Is SimpleLogin: Open-source Email Protection safe?
Low risk
SimpleLogin exposes an unguarded postMessage handler on every page, letting any site script force navigation to the SimpleLogin dashboard.
The extension injects a content script into every HTTP and HTTPS page. This script listens for postMessage events without checking the sender's origin, allowing any page script to query whether the extension is installed and, if the user is logged in, force a redirect to app.simplelogin.io/dashboard/. A separate handler broadcasts the extension's version back to any requesting page script.
Part of this rating comes from analysis signals we haven't published as detailed findings yet.
20Risk
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.