Is Vencord Web safe?

Low risk

Vencord Web removes Discord Content-Security-Policy headers on Discord page and frame loads.

On Discord pages, Vencord Web's declarativeNetRequest rule removes both content-security-policy and content-security-policy-report-only response headers for main frames and subframes. Its content scripts then run on Discord, and an optional oneko plugin can fetch JavaScript from raw.githubusercontent.com and execute it on those pages.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

Xintov1.15.6Chrome Web Store
20Risk
Who publishes it

Xinto - no other listings under this identity

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
Xinto

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Where it sends data

Destinations our analysis observed Vencord Web contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.

  • raw.githubusercontent.comwidely used

    Vencord Web sends data to raw.githubusercontent.com. A widely used service: 26 other extensions we have analysed send data here.

Updated 30 September 2026cbghhgpcnddeihccjmnadmkaejncjndb