Sandkey

Sandkey

ID: koohoomgojfknaoilpochdceohbebjpn

Supported Languages

πŸ‡ΊπŸ‡ΈUS English

Extension Info & Metadata

Status
Active
Version
1.1.0
Size
0.04 MB
Rating
0.0/5
Reviews
0
Users
5
Type
Extension
Updated
Mar 25, 2026
Category
Developer tools
Price
Free
Featured
No
Visibility
Listed
Mature
No
By Google
No
Trusted
No

Publisher Contextual Analysis

Author
Illegal StudioView Profile
Country
IT
MX records exist
Yes
Domain exists
Yes
Is disposable
No
Is role-based
Yes
Mailbox exists
Yes
Address
Via del Progresso, 16 Canzano, TE 64020 IT
Total Extensions
1
Active
1
Obsolete
0
Listed
1
Unlisted
0
Total Users
5
Screenshot 1

Credential manager for local development environments

Sandkey is the credential manager built for developers, not end users. When you spin up a new local project β€” Laravel, Rails, Django, a Docker stack β€” you always end up typing the same default credentials over and over: admin / admin, root / secret, [email protected] / password. Sandkey remembers them for you and fills them in with one click. Local-first, always. Your credentials never leave your machine. There is no account, no server, no sync, no analytics. Everything is stored in Chrome's local storage and stays there. Sandkey cannot phone home because it has no home to phone. Open source. Sandkey is fully open source and available on GitHub: https://github.com/illegalstudio/sandkey Read the code, audit it, fork it, contribute to it. Built for sandbox domains. Sandkey is designed around the domains developers actually use: localhost, *.test, *.local, *.home.arpa, custom Docker hostnames. It supports wildcard patterns at any depth and port-aware matching β€” localhost:3000 can have different credentials than localhost:8080. Longest-match priority. Configure *.test as a catch-all and *.api.test for a specific project. Sandkey always picks the most specific rule β€” no surprises. Autofill that works everywhere. The autofill dropdown is injected via Shadow DOM, so it never clashes with the page's own styles. It works with React, Vue, Angular, and plain HTML forms β€” including dynamically rendered ones. No bloat. No background service worker. No remote calls. No dependencies. The entire extension is a handful of vanilla JavaScript files.

Item
Type
Severity
Description
<all_urls>
Host
Critical
Broad host access β€” the extension can read/modify content on every website.
Broad Host Permissions
Risk Factor
High
This extension has broad host permissions allowing it to access many or all websites.
Broad Content Script Access
Risk Factor
High
This extension can inject scripts into any website.
storage
Permission
Medium
This permission allows storing data locally in the browser. Rated Medium because it can persist sensitive user data, track user activities over time, and potentially store malicious payloads.
activeTab
Permission
Medium
This permission grants temporary access to the current tab. Rated Medium because it can access current page content when invoked, though limited to user-initiated actions.
URLs
0
IPv4
0
IPv6
0

URLs

View the external URLs this extension communicates with to understand its network activity and data interactions.

Gain full insight into all external connections.

Upgrade for full visibility.

No URLs found

Gain full insight into all external connections.

Upgrade for full visibility.

No IP addresses found
Version
Size
Is Malicious
Findings
Permhash
1.1.0
Latest
0.04 MB
Benign
β€”
1.0.0
0.04 MB
Benign
β€”
Showing 1 to 2 of 10 rows
Rows per page:

Code Diff

Compare extension code between any two versions.

0 changed files (scanned top 25 shared text files)

No comparable text files found between these versions.

Browse and explore files within this extension package

Gain full insight into all external connections.

Upgrade for full visibility.