Is Sticky Password manager & safe safe?
Sticky Password intercepts WebAuthn API calls and disables the browser's built-in password manager, routing credentials via its native app.
On every HTTP and HTTPS page, the extension injects a script that intercepts navigator.credentials.create and navigator.credentials.get calls and forwards them to a local native messaging host. It also disables the browser's built-in password manager, autofill for addresses, and autofill for credit cards on first install. When the Contactless Autofill feature is used, the extension sends a persistent client ID and an RSA public key to spcb.stickypassword.com to initiate a QR-based session.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.