Browserpass

Browserpass

ID: naepdomgkenhinolocfifgehidddafch

Supported Languages

🇺🇸English

Extension Info & Metadata

Status
Active
Version
3.12.0
Size
1.07 MB
Rating
4.7/5
Reviews
33
Users
7,000
Type
Extension
Updated
May 31, 2026
Category
Privacy & security
Price
Free
Featured
No
Visibility
Listed
Mature
No
By Google
No
Trusted
No

Publisher Contextual Analysis

Author
browserpass-devView Profile
MX records exist
Yes
Domain exists
Yes
Is disposable
No
Is role-based
No
Mailbox exists
Yes
Total Extensions
2
Active
1
Obsolete
1
Listed
2
Unlisted
0
Total Users
7,372
Screenshot 1

Browser extension for zx2c4's pass (password manager)

Browserpass is a browser extension for Chrome (and Firefox) to retrieve login details from pass (passwordstore.org) straight from your browser. It uses native messaging to talk to a local binary to retrieve the login details in a secure manner. Hit "Ctrl+Shift+L" to open up the password search or click the lock icon , cycle through the logins with TAB and hit ENTER to auto-fill & submit the login form of the current site. This add-on depends on a small binary you'll need to install on your OS. Installation instructions can be found here: https://github.com/browserpass/browserpass-native

Item
Type
Severity
Description
scripting
Permission
Critical
This permission allows injection and execution of JavaScript on any webpage. Rated Critical because it can modify page content, steal sensitive data, and inject malicious code into any site the extension has access to.
webRequest
Permission
Critical
This permission enables the extension to monitor and analyze all web requests made by the browser. Rated Critical because it can observe all network traffic including sensitive data, track browsing behavior, and gather authentication tokens.
webRequestAuthProvider
Permission
Critical
This permission allows the extension to handle authentication requests and modify authentication headers. Rated Critical because it can intercept login credentials, session tokens, and modify authentication flows to compromise accounts.
http://*/*
Host
Critical
Broad host access — the extension can read/modify content on every website.
https://*/*
Host
Critical
Broad host access — the extension can read/modify content on every website.
clipboardRead
Permission
High
This permission allows reading clipboard content. Rated High because it can steal copied passwords, sensitive data, and monitor all content copied to clipboard.
clipboardWrite
Permission
High
This permission allows modification of clipboard content. Rated High because it can inject malicious content into the clipboard, modify copied passwords, and manipulate copied data.
nativeMessaging
Permission
High
This permission enables communication with applications installed on your computer. Rated High because it can exchange data with native programs, potentially exposing system-level information and local files.
offscreen
Permission
High
This permission creates hidden browser documents with full DOM access. Rated High because it can run background operations invisibly, potentially executing malicious code without user awareness.
Contextual Risk Factors
Risk Factor
High
The following context increases the overall risk:• 10% increase: Early script execution enables pre-emptive content manipulation
activeTab
Permission
Medium
This permission grants temporary access to the current tab. Rated Medium because it can access current page content when invoked, though limited to user-initiated actions.
tabs
Permission
Medium
This permission enables tab management and monitoring. Rated Medium because it can track open tabs, access tab metadata, and monitor user browsing patterns.
storage
Permission
Medium
This permission allows storing data locally in the browser. Rated Medium because it can persist sensitive user data, track user activities over time, and potentially store malicious payloads.
Early Content Script Execution
Risk Factor
Medium
This extension runs content scripts at document_start.
alarms
Permission
Low
This permission schedules periodic tasks. Rated Low because it can only trigger events at specified times without access to sensitive data.
notifications
Permission
Low
This permission displays system notifications. Rated Low because it can only show user-visible notifications without accessing system data.
URLs
74
IPv4
4
IPv6
0

URLs

View the external URLs this extension communicates with to understand its network activity and data interactions.

Gain full insight into all external connections.

Upgrade for full visibility.

developer.chrome.com/docs/extensions/reference/api/windowshttps://developer.chrome.com/docs/extensions/reference/api/windows
github.com/browserpass/browserpass-nativehttps://github.com/browserpass/browserpass-native
serverfault.com/a/846523https://serverfault.com/a/846523
invalid.invalid-http://invalid.invalid
en.wikipedia.org/wiki/Base64https://en.wikipedia.org/wiki/Base64#URL_applications
github.com/beatgammit/base64-js/issues/42https://github.com/beatgammit/base64-js/issues/42
github.com/keybase/triplesechttps://github.com/keybase/triplesec
code.google.com/p/crypto-js/https://code.google.com/p/crypto-js/
bitwiseshiftleft.github.io/sjcl/doc/symbols/src/core_gcm.js.htmlhttp://bitwiseshiftleft.github.io/sjcl/doc/symbols/src/core_gcm.js.html
developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Global_Objects/Symbolhttps://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Global_Objects/Symbol#Browser_compatibility
Showing 1 to 10 of 80 rows
Rows per page:

Gain full insight into all external connections.

Upgrade for full visibility.

1.3.132.0
IPv4
-
13.3.3.7
IPv4
-
1.101.3.4
IPv4
-
4.4.3.2
IPv4
-
Showing 1 to 9 of 10 rows
Rows per page:

Code Diff

Compare extension code between any two versions.

0 changed files (scanned top 25 shared text files)

No comparable text files found between these versions.

Browse and explore files within this extension package

Gain full insight into all external connections.

Upgrade for full visibility.