Chrome Web Store
55Versions
3Code reviewed

No malware found

In code review

Our reviewer read this extension’s code and found no malicious behaviour. Review the permissions below before installing.

1 high-severity finding in this extension’s code

1 high
38 indicators
3 versions analysed

Every finding is verified by a security analyst. Unlock the code evidence, indicators and version history.

Unlock this report — $4.99Start 7-day trial — all reports
One-time payment · Secure checkout by Stripe

What our analysis found

Dex for Chrome - Personal CRM and Rolodex, used by 10,000 people, showed no malicious code in Extension Auditor's review. Our code review reported 1 finding (1 high), led by unauthorized data collection. It comes from a trusted publisher and was last updated in August 2026.

Key findings

  • High

    Unauthorized Data Collection

    On a getCookies message (handler registered at:218 with no sender-origin check), the extension reads the complete cookie jar for.[domain withheld] and.[domain withheld] — the websites table at -872 supplies only the domains ('c_user','xs','sessionid' names are never used as a filter, the filter at matches on domain alone), so HttpOnly session tokens that page JavaScript can never read are included — and forwards them into the requesting tab's content script, which re-broadcasts them to the page with window.postMessage(..., '*'). The destination is first-party (the sink is gated to [domain withheld] via isDexSite()), but authentication credentials are not in the CWS-disclosed collection list, which declares only 'Website content', and full third-party session cookies are account-takeover-grade material; the wildcard postMessage target also exposes them to any other script or iframe present in the Dex page.

Analyst notes

The bundle is a genuine personal-CRM extension: is verbatim InboxSDK (68 'inboxsdk' references, the XHR wrappers at: and the ext-corb-workaround MessagePort at),:1-18 is InboxSDK's standard MAIN-world injection of the packaged, and the only network sink in the reviewed code is a first-party POST to [domain withheld] (:508) for AI message drafting. The signals are circular here: the internal note states the malware label came from a 2026-09-13 bulk malext-feed import that was explicitly 'not an independent code review', and the permhash cluster is almost certainly Dex's own version history carrying that same imported label; chrome-stats likelihood, a trusted-publisher badge and a rating all contradict the malware label. One real issue stands and contradicts a clean bill::246-306 harvests the full [domain withheld] and [domain withheld] cookie jars (filtered by domain only, so HttpOnly session tokens are included) and hands them to the requesting tab, which the (not-supplied) re-broadcasts to the page with window.postMessage(...,'*') — gated to [domain withheld] via isDexSite(), so first-party, but authentication data is not in the CWS disclosure ('Website content' only). Caveat on scope: only 3 of the 7 files listed in were supplied; (~1.79 MB, where most of the counts live) was absent from extract_dir and I verified the cookie sink from the archived v3.0.4 CRX instead, so this verdict is medium, not high, confidence. Also note the prompt's 'bundled manifest' and the risk-engine flags (MV2, document_start, activeTab, xing) describe an older release; this ZIP is MV3, document_end, and matches the live listing apart from [domain withheld] vs host variations.

Dex for Chrome - Personal CRM and Rolodex

Dex for Chrome - Personal CRM and Rolodex Chrome extension security report

ID: amlpnkfionniifnajgcalfndolieichk

Supported Languages

🇺🇸US English

Extension Info & Metadata

Status
Active
Version
3.0.4
Size
0.48 MB
Rating
4.8/5
Reviews
82
Users
10,000
Type
Extension
Updated
Aug 26, 2026
Category
Social networking
Price
Free
Featured
No
Visibility
Listed
Mature
No
By Google
No
Trusted
Yes
This publisherTrack record
1extension
All still listed
Scanned by Extension Auditor — Low RiskDevelopers: embed this badge to link to this report.

Publisher Contextual Analysis

Trusted
Author
Dana HQ Inc
MX records exist
Yes
Domain exists
Yes
Is disposable
No
Is role-based
Yes
Mailbox exists
Yes
Website
Visit
Extensions
1
Active
1
Obsolete
0
Listed
1
Unlisted
0
Users
10,000

You reached today's free scan limit (3/3 unique extensions).

Upgrade for full visibility.

Screenshots & videos

Screenshot 1
Screenshot 2
Screenshot 3
Screenshot 4

Install growth

Item
Type
Severity
Description
Contextual Risk Factors
Risk Factor
High
The following context increases the overall risk:• 20% increase: Access to sensitive domains increases potential impact• 10% increase: Early script execution enables pre-emptive content manipulation• 15% increase: Older manifest version lacks modern security controls
storage
Permission
Medium
This permission allows storing data locally in the browser. Rated Medium because it can persist sensitive user data, track user activities over time, and potentially store malicious payloads.
tabs
Permission
Medium
This permission enables tab management and monitoring. Rated Medium because it can track open tabs, access tab metadata, and monitor user browsing patterns.
activeTab
Permission
Medium
This permission grants temporary access to the current tab. Rated Medium because it can access current page content when invoked, though limited to user-initiated actions.
*://*.linkedin.com/*
Host
Medium
Host permission — access limited to this URL pattern.
*://*.facebook.com/*
Host
Medium
Host permission — access limited to this URL pattern.
*://*.instagram.com/*
Host
Medium
Host permission — access limited to this URL pattern.
*://*.getdex.com/*
Host
Medium
Host permission — access limited to this URL pattern.
*://*.twitter.com/*
Host
Medium
Host permission — access limited to this URL pattern.
*://*.mail.google.com/*
Host
Medium
Host permission — access limited to this URL pattern.
*://*.superhuman.com/*
Host
Medium
Host permission — access limited to this URL pattern.
*://*.xing.com/*
Host
Medium
Host permission — access limited to this URL pattern.
Access to Sensitive Domains
Risk Factor
Medium
This extension requests access to sensitive domains: *://*.linkedin.com/*, *://*.facebook.com/*, *://*.instagram.com/*, *://*.twitter.com/*, *://*.mail.google.com/*, *://*.xing.com/*
Early Content Script Execution
Risk Factor
Medium
This extension runs content scripts at document_start.
Older Manifest Version
Risk Factor
Medium
This extension uses Manifest Version 2
  • 1 high

The file, code excerpt and explanation behind each finding are part of the full report. No conclusion has been withheld — only the evidence. The verdict above already reflects everything found here.

1 high-severity finding in this extension’s code

1 high
38 indicators
3 versions analysed

Every finding is verified by a security analyst. Unlock the code evidence, indicators and version history.

Unlock this report — $4.99Start 7-day trial — all reports
One-time payment · Secure checkout by Stripe

About this extension

Be better at relationships with Dex. Visualize, understand, and manage your relationships for free.

Read the publisher’s full description

Be better at relationships with Dex. Dex reminds you to keep in touch with the people you care about. Easily visualize, understand, and manage all your relationships for free. By installing the extension, you agree to Dex's Terms of Service (getdex.com/termsofservice). ★ Integrate where you need it! - Add Dex to Chrome to manage relationships from Facebook, Messenger, Twitter, Gmail, and more! - No data entry or separate websites needed. ★ Stay in touch better - Configure Dex to send regular reminders: maintain relationships even when life gets busy. - Stay warm with your network and see people you haven’t seen in a while. ★ Remember the important details - Remember the name of your coworker’s daughter? What you did with your friend from college? - Dex makes it easy to remember important details. Be more thoughtful and better at relationships. ★ Become a superconnector - With the Dex Dashboard, organize all your relationships with custom tags and views. - Search through all the notes you’ve taken in one place. Make connections that help your friends and strengthen your relationships.

User reviews

Extension files

Browse and explore files within this extension package

You reached today's free scan limit (3/3 unique extensions).

Upgrade for full visibility.

URLs
38

URLs

View the external URLs this extension communicates with to understand its network activity and data interactions.

No URLs found
No IP addresses found

1 high-severity finding in this extension’s code

1 high
38 indicators
3 versions analysed

Every finding is verified by a security analyst. Unlock the code evidence, indicators and version history.

Unlock this report — $4.99Start 7-day trial — all reports
One-time payment · Secure checkout by Stripe
Version
Size
Verdict
Findings
Permhash
3.0.4
Latest
0.48 MBNo malware found0
2145d59a21412a56b2c215ce369adcc5fdc58743b7407934ec1d6f59a4faccaa
3.0.3
0.48 MBCaution—
2145d59a21412a56b2c215ce369adcc5fdc58743b7407934ec1d6f59a4faccaa
3.0.2
0.48 MBNo malware found0
a17514466c9b61cb26cd82eccf0995075f5747c99a29bd37b49dc0efb56de43e
3.0.1
0.50 MBNot scanned—
e7e8d3df4a8180fe4582d416604a70321e98c2d80a10324e733cbf6e049707cd
2.0.13
5.22 MBCaution—
a17514466c9b61cb26cd82eccf0995075f5747c99a29bd37b49dc0efb56de43e
2.0.12
5.22 MBCaution—
a17514466c9b61cb26cd82eccf0995075f5747c99a29bd37b49dc0efb56de43e
2.0.11
5.22 MBCaution—
a17514466c9b61cb26cd82eccf0995075f5747c99a29bd37b49dc0efb56de43e
2.0.10
5.22 MBCaution—
a17514466c9b61cb26cd82eccf0995075f5747c99a29bd37b49dc0efb56de43e
2.0.9
5.22 MBCaution—
a17514466c9b61cb26cd82eccf0995075f5747c99a29bd37b49dc0efb56de43e
2.0.8
4.93 MBCaution—
a17514466c9b61cb26cd82eccf0995075f5747c99a29bd37b49dc0efb56de43e
Showing 1 to 10 of 60 rows
Rows per page:

Code Diff

Compare extension code between any two versions.

0 changed files detected

No comparable text files found between these versions.

You reached today's free scan limit (3/3 unique extensions).

Upgrade for full visibility.

Popular in Social Networking