Is RightInbox: Email Reminders, Tracking, Notes safe?

Medium risk

RightInbox connects Gmail pages to RightInbox and Mailshake services for reminders, tracking, templates, and notes.

The stored analysis describes RightInbox as a Gmail productivity extension for scheduling email, reminders, tracking, templates, and notes. It communicates with RightInbox and Mailshake service endpoints while those Gmail features run. No confirmed critical or high findings were recorded for this extension in the available analysis.

Right Inboxv11.0.2Chrome Web Store
45Risk
Who publishes it

VoilaNorbert LLC - no other listings under this identity, 1 shared hostname

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
Right Inbox
Declared legal entity
VoilaNorbert LLC
Registered address
1920 East Riverside Drive, Suite A120-116, Austin, TX 78741, US
Registered contact
Robert Senoff

Shared hosts - 1 hostname

Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.

rightinbox.com
Also called by 2 other listings, including Gmail Notes - Add notes to email in Gmail

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

SeverityMEDIUM
ClassUNWANTED
TypeUnexpected
CWECWE-359
SourceAI SANDBOX

Gmail page details are sent to a Stripe m-frame

Opening Gmail with RightInbox installed runs bundled Stripe.js and creates a 1x1 Stripe iframe.

Its URL fragment carries the Gmail URL, page title, referrer, and Stripe IDs; one captured URL had the inbox URL, title, and merchant ID.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You open Gmail while RightInbox is installed.

The extension manifest injects its Gmail script on mail.google.com and inbox.google.com pages.

The extension did this

The extension creates a Stripe iframe whose URL includes details from that Gmail page.

The source sets the iframe to 1x1 pixels and appends it to the page body.

02EvidenceNETWORK CAPTURE
Captured request
GEThttps://js.stripe.com/v2/m/outer.html
Dynamic analysis observed the Stripe m-frame carrying Gmail title, Gmail URL, and a Stripe merchant identifier in the URL fragment.
03EvidenceFIELD TABLE
Fields placed in the Stripe iframe URL fragment
FieldValueWhy it matters
Gmail page URL
https://mail.google.com/mail/u/0/#inboxShows which Gmail view you had open, such as the inbox or another mailbox page.
Gmail page title
Inbox (199) - lennyyeeman@gmail.com - GmailCan reveal account and mailbox context from the Gmail tab title.
Referrer
https://mail.google.com/Shows the page that led into the current Gmail page when the browser provides one.
Stripe merchant ID
7cb2f3d8-6a11-4cf0-9a21-4fd3c0d75901Gives the Stripe frame a browser identifier that can be reused across page loads on this host.
Stripe session ID
2e14b7a9-8c33-44db-b312-fc978a2264efLinks activity within a short browsing session on the Gmail host.
04EvidenceCODE COMPARE
The code that does this

Bundled Stripe.js builds the Gmail-to-Stripe m-frame

What it actually does
Readable fragment builder in the deobfuscated bundleapp/rightinbox-client-chrome.js:20643-20709
c = {
  referrer: document.referrer,
  title: document.title,
  url: q,
  muid: a.utils.getMerchantID(),
  sid: a.utils.getSessionID(),
  preview: i && !f
}, null != l && (c.metaReferrerPolicy = l), e = "#", c) r = c[m], e += m + "=" + encodeURIComponent(r) + "&";
(h = document.createElement("iframe")).src = "https://js.stripe.com/v2/m/outer.html" + e
Readable URL-change and mouse-timing posts in the deobfuscated bundleapp/rightinbox-client-chrome.js:20670-20709
n = window.location.href, setInterval(function() {
  var d, c = window.location.href;
  if (c !== n) {
    try {
      d = JSON.stringify({
        action: "ping",
        sid: a.utils.getSessionID(),
        muid: a.utils.getMerchantID(),
        referrer: n,
        url: c,
        title: document.title
      }), h.contentWindow.postMessage(d, "*")
    } catch (e) {
      0
    }
    return n = c
  }
}, 5e3)
return p = function(b, c) {
  b = JSON.stringify({
    action: "track",
    sid: a.utils.getSessionID(),
    muid: a.utils.getMerchantID(),
    url: window.location.href,
    source: b,
    data: c
  });
  return h.contentWindow.postMessage(b, "*")
}, g = [], o = new Date, d = function() {
  var a;
  try {
    return a = new Date, g.push(a - o), 10 === g.length && (p("mouse-timings-10", g), document.removeEventListener("mousemove", d)), o = a
  } catch (c) {
    0
  }
}, document.addEventListener("mousemove", d)
}, "function" == typeof window.addEventListener && window.addEventListener("load", b), setTimeout(b, 5e3)
Readable helpers that create the Stripe IDsapp/rightinbox-client-chrome.js:21591-21624
b.generateID = function() {
  return "xxxxxxxx-xxxx-4xxx-yxxx-xxxxxxxxxxxx".replace(/[xy]/g, function(a) {
    var b = 16 * Math.random() | 0;
    return ("x" === a ? b : 3 & b | 8).toString(16)
  })
}, b.setCookie = function(a, b, c) {
  var e, f;
  return null == c && (c = {}), e = new Date, f = c.expiresIn || 31536e6, e.setTime(e.getTime() + f), null == c.path && (c.path = "/"), b = (b + "").replace(/[^!#-+\--:<-\[\]-~]/g, encodeURIComponent), f = encodeURIComponent(a) + "=" + b + ";expires=" + e.toGMTString() + ";path=" + c.path, c.domain && (f += ";domain=" + c.domain), document.cookie = f
}, b.getCookie = function(a) {
  for (var d, e, b, c = document.cookie.split("; "), g = 0, h = c.length; g < h; g++)
    if (d = (b = c[g]).indexOf("="), e = decodeURIComponent(b.substr(0, d)), b = decodeURIComponent(b.substr(d + 1)), e === a) return b;
  return null
}, b.getMerchantID = function() {
  var b;
  try {
    return b = this.getCookie("__stripe_mid") || this.generateID(), this.setCookie("__stripe_mid", b, {
      domain: "." + document.location.hostname
    }), b
  } catch (c) {
    return "NA"
  }
}, b.getStripeID = function() {
  try {
    return Stripe.__sid || "NA"
  } catch (b) {
    return "NA"
  }
}, b.getSessionID = function() {
  var b, c;
  try {
    return b = this.getCookie("__stripe_sid") || this.generateID(), c = {
      domain: "." + document.location.hostname,
      expiresIn: 18e5
    }, this.setCookie("__stripe_sid", b, c), b
  } catch (d) {
    return "NA"
  }
}
05EvidenceTHIRD PARTY LIST
Stripe hosts involved in the m-frame flow
  • js.stripe.com

    The bundled Stripe code sets the iframe source to this host and appends Gmail page fields in the URL fragment.

  • m.stripe.network

    Dynamic analysis observed the resulting Stripe m-frame on this host with Gmail title, URL, and merchant identifier fields.

What it can do

Permissions this extension asks for, as declared in version 11.0.2. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Read and change your data on rightinbox.com

    https://*.rightinbox.com/

Where it sends data

Destinations our analysis observed RightInbox: Email Reminders, Tracking, Notes contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.

  • app.rightinbox.com

    RightInbox: Email Reminders, Tracking, Notes sends data to app.rightinbox.com. One other extension we have analysed sends data here.

  • app.mailshake.com

    RightInbox: Email Reminders, Tracking, Notes sends data to app.mailshake.com. No other extension we have analysed sends data here.

  • init.rightinbox.com

    RightInbox: Email Reminders, Tracking, Notes sends data to init.rightinbox.com. No other extension we have analysed sends data here.

  • logger.rightinbox.com

    RightInbox: Email Reminders, Tracking, Notes sends data to logger.rightinbox.com. No other extension we have analysed sends data here.

  • poll.rightinbox.com

    RightInbox: Email Reminders, Tracking, Notes sends data to poll.rightinbox.com. No other extension we have analysed sends data here.

Updated 30 September 2026mflnemhkomgploogccdmcloekbloobgb