Chrome Web Store
39Versions
1Code reviewed

No malware found

In code review

Our reviewer read this extension’s code and found no malicious behaviour. An automated risk flag was reviewed and overturned.

What our analysis found

Endpoint Verification, used by 10,000,000 people, showed no malicious code in Extension Auditor's review. It comes from a trusted publisher and was last updated in March 2026.

The extension is a Google Workspace enterprise tool for endpoint verification. All powerful permissions (cookies, nativeMessaging, enterprise.deviceAttributes, etc.) are required for its legitimate functionality. Code review found no unauthorized data exfiltration; all network communication goes to Google domains. The high number of security findings in the risk report are permission-based and expected for this type of extension. The ML model's low risk score (0.00) and the publisher's identity corroborate the false positive.

Endpoint Verification

Endpoint Verification Chrome extension security report

ID: callobklhcbilhphinckomhgkigmfocg

Supported Languages

🇺🇸English

Extension Info & Metadata

Status
Active
Version
1.140.0
Size
1.31 MB
Rating
3.4/5
Reviews
95
Users
10,000,000
Type
Extension
Updated
Mar 2, 2026
Category
Workflow & planning
Price
Free
Featured
Yes
Visibility
Listed
Mature
No
By Google
No
Trusted
Yes
This publisherTrack record
27extensions
11 no longer listed
Scanned by Extension Auditor — Low RiskDevelopers: embed this badge to link to this report.

Publisher Contextual Analysis

Trusted
Author
google.com
Country
IE
Address
Gordon House Barrow Street Dublin 4 D04 E5W5 IE
Website
Visit
Extensions
27
Active
14
Obsolete
11
Listed
22
Unlisted
5
Users
22,295,571

Screenshots & videos

Screenshot 1

Install growth

Item
Type
Severity
Description
cookies
Permission
High
This permission provides full access to read and modify browser cookies. Rated High because it can steal session tokens, modify authentication cookies, and compromise accounts across websites.
nativeMessaging
Permission
High
This permission enables communication with applications installed on your computer. Rated High because it can exchange data with native programs, potentially exposing system-level information and local files.
enterprise.deviceAttributes
Permission
High
This permission accesses device hardware information. Rated High because it can fingerprint devices, gather system information, and potentially identify enterprise assets.
enterprise.platformKeys
Permission
High
This permission accesses enterprise platform cryptographic keys. Rated High because it can access enterprise authentication mechanisms and potentially compromise enterprise security.
identity
Permission
High
This permission accesses Chrome identity service and user information. Rated High because it can obtain OAuth tokens, access connected accounts, and impersonate the user in authenticated service.
identity.email
Permission
High
This permission directly accesses the user's email address. Rated High because it reveals personally identifiable information and can be used for tracking or targeting.
platformKeys
Permission
High
This permission accesses platform cryptographic keys. Rated High because it can interact with system certificates, potentially compromising secure communications.
offscreen
Permission
High
This permission creates hidden browser documents with full DOM access. Rated High because it can run background operations invisibly, potentially executing malicious code without user awareness.
Contextual Risk Factors
Risk Factor
High
The following context increases the overall risk:• 20% increase: Access to sensitive domains increases potential impact
storage
Permission
Medium
This permission allows storing data locally in the browser. Rated Medium because it can persist sensitive user data, track user activities over time, and potentially store malicious payloads.
gcm
Permission
Medium
This permission enables Google Cloud Messaging for push notifications. Rated Medium because it can maintain persistent connections, receive external messages, and operate in the background.
*://*.google.com/*
Host
Medium
Host permission — access limited to this URL pattern.
Access to Sensitive Domains
Risk Factor
Medium
This extension requests access to sensitive domains: *://*.google.com/*
idle
Permission
Low
This permission detects system idle state. Rated Low because it only observes user activity state without access to activity details.
alarms
Permission
Low
This permission schedules periodic tasks. Rated Low because it can only trigger events at specified times without access to sensitive data.
enterprise.reportingPrivate
Permission
Unknown
No classification available for this permission.

Each row lists a threat category the scanner evaluates. A checkmark means the review ran and found no matching issues in that category for this version.

  • Data Exfiltration

    Code review completed; no malicious patterns detected for this category.

  • Unauthorized Data Collection

    Code review completed; no malicious patterns detected for this category.

  • Network Interception

    Code review completed; no malicious patterns detected for this category.

  • Code Injection

    Code review completed; no malicious patterns detected for this category.

  • Credential Theft

    Code review completed; no malicious patterns detected for this category.

  • Obfuscation

    Code review completed; no malicious patterns detected for this category.

  • Tracking

    Code review completed; no malicious patterns detected for this category.

  • Privilege Escalation

    Code review completed; no malicious patterns detected for this category.

  • Phishing

    Code review completed; no malicious patterns detected for this category.

  • Remote Code Loading

    Code review completed; no malicious patterns detected for this category.

  • Other

    Code review completed; no malicious patterns detected for this category.

Gain full insight into all external connections.

Upgrade for full visibility.

About this extension

Allows Google Workspace administrators to view laptop and desktop status, including OS, device, and user information.

Read the publisher’s full description

By installing this item, you agree to the Google Terms of Service and Privacy Policy at https://www.google.com/intl/en/policies/. For more information: https://support.google.com/a/users/answer/9018161

User reviews

Extension files

Browse and explore files within this extension package

Gain full insight into all external connections.

Upgrade for full visibility.

URLs
22
IPv4
35

URLs

View the external URLs this extension communicates with to understand its network activity and data interactions.

No URLs found
No IP addresses found

Gain full insight into all external connections.

Upgrade for full visibility.

Version
Size
Verdict
Findings
Permhash
1.139.0
Latest
1.31 MBNot scanned—
4bf3c945c46350322586f577652cea82e113226509d535854db79384b767404b
1.140.0
1.31 MBNo malware found0
4bf3c945c46350322586f577652cea82e113226509d535854db79384b767404b
1.138.0
1.31 MBNot scanned—
4bf3c945c46350322586f577652cea82e113226509d535854db79384b767404b
1.127.0
1.31 MBNot scanned—
4bf3c945c46350322586f577652cea82e113226509d535854db79384b767404b
1.126.0
1.31 MBNot scanned—
6f2a9cb53a61946c2ef1a8d6fc45f0b7c424d2daaf5e07595f0c56f2e015ebd4
1.118.0
1.31 MBNot scanned—
6f2a9cb53a61946c2ef1a8d6fc45f0b7c424d2daaf5e07595f0c56f2e015ebd4
1.117.0
1.31 MBNot scanned—
6f2a9cb53a61946c2ef1a8d6fc45f0b7c424d2daaf5e07595f0c56f2e015ebd4
1.114.0
1.31 MBNot scanned—
6f2a9cb53a61946c2ef1a8d6fc45f0b7c424d2daaf5e07595f0c56f2e015ebd4
1.112.0
1.31 MBNot scanned—
6f2a9cb53a61946c2ef1a8d6fc45f0b7c424d2daaf5e07595f0c56f2e015ebd4
1.90.0
1.30 MBNot scanned—
cad4afbf5574f544d0dfb80ca8a45cf62963c8b27ec517561e4f218235620d16
Showing 1 to 10 of 40 rows
Rows per page:

Code Diff

Compare extension code between any two versions.

0 changed files detected

No comparable text files found between these versions.

Gain full insight into all external connections.

Upgrade for full visibility.