Is Ziplyne Flex Staging Creator safe?

Low risk

Ziplyne Flex Staging Creator overwrites its stored authentication token with data from unauthenticated postMessage events on any page.

This extension injects a content script into every website and listens for 'authentication' postMessage events, but never checks which page sent them. Any web page a user visits can send a message that overwrites the extension's stored creator/player token and user role in chrome.storage.local. That token is then attached as a Bearer credential on the extension's own API calls to flexstagingapi.ziplyne.com.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

Ziplynev7.9.0.0Chrome Web Store
20Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Data recipients

flexstagingapi.ziplyne.com
Updated 20 September 2026eggiooohajanigaphhfhddpnadlnnpok