Is SCheckPro safe?
SCheckPro is high risk. Dynamic analysis confirmed SCheckPro's content scripts, jQuery plus a 35KB automation script, load on every website at document-start, including banking and email sites. The listing claims spineditor.com only, but no code enforces that.
Who publishes itphamtri262 - no other listings under this identity, 1 shared hostname
phamtri262 - no other listings under this identity, 1 shared hostname
What this publisher told the store about itself, and the other listings that told it the same thing.
Shared hosts - 1 hostname
Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
SEO Tool Injects Into Every Website, Including Banking and Email
Dynamic analysis confirmed SCheckPro's content scripts, jQuery plus a 35KB automation script, load on every website at document-start, including banking and email sites.
The listing claims spineditor.com only, but no code enforces that.
You visit any website after installing SCheckPro.
No action beyond navigation is required; the injection is unconditional.
jquery.js and popup.js load into the page before any content renders.
The manifest declares matches=["*://*/*"], run_at=document_start, all_frames=true, so both scripts execute in every tab and every iframe on that tab.
Manifest declares universal content script injection
document.addEventListener('TestScheckPro', function (evt) { ... });
document.addEventListener('RequestWindow', function (evt) { ... });
document.addEventListener('ChangeDevice', function (evt) { ... });
document.addEventListener('OpenWindowCaptcha', function (evt) { ... });
document.addEventListener('RequestLink', function (evt) { ... });
document.addEventListener('AjaxLink', function (evt) { ... });
document.addEventListener('OpenView', function (evt) { ... });
document.addEventListener('GetTabCount', function (evt) { ... });Forum credential fill: username and password written to third-party login forms
} else if (login == 'unlogin' || login == 'unlogin2') {
if ($("#LoginControl").size() > 0) {
setWindowName("spineditorpost_login1_" + id);
$("#LoginControl").val(username);
$("#ctrl_password").val(pass);
$("#ctrl_pageLogin_login").val(username);
$("#ctrl_pageLogin_password").val(pass);
$("form#pageLogin").submit();
$("form#login").submit();
}
}- spineditor.com
Primary backend: serves forum post data, credentials, captcha coordination, and sound assets. Receives captcha solve results.
What it can do
Permissions this extension asks for, as declared in version 16.32. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to. The current listed version is 16.36, which we have not unpacked yet.
Read and change your data on every site you visit
*://*/*
Act on the current tab, but only after you click the extension
activeTab
See the address and title of every tab you have open
tabs
Run its own code inside the pages you visit
scripting
Schedule its own background tasks
alarms