Is VIT Vellore Library safe?

Low risk

VIT Vellore Library's injected domain-rules script accepts window messages from any frame without checking their origin.

On pages matching an institute-configured domain rule, the extension injects a script that listens for postMessage events without verifying who sent them. Any other script or frame sharing that page can use this to make the extension forward analytics data (sent to reporting.myloft.xyz along with the user's stored session token) or add entries to its local domain-rule blacklist.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

Eclat Engineering Pvt. Ltd.v3.2.52Chrome Web Store
20Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Data recipients

reporting.myloft.xyz
Updated 20 September 2026amehmldllgkbechfliekpnankecbgohh