Chrome Web Store
12Versions
1Code reviewed

No malware found

In code review

Our reviewer read this extension’s code and found no malicious behaviour. Review the permissions below before installing.

What our analysis found

360 Internet Protection, used by 19,000,000 people, showed no malicious code in Extension Auditor's review. Its permissions mean it can read and change data on all websites, can inject scripts into pages and can observe network requests. It comes from a trusted publisher and was last updated in December 2025.

360 Internet Protection is a legitimate browser companion for Qihoo 360's desktop antivirus product. Every behavior observed in source is consistent with the stated purpose: visited URLs are relayed to the locally installed native host (`com.google.chrome.wdwedpro`) for cloud lookups, the anti-tracking module modifies User-Agent headers as a privacy feature (opt-in, disabled by default at `AntiTrack.enable_antitrack = false`), and ` ` is the stock Google Analytics library used for product telemetry — accounting for most of the ML pattern hits (minified exclamation marks, encoded strings, script injection). No data exfiltration to unknown third parties was found; the explicitly only contacts ` ` via the native application, not directly from the extension. The ML score of 0.00 and a clean permhash cluster (0% malware peers) corroborate the benign read. The third-party `removed-from-store` flag and the broad permission set are the only concerns, but neither indicates malice.

360 Internet Protection

360 Internet Protection

ID: glcimepnljoholdmjchkloafkggfoijh

Supported Languages

🇸🇦Arabic
🇨🇳Chinese (Simplified)
🇹🇼Chinese (Traditional)
🇺🇸English
🇫🇷French
🇩🇪German
🇮🇳Hindi
🇮🇹Italian
🇯🇵Japanese
🇵🇹Portuguese
🇷🇺Russian
🇪🇸Spanish
🇹🇷Turkish
🇻🇳Vietnamese

Extension Info & Metadata

Status
Active
Version
2.1.60
Size
0.25 MB
Rating
4.5/5
Reviews
5,600
Users
19,000,000
Type
Extension
Updated
Dec 12, 2025
Category
Accessibility
Price
Free
Featured
No
Visibility
Listed
Mature
No
By Google
No
Trusted
No
This publisherTrack record
1extension
All still listed
Scanned by Extension Auditor — Low RiskDevelopers: embed this badge to link to this report.

Publisher Contextual Analysis

Trusted
Author
https://www.360totalsecurity.com/View Profile
Country
CN
MX records exist
Yes
Domain exists
Yes
Is disposable
No
Is role-based
Yes
Mailbox exists
Yes
Address
酒仙桥路 6号院2号楼 朝阳区, 北京市 100015 CN
Website
Visit
Extensions
1
Active
1
Obsolete
0
Listed
1
Unlisted
0
Users
19,000,000

Screenshots & videos

Screenshot 1
Screenshot 2
Screenshot 3

Install growth

Item
Type
Severity
Description
scripting
Permission
Critical
This permission allows injection and execution of JavaScript on any webpage. Rated Critical because it can modify page content, steal sensitive data, and inject malicious code into any site the extension has access to.
webRequest
Permission
Critical
This permission enables the extension to monitor and analyze all web requests made by the browser. Rated Critical because it can observe all network traffic including sensitive data, track browsing behavior, and gather authentication tokens.
declarativeNetRequestWithHostAccess
Permission
Critical
This permission combines network request modification with host permissions. Rated Critical because it can modify requests for specific domains, potentially targeting sensitive websites with precise attack rules.
<all_urls>
Host
Critical
Broad host access — the extension can read/modify content on every website.
nativeMessaging
Permission
High
This permission enables communication with applications installed on your computer. Rated High because it can exchange data with native programs, potentially exposing system-level information and local files.
webNavigation
Permission
High
This permission enables monitoring of all browser navigation events and transitions. Rated High because it can track every page visit, navigation method, and browsing pattern, potentially exposing sensitive browsing behavior and user activities.
Contextual Risk Factors
Risk Factor
High
The following context increases the overall risk:• 10% increase: Early script execution enables pre-emptive content manipulation
Broad Host Permissions
Risk Factor
High
This extension has broad host permissions allowing it to access many or all websites.
Broad Content Script Access
Risk Factor
High
This extension can inject scripts into any website.
tabs
Permission
Medium
This permission enables tab management and monitoring. Rated Medium because it can track open tabs, access tab metadata, and monitor user browsing patterns.
storage
Permission
Medium
This permission allows storing data locally in the browser. Rated Medium because it can persist sensitive user data, track user activities over time, and potentially store malicious payloads.
activeTab
Permission
Medium
This permission grants temporary access to the current tab. Rated Medium because it can access current page content when invoked, though limited to user-initiated actions.
Early Content Script Execution
Risk Factor
Medium
This extension runs content scripts at document_start.
alarms
Permission
Low
This permission schedules periodic tasks. Rated Low because it can only trigger events at specified times without access to sensitive data.

Each row lists a threat category the scanner evaluates. A checkmark means the review ran and found no matching issues in that category for this version.

  • Data Exfiltration

    Code review completed; no malicious patterns detected for this category.

  • Unauthorized Data Collection

    Code review completed; no malicious patterns detected for this category.

  • Network Interception

    Code review completed; no malicious patterns detected for this category.

  • Code Injection

    Code review completed; no malicious patterns detected for this category.

  • Credential Theft

    Code review completed; no malicious patterns detected for this category.

  • Obfuscation

    Code review completed; no malicious patterns detected for this category.

  • Tracking

    Code review completed; no malicious patterns detected for this category.

  • Privilege Escalation

    Code review completed; no malicious patterns detected for this category.

  • Phishing

    Code review completed; no malicious patterns detected for this category.

  • Remote Code Loading

    Code review completed; no malicious patterns detected for this category.

  • Other

    Code review completed; no malicious patterns detected for this category.

Gain full insight into all external connections.

Upgrade for full visibility.

About this extension

360 Internet Protection

Read the publisher’s full description

This extension is web threat protection of 360 Total Security for Chrome. It's based on the cloud malicious URL database of 360 cloud security center. It can identify malicious URL in real-time and protect you from web threats. The capabilities of anti-fraud, anti-phishing and anti-malicious URL will be enabled once installed. Integrated privacy anti-tracking, disguise your online information, away from the risk of targeted advertising and privacy leakage, so that you have a safe online environment. Note: 1. You need to install latest 360 Total Security to have the above functions. 2. Support Windows Version of 360 Total Security only. Official Website: http://www.360totalsecurity.com/

User reviews

Extension files

Browse and explore files within this extension package

Gain full insight into all external connections.

Upgrade for full visibility.

URLs
21

URLs

View the external URLs this extension communicates with to understand its network activity and data interactions.

No URLs found
No IP addresses found

Gain full insight into all external connections.

Upgrade for full visibility.

Showing 1 to 10 of 20 rows
Rows per page:

Code Diff

Compare extension code between any two versions.

0 changed files detected

No comparable text files found between these versions.

Gain full insight into all external connections.

Upgrade for full visibility.

Popular in Accessibility