Is Traffic Lite safe?

Medium risk

Traffic Lite exposes JWT auth tokens in browser-history URLs and accepts storage-wipe commands from any Netlify subdomain.

When opening the web dashboard, the extension appends the user's JWT token and email address as URL fragment parameters, storing them in the browser's history and making them accessible to JavaScript on the Netlify domain. The extension also accepts CLEAR_ALL_DATA messages from any *.netlify.app origin—including attacker-controlled subdomains—which causes it to immediately erase all stored auth tokens, classroom data, and session state without any additional authentication check.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

dtranchina25v1.5.38Chrome Web Store
45Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Updated 17 September 2026fbgdjpgcehknbpaoigchadbjfibmpife