Is Vonage® Integration Suite safe?
Clean risk
Vonage Integration Suite bundles a hardcoded OAuth client_secret that allows any installer to perform token exchanges against the Vonage API.
The extension's JavaScript bundle contains a static OAuth client_secret used when refreshing or exchanging authorization codes against the Vonage API endpoint at extensions.gunify.vonage.com/v2/auth/token. Because the secret is embedded in plain text within the distributed .crx file, any party who downloads or installs the extension can extract it and submit OAuth requests as the registered client. No user interaction beyond installation is required to access the credential.
0Risk
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Data recipients
extensions.gunify.vonage.com