Is Sticky Password manager & safe safe?

Clean risk

Sticky Password intercepts WebAuthn API calls and disables the browser's built-in password manager, routing credentials via its native app.

On every HTTP and HTTPS page, the extension injects a script that intercepts navigator.credentials.create and navigator.credentials.get calls and forwards them to a local native messaging host. It also disables the browser's built-in password manager, autofill for addresses, and autofill for credit cards on first install. When the Contactless Autofill feature is used, the extension sends a persistent client ID and an RSA public key to spcb.stickypassword.com to initiate a QR-based session.

Sticky Passwordv8.9.11.1343Firefox Add-ons
0Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Data recipients

spcb.stickypassword.com
Updated 17 September 2026amo-767490