Chrome Web Store
7Versions
1Code reviewed

No malware found

In code review

Our reviewer read this extension’s code and found no malicious behaviour. An automated risk flag was reviewed and overturned.

What our analysis found

seats.aero, used by 100,000 people, showed no malicious code in Extension Auditor's review. It comes from a trusted publisher and was last updated in August 2026.

All network requests originate from seats.aero's own backend APIs (` /*`, ` `). The interception in and sends intercepted flight-search responses via `window.postMessage` to the same-origin page only — not to any external server — and the intercepted data is used exclusively to match award prices from the publisher's own service. No third-party analytics, tracking, or exfiltration destinations appear anywhere in the code. The high `js_innerhtml`/`js_appendchild` counts are attributable to framework rendering, and the large bundle size includes the entire Vue runtime.

seats.aero

seats.aero

ID: oedchdidbnokclkbokgpilmeabomahlj

Supported Languages

🇺🇸US English

Extension Info & Metadata

Status
Active
Version
1.3.43
Size
0.72 MB
Rating
5.0/5
Reviews
18
Users
100,000
Type
Extension
Updated
Aug 28, 2026
Category
Travel
Price
Paid
Featured
No
Visibility
Listed
Mature
No
By Google
No
Trusted
Yes
This publisherTrack record
3extensions
All still listed
Scanned by Extension Auditor — Low RiskDevelopers: embed this badge to link to this report.

Publisher Contextual Analysis

Trusted
Author
Travel Data CorporationView Profile
MX records exist
Yes
Domain exists
Yes
Is disposable
No
Is role-based
Yes
Mailbox exists
Yes
Website
Visit
Extensions
3
Active
2
Obsolete
0
Listed
3
Unlisted
0
Users
100,652

Screenshots & videos

Screenshot 1
Screenshot 2
Screenshot 3
Screenshot 4

Install growth

Item
Type
Severity
Description
Contextual Risk Factors
Risk Factor
High
The following context increases the overall risk:• 10% increase: Early script execution enables pre-emptive content manipulation
activeTab
Permission
Medium
This permission grants temporary access to the current tab. Rated Medium because it can access current page content when invoked, though limited to user-initiated actions.
storage
Permission
Medium
This permission allows storing data locally in the browser. Rated Medium because it can persist sensitive user data, track user activities over time, and potentially store malicious payloads.
https://seats.aero/*
Host
Medium
Host permission — access limited to this URL pattern.
Early Content Script Execution
Risk Factor
Medium
This extension runs content scripts at document_start.

Each row lists a threat category the scanner evaluates. A checkmark means the review ran and found no matching issues in that category for this version.

  • Data Exfiltration

    Code review completed; no malicious patterns detected for this category.

  • Unauthorized Data Collection

    Code review completed; no malicious patterns detected for this category.

  • Network Interception

    Code review completed; no malicious patterns detected for this category.

  • Code Injection

    Code review completed; no malicious patterns detected for this category.

  • Credential Theft

    Code review completed; no malicious patterns detected for this category.

  • Obfuscation

    Code review completed; no malicious patterns detected for this category.

  • Tracking

    Code review completed; no malicious patterns detected for this category.

  • Privilege Escalation

    Code review completed; no malicious patterns detected for this category.

  • Phishing

    Code review completed; no malicious patterns detected for this category.

  • Remote Code Loading

    Code review completed; no malicious patterns detected for this category.

  • Other

    Code review completed; no malicious patterns detected for this category.

Gain full insight into all external connections.

Upgrade for full visibility.

About this extension

Easily search for award availability on Google Flights, Chase Travel, and Amex Travel.

User reviews

Extension files

Browse and explore files within this extension package

Gain full insight into all external connections.

Upgrade for full visibility.

URLs
31
IPv4
1

URLs

View the external URLs this extension communicates with to understand its network activity and data interactions.

No URLs found
No IP addresses found

Gain full insight into all external connections.

Upgrade for full visibility.

Showing 1 to 7 of 10 rows
Rows per page:

Code Diff

Compare extension code between any two versions.

0 changed files detected

No comparable text files found between these versions.

Gain full insight into all external connections.

Upgrade for full visibility.