Is Strongbox AutoFill safe?
Strongbox AutoFill accepts postMessage commands from any web origin to fill credentials into forms or open new browser tabs.
The extension registers a window message listener on every page (http://* and https://*) without validating the sender's origin. Any website can send a postMessage with type onFillWithCredential to write an attacker-supplied username and password into the current page's input fields, or with type onRedirectUrl to instruct the extension to open an arbitrary URL in a new tab. The listener is active whenever the extension's inline autofill UI has been injected into the page.
Part of this rating comes from analysis signals we haven't published as detailed findings yet.
Who publishes itPHOEBE CODE LIMITED - no other listings under this identity
PHOEBE CODE LIMITED - no other listings under this identity
What this publisher told the store about itself, and the other listings that told it the same thing.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
What it can do
Permissions this extension asks for, as declared in version 1.2.5. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Read and change your data on every site you visit
http://*/*
Read and change your data on every secure site you visit
https://*/*
See the address and title of every tab you have open
tabs
Talk to a program installed on your computer, outside the browser's sandbox
nativeMessaging
See every page you navigate to, as you navigate to it
webNavigation
Store data in your browser
storage