Is TestGen Plug-In safe?
TestGen Plug-In proxies credentialed browser requests to arbitrary URLs—including internal network hosts—through a native host application.
The extension's content script intercepts embed and object elements on any HTTP/HTTPS page and relays their source URLs to a native application via chrome.runtime messaging. This allows a malicious page to trigger credentialed browser-context fetches to attacker-supplied URLs, including intranet resources, whose full responses are forwarded to the installed native host. The native host can also instruct the extension to POST arbitrary data to any URL with custom HTTP headers, bypassing the page's CORS restrictions.
Part of this rating comes from analysis signals we haven't published as detailed findings yet.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
What it can do
Permissions this extension asks for, as declared in version 1.2. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Read and change your data on every site you visit
http://*/ and 1 more
Talk to a program installed on your computer, outside the browser's sandbox
nativeMessaging
Where it sends data
Destinations our analysis observed TestGen Plug-In contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.
- com.tamarack_software.plugin_host
TestGen Plug-In sends data to com.tamarack_software.plugin_host. No other extension we have analysed sends data here.