.com. No other extension we have analysed sends data here.
- init.rightinbox.com
RightInbox: Email Reminders, Tracking, Notes sends data to init.rightinbox.com. No other extension we have analysed sends data here.
- logger.rightinbox.com
RightInbox: Email Reminders, Tracking, Notes sends data to logger.rightinbox.com. No other extension we have analysed sends data here.
- poll.rightinbox.com
RightInbox: Email Reminders, Tracking, Notes sends data to poll.rightinbox.com. No other extension we have analysed sends data here.