Chrome Web Store
29Versions
1Code reviewed

No malware found

In code review (v1.0.239.0)

Our reviewer read version 1.0.239.0 — the most recent version we have reviewed — and found no malicious behaviour. The version shown here has not been individually reviewed yet.

What our analysis found

Test & Feedback, used by 200,000 people, showed no malicious code in Extension Auditor's review. Its permissions mean it can read and change data on all websites. It comes from a trusted publisher and was last updated in September 2026.

Analyst notes

The extension is a legitimate testing and feedback tool by Microsoft. Broad permissions are required for screen capture, action logging, and Azure DevOps integration. No exfiltration to unauthorized third parties was found in the provided source; telemetry likely flows to Microsoft's own endpoints. The low ML risk score (0.00), zero third-party likelihood, and the publisher's strong reputation all indicate a false positive. The manifest mismatch (bundled v2 vs. published v3) is a hygiene issue, not malice.

Test & Feedback

Test & Feedback Chrome extension security report

ID: gnldpbnocfnlkkicnaplmkaphfdnlplb

Supported Languages

🇺🇸US English

Extension Info & Metadata

Status
Active
Version
1.0.279.4
Size
1.88 MB
Rating
4.2/5
Reviews
176
Users
200,000
Type
Extension
Updated
Sep 9, 2026
Category
Workflow & planning
Price
Free
Featured
Yes
Visibility
Listed
Mature
No
By Google
No
Trusted
Yes
This publisherTrack record
877extensions
41 no longer listed
Scanned by Extension Auditor — Low RiskDevelopers: embed this badge to link to this report.

Publisher Contextual Analysis

Trusted
Author
Microsoft Corporation
Country
US
MX records exist
Yes
Domain exists
Yes
Is disposable
No
Is role-based
No
Mailbox exists
Yes
Address
One Microsoft Way Redmond, WA 98052 US
Website
Visit
Extensions
877
Active
820
Obsolete
41
Listed
859
Unlisted
18
Users
1,163,809,589

Screenshots & videos

Screenshot 2
Screenshot 3
Screenshot 4

Install growth

Item
Type
Severity
Description
userScripts
Permission
Critical
This permission allows registration of arbitrary user scripts that run in a page's main world. Rated Critical because the scripts execute with full access to page JavaScript, can be updated at runtime from remote code, and bypass the isolated world that normally contains content scripts.
<all_urls>
Host
Critical
Broad host access — the extension can read/modify content on every website.
clipboardRead
Permission
High
This permission allows reading clipboard content. Rated High because it can steal copied passwords, sensitive data, and monitor all content copied to clipboard.
desktopCapture
Permission
High
This permission captures content from your desktop screens. Rated High because it can record sensitive information from any window, capture passwords, and monitor user activity.
webNavigation
Permission
High
This permission enables monitoring of all browser navigation events and transitions. Rated High because it can track every page visit, navigation method, and browsing pattern, potentially exposing sensitive browsing behavior and user activities.
offscreen
Permission
High
This permission creates hidden browser documents with full DOM access. Rated High because it can run background operations invisibly, potentially executing malicious code without user awareness.
tabCapture
Permission
High
This permission captures content and audio from browser tabs. Rated High because it can record sensitive web content, capture form input, and monitor user interactions.
Contextual Risk Factors
Risk Factor
High
The following context increases the overall risk: • 10% increase: About:blank access enables potential sandbox escape vectors
Broad Host Permissions
Risk Factor
High
This extension has broad host permissions allowing it to access many or all websites.
Broad Content Script Access
Risk Factor
High
This extension can inject scripts into any website.
activeTab
Permission
Medium
This permission grants temporary access to the current tab. Rated Medium because it can access current page content when invoked, though limited to user-initiated actions.
tabs
Permission
Medium
This permission enables tab management and monitoring. Rated Medium because it can track open tabs, access tab metadata, and monitor user browsing patterns.
storage
Permission
Medium
This permission allows storing data locally in the browser. Rated Medium because it can persist sensitive user data, track user activities over time, and potentially store malicious payloads.
unlimitedStorage
Permission
Medium
This permission removes storage quota restrictions. Rated Medium because it can store large amounts of user data without limits, potentially impacting browser performance and storing extensive tracking data.
system.cpu
Permission
Medium
This permission provides access to CPU usage and information. Rated Medium because it can monitor system performance, detect other applications, and potentially identify user activities.
system.memory
Permission
Medium
This permission accesses system memory information. Rated Medium because it can monitor memory usage patterns, detect other applications, and gather system state information.
background
Permission
Medium
This permission allows continuous background operation. Rated Medium because it can perform actions without user awareness, consume system resources, and maintain persistent connections.
About:blank Access
Risk Factor
Medium
This extension can run content scripts in about:blank pages.
system.display
Permission
Low
This permission reads display configuration. Rated Low because it only accesses screen properties without content access.
alarms
Permission
Low
This permission schedules periodic tasks. Rated Low because it can only trigger events at specified times without access to sensitive data.

About this extension

Now everyone on the team can own quality. Capture findings, create issues, and collaborate with the team, directly from the browser.

Read the publisher’s full description

Test & Feedback - Now everyone on the team can own quality. Capture findings, create issues, and collaborate with the team, directly from the browser. Everyone in the team, be it product owners, developers, testers, UX designers etc., can now test their web-apps and give feedback, all directly from the browser on any platform: Windows, Mac, or Linux. All kinds of teams will now be able to drive quality in 3 easy steps – capture, create & collaborate. Capture - Take notes, screenshots with annotations, and screen recordings to capture problems. Automatically include rich data like user actions (as an image action log), page load data, and system information. Create - Create bugs, tasks, and feedback response work items to send feedback or report problems. Create test cases quickly based on the image action log while you explore your app. Automatically attach all your captured information. Collaborate - Work offline in standalone mode, then export your session to share findings with your team. For more integrated experiences with end-to-end traceability, connect to Azure DevOps Services or to Team Foundation Server 2015 or later. For example, you can explore user stories directly from the board, manage all feedback requests received, and easily track bugs, tasks and other work-items. To view completed exploratory sessions and get insights across all completed sessions, for example, details about sessions and work items that are created, explored, and weren’t explored, plus other data, go to your exploratory testing insights page. You can use the extension for FREE in these modes: Standalone and Connected Standalone Mode: Available to everyone. Any team, large or small, can use standalone mode to capture issues using screenshots with inline annotations and notes and then share the results using a session report. No connection to Azure DevOps Services or Team Foundation Server required. Connected Mode: Connect to Azure DevOps Services/Team Foundation Server to drive your exploratory testing and feedback flows. - Users with Basic access: Full capture and create capabilities to submit bugs, tasks and test cases. Includes collaboration capabilities like end-to-end traceability, rich insights across completed exploratory sessions, simplified bug/task tracking & triaging, and so on. - Users with Stakeholder access: Full capture and create capabilities, except for test cases, to submit feedback and respond to feedback requests from your team. Feedback experiences are available in Team Services and TFS 2017 or later only. Learn more https://docs.microsoft.com/en-us/azure/devops/test/perform-exploratory-tests?view=vsts

User reviews

Extension files

Browse and explore files within this extension package

Gain full insight into all external connections.

Upgrade for full visibility.

No network indicators were extracted from this version.

Version
Size
Verdict
Findings
Permhash
1.0.279.4
Latest
1.88 MBNot scanned—
53bf308e26f15252ef7b1bd590724179dd8b85efb34a074ffa2569aec30e3f17
1.0.278.2
1.88 MBNot scanned—
53bf308e26f15252ef7b1bd590724179dd8b85efb34a074ffa2569aec30e3f17
1.0.276.2
1.87 MBNot scanned—
f8f128e97e318b00dc82b1cc65b8e6bc7091ea2116e2141c46970808892db5ad
1.0.275.4
1.87 MBNot scanned—
f8f128e97e318b00dc82b1cc65b8e6bc7091ea2116e2141c46970808892db5ad
1.0.275.3
1.87 MBNot scanned—
f8f128e97e318b00dc82b1cc65b8e6bc7091ea2116e2141c46970808892db5ad
1.0.275.2
1.87 MBNot scanned—
f8f128e97e318b00dc82b1cc65b8e6bc7091ea2116e2141c46970808892db5ad
1.0.275.1
1.87 MBNot scanned—
f8f128e97e318b00dc82b1cc65b8e6bc7091ea2116e2141c46970808892db5ad
1.0.274.1
1.87 MBNot scanned—
f8f128e97e318b00dc82b1cc65b8e6bc7091ea2116e2141c46970808892db5ad
1.0.271.1
1.83 MBNot scanned—
f8f128e97e318b00dc82b1cc65b8e6bc7091ea2116e2141c46970808892db5ad
1.0.270.2
1.83 MBNot scanned—
f8f128e97e318b00dc82b1cc65b8e6bc7091ea2116e2141c46970808892db5ad
Showing 1 to 10 of 30 rows
Rows per page:

Code Diff

Compare extension code between any two versions.

0 changed files detected

No comparable text files found between these versions.

Gain full insight into all external connections.

Upgrade for full visibility.

More from Microsoft Corporation

Popular in Workflow & Planning