Is User-Agent Switcher and Manager safe?
Medium risk
User-Agent Switcher and Manager fetches its agent list from cdn.jsdelivr.net at an unpinned @latest reference with no integrity check.
The extension lets users spoof the User-Agent header on outgoing requests. When the popup opens, it fetches the list of available user-agent strings from cdn.jsdelivr.net pointing at the @latest tag of the author's GitHub repository, with no subresource integrity check. This means any update to that repository is automatically picked up by the extension without a version bump or user consent.
Part of this rating comes from analysis signals we haven't published as detailed findings yet.
45Risk
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Data recipients
cdn.jsdelivr.net