Is Verbal safe?

Low risk

Verbal loads its uuid library live from jspm.dev with no version pin, in a worker with tabCapture, scripting and all-site access.

Every time Verbal's background service worker starts up, it fetches the 'uuid' code library directly from the public CDN jspm.dev instead of bundling it, with no version lock and no integrity check on what comes back. That same worker holds permission to capture tab audio/video, run scripts on any page, and access every website you visit, so whatever jspm.dev serves for that import runs with all of those privileges.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

Verbalv1.3.4Chrome Web Store
20Risk
Who publishes it

Verbal - no other listings under this identity

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
Verbal
Declared legal entity
Verbal

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

What it can do

Permissions this extension asks for, as declared in version 1.3.4. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Read and change your data on every site you visit

    <all_urls>

  • Act on the current tab, but only after you click the extension

    activeTab

  • Capture the video and audio of a tab

    tabCapture

  • See the address and title of every tab you have open

    tabs

  • Store data in your browser

    storage

  • Run its own code inside the pages you visit

    scripting

  • Run hidden pages in the background

    offscreen

  • Schedule its own background tasks

    alarms

Updated 30 September 2026bdneobnjhgednodmmclilkohakeieilm