Is Strongbox AutoFill safe?

Low risk

Strongbox AutoFill accepts postMessage commands from any web origin to fill credentials into forms or open new browser tabs.

The extension registers a window message listener on every page (http://* and https://*) without validating the sender's origin. Any website can send a postMessage with type onFillWithCredential to write an attacker-supplied username and password into the current page's input fields, or with type onRedirectUrl to instruct the extension to open an arbitrary URL in a new tab. The listener is active whenever the extension's inline autofill UI has been injected into the page.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

Phoebe Code Limitedv1.2.5Chrome Web Store
20Risk
Who publishes it

PHOEBE CODE LIMITED - no other listings under this identity

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
Phoebe Code Limited
Declared legal entity
PHOEBE CODE LIMITED
Registered address
57 Newtown Road the Offices, HOVE BN3 7BA, GB
Registered contact
PHOEBE CODE LIMITED

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

What it can do

Permissions this extension asks for, as declared in version 1.2.5. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Read and change your data on every site you visit

    http://*/*

  • Read and change your data on every secure site you visit

    https://*/*

  • See the address and title of every tab you have open

    tabs

  • Talk to a program installed on your computer, outside the browser's sandbox

    nativeMessaging

  • See every page you navigate to, as you navigate to it

    webNavigation

  • Store data in your browser

    storage

favicon
Updated 30 September 2026mnilpkfepdibngheginihjpknnopchbn