Is Whatfix for Shell (Preview Extension) safe?
Whatfix for Shell removes the X-Frame-Options and Content-Security-Policy headers from every page you visit.
A built-in declarativeNetRequest rule (dev-rules.json) strips the X-Frame-Options and Content-Security-Policy response headers from every top-level page and every iframe loaded in the browser, not just the specific vendor domains (like ariba.com or docusign.com) where Whatfix's own walkthrough widget runs. The rule matches all URLs unconditionally and is enabled by default, so any site's clickjacking and script-injection protections are weakened for as long as the extension is installed.
Part of this rating comes from analysis signals we haven't published as detailed findings yet.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.