Is User-Agent Switcher and Manager safe?

Medium risk

User-Agent Switcher and Manager fetches its agent list from cdn.jsdelivr.net at an unpinned @latest reference with no integrity check.

The extension lets users spoof the User-Agent header on outgoing requests. When the popup opens, it fetches the list of available user-agent strings from cdn.jsdelivr.net pointing at the @latest tag of the author's GitHub repository, with no subresource integrity check. This means any update to that repository is automatically picked up by the extension without a version bump or user consent.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

45Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Data recipients

cdn.jsdelivr.net
Updated 17 September 2026amo-853731