Is "Draftback" on Chrome Web Store Safe to Install?
Draftback is a Chrome extension that lets you replay the revision history of any Google Doc you can edit. It’s mostly used by teachers to detect plagiarism and to find out when students are using ChatGPT. It has more than 500,000 users. * Draftback lets you play, pause, and rewind a Google Doc’s revision history. It can be used retroactively on existing documents. * After you install the extension, a Draftback button appears in the toolbar in Google Docs. Click to see the doc's full replay. Pause, rewind, skip ahead—you can even play back at actual speed, as if looking over the author's shoulder. * A page shows you at-a-glance insights into writing patterns and time spent. For more information, see draftback.com 30 DAY FREE TRIAL - NO CREDIT CARD REQUIRED You can try Draftback free for 30 days, with no credit card required. Just try it right away and take your time seeing whether it's useful to you. WHAT EDUCATORS ARE SAYING “I have been relying on draftback for the past couple of years as a tool to monitor my student writing - to say that this app has been a game changer, not just for me, but for my colleagues AND students, is not giving it enough credit. Students have become better writers as they realize that their work is being checked for AI use, and my colleagues and I have seen huge increases in their learning and skills as a result.” — AP World History teacher, Allenton, PA “My teachers, especially my English teachers, use your Draftback Chrome extension and it has become invaluable to their teaching and their student's learning. It is a wonderful way for them to keep up with students' writing to evaluate the writing process, not just the final outcome.” — Technology Specialist, Birmingham, AL “At the school where I teach, we have determined that it is the only tool we can find that allows us to determine if AI plagiarism using Grammarly or ChatGPT is taking place, by seeing whole blocks of text be replaced faster than they could be re-written. We are considering requiring all typed work to be submitted in the original Google Doc so Draftback can see the changes. Congratulations on inventing exactly the tool every teacher needs now.” — Private school administrator, Portland, OR PRIVACY POLICY Draftback was designed to be as careful as possible about user privacy. No document data is collected by or sent to any remote service by the extension. All such data is stored locally on the user’s own computer, by their Chrome browser, and is only stored there so that future replays of an already-replayed document will go faster. (Draftback is a Chrome Extension instead of a standalone app specifically so that it doesn't get access to sensitive document data.) No one, including the extension’s developer, has access to any document processed by Draftback or to its revision history. The extension uses Google Analytics; this data is anonymized and doesn't include personally identifiable information. To manage subscriptions and free trials, the extension does collect the active user’s email address and a unique id identifying their browser, but only after the user has explicitly consented to share their email. Draftback will then “phone home” when it loads to find out if the given email address / id is a subscriber or within a free trial window. (Note that the extension does not collect the email address of document authors, if these are different from the active user.) It's possible that Google itself collects some user data on every one of its extensions, in which case Draftback wouldn't be an exception. OTHER NOTES - With Draftback, your data is kept entirely private. Draftback was purposely designed so that you could play back your own docs without having to share them with a third party. This is -your- data; Draftback just lets you see it in a new way. - Draftback only needs access to docs.google.com to get the revision data for playback—but that data never leaves your own browser. It also uses this access to get your email address from the Docs page if the regular "Sign in with Google" flow fails. SUPPORT AND FEEDBACK Contact [email protected]
Risk Assessment
Analyzed495 security findings detected across all analyzers
Chrome extension requesting 5 permissions
Severity Breakdown
Finding Categories
YARA Rules Matched
9 rules(50 hits)Requested Permissions
5 permissionsAccess your identity and sign-in tokens
About This Extension
Detailed Findings
53 totalYARA Rule Matches
9 rulesIndicators of Compromise
Network indicators, suspicious strings, and potential IoCs extracted during analysis
All Indicators · 438
detected Domain: this.offset.top XIOC detected Domain: this.offset.top
extracted_from_files
detected Domain: p.call XIOC detected Domain: p.call
extracted_from_files
detected Domain: g.call XIOC detected Domain: g.call
extracted_from_files
detected URL: http://purl.eligrey.com/github/classList.js/blob/master/classList.js XIOC detected URL: http://purl.eligrey.com/github/classList.js/blob/master/classList.js
extracted_from_files
detected URL: http://www.w3.org/2000/svg XIOC detected URL: http://www.w3.org/2000/svg
extracted_from_files
detected MD5 Hash: 7FE7C837565711E39964B5CF19ADE07A XIOC detected MD5 Hash: 7FE7C837565711E39964B5CF19ADE07A
extracted_from_files
detected MD5 Hash: 7FE7C834565711E39964B5CF19ADE07A XIOC detected MD5 Hash: 7FE7C834565711E39964B5CF19ADE07A
extracted_from_files
detected MD5 Hash: 7FE7C835565711E39964B5CF19ADE07A XIOC detected MD5 Hash: 7FE7C835565711E39964B5CF19ADE07A
extracted_from_files
detected URL: http://en.wikipedia.org/wiki/ISO_week_date#Calculating_a_date_given_the_year.2C_week_number_and_weekday XIOC detected URL: http://en.wikipedia.org/wiki/ISO_week_date#Calculating_a_date_given_the_year.2C_week_number_and_weekday
extracted_from_files
detected URL: https://github.com/moment/moment/issues/1423 XIOC detected URL: https://github.com/moment/moment/issues/1423
extracted_from_files
detected URL: https://github.com/moment/moment/issues/1407 XIOC detected URL: https://github.com/moment/moment/issues/1407
extracted_from_files
detected URL: https://github.com/moment/moment/issues/1548', XIOC detected URL: https://github.com/moment/moment/issues/1548',
extracted_from_files
detected URL: https://github.com/moment/moment/pull/1871 XIOC detected URL: https://github.com/moment/moment/pull/1871
extracted_from_files
detected URL: https://github.com/dordille/moment-isoduration/blob/master/moment.isoduration.js XIOC detected URL: https://github.com/dordille/moment-isoduration/blob/master/moment.isoduration.js
extracted_from_files
detected URL: https://draftback.com XIOC detected URL: https://draftback.com
extracted_from_files
detected URL: https://clients2.google.com/service/update2/crx XIOC detected URL: https://clients2.google.com/service/update2/crx
extracted_from_files
detected URL: https://www.googleapis.com/auth/userinfo.email XIOC detected URL: https://www.googleapis.com/auth/userinfo.email
extracted_from_files
detected URL: https://accounts.draftback.com/* XIOC detected URL: https://accounts.draftback.com/*
extracted_from_files
detected URL: http://docs.closure-library.googlecode.com/git/closure_goog_date_date.js.source.html XIOC detected URL: http://docs.closure-library.googlecode.com/git/closure_goog_date_date.js.source.html
extracted_from_files
detected URL: http://jsperf.com/left-zero-filling XIOC detected URL: http://jsperf.com/left-zero-filling
extracted_from_files
detected URL: http://stackoverflow.com/questions/3561493/is-there-a-regexp-escape-function-in-javascript XIOC detected URL: http://stackoverflow.com/questions/3561493/is-there-a-regexp-escape-function-in-javascript
extracted_from_files
detected URL: http://stackoverflow.com/questions/181348/instantiating-a-javascript-object-by-calling-prototype-constructor-apply XIOC detected URL: http://stackoverflow.com/questions/181348/instantiating-a-javascript-object-by-calling-prototype-constructor-apply
extracted_from_files
detected URL: http://api.jqueryui.com/mouse/ XIOC detected URL: http://api.jqueryui.com/mouse/
extracted_from_files
detected URL: http://api.jqueryui.com/draggable/ XIOC detected URL: http://api.jqueryui.com/draggable/
extracted_from_files
detected URL: http://bugs.jqueryui.com/ticket/9446 XIOC detected URL: http://bugs.jqueryui.com/ticket/9446
extracted_from_files
detected URL: http://api.jqueryui.com/resizable/ XIOC detected URL: http://api.jqueryui.com/resizable/
extracted_from_files
detected URL: http://api.jqueryui.com/progressbar/ XIOC detected URL: http://api.jqueryui.com/progressbar/
extracted_from_files
detected URL: http://api.jqueryui.com/slider/ XIOC detected URL: http://api.jqueryui.com/slider/
extracted_from_files
detected URL: http://flesler.blogspot.com XIOC detected URL: http://flesler.blogspot.com
extracted_from_files
detected URL: http://docs.jquery.com/UI/Menu#theming XIOC detected URL: http://docs.jquery.com/UI/Menu#theming
extracted_from_files
detected URL: http://jqueryui.com XIOC detected URL: http://jqueryui.com
extracted_from_files
detected URL: http://api.jqueryui.com/category/ui-core/ XIOC detected URL: http://api.jqueryui.com/category/ui-core/
extracted_from_files
detected URL: http://bugs.jquery.com/ticket/9413) XIOC detected URL: http://bugs.jquery.com/ticket/9413)
extracted_from_files
detected URL: http://api.jqueryui.com/jQuery.widget/ XIOC detected URL: http://api.jqueryui.com/jQuery.widget/
extracted_from_files
detected URL: http://bugs.jquery.com/ticket/8235 XIOC detected URL: http://bugs.jquery.com/ticket/8235
extracted_from_files
detected URL: http://bugs.jquery.com/ticket/9413 XIOC detected URL: http://bugs.jquery.com/ticket/9413
extracted_from_files
detected URL: http://purl.org/dc/elements/1.1/ XIOC detected URL: http://purl.org/dc/elements/1.1/
extracted_from_files
detected URL: http://ns.adobe.com/photoshop/1.0/ XIOC detected URL: http://ns.adobe.com/photoshop/1.0/
extracted_from_files
detected URL: http://ns.adobe.com/tiff/1.0/ XIOC detected URL: http://ns.adobe.com/tiff/1.0/
extracted_from_files
detected URL: http://ns.adobe.com/exif/1.0/ XIOC detected URL: http://ns.adobe.com/exif/1.0/
extracted_from_files
detected URL: https://github.com/jquery/jquery-ui XIOC detected URL: https://github.com/jquery/jquery-ui
extracted_from_files
detected URL: http://jqueryui.com/about) XIOC detected URL: http://jqueryui.com/about)
extracted_from_files
detected URL: http://jquery.org/license XIOC detected URL: http://jquery.org/license
extracted_from_files
detected URL: https://draftback.com/?ref=$ XIOC detected URL: https://draftback.com/?ref=$
extracted_from_files
detected URL: http://www.w3.org/1999/02/22-rdf-syntax-ns# XIOC detected URL: http://www.w3.org/1999/02/22-rdf-syntax-ns#
extracted_from_files
detected URL: http://ns.adobe.com/xap/1.0/ XIOC detected URL: http://ns.adobe.com/xap/1.0/
extracted_from_files
detected URL: http://ns.adobe.com/xap/1.0/mm/ XIOC detected URL: http://ns.adobe.com/xap/1.0/mm/
extracted_from_files
detected URL: http://ns.adobe.com/xap/1.0/sType/ResourceRef# XIOC detected URL: http://ns.adobe.com/xap/1.0/sType/ResourceRef#
extracted_from_files
detected URL: http://ns.adobe.com/xap/1.0/sType/ResourceEvent# XIOC detected URL: http://ns.adobe.com/xap/1.0/sType/ResourceEvent#
extracted_from_files
detected Domain: tostring.call XIOC detected Domain: tostring.call
extracted_from_files
detected Domain: github.com XIOC detected Domain: github.com
extracted_from_files
detected IP: ::4 XIOC detected IP: ::4
extracted_from_files
detected IP: ::b XIOC detected IP: ::b
extracted_from_files
detected IP: 4.4.3.2 XIOC detected IP: 4.4.3.2
extracted_from_files
detected IP: 9:: XIOC detected IP: 9::
extracted_from_files
detected IP: 8:: XIOC detected IP: 8::
extracted_from_files
detected Domain: eachfn.map XIOC detected Domain: eachfn.map
extracted_from_files
detected Domain: iterator.next XIOC detected Domain: iterator.next
extracted_from_files
detected Domain: async.auto XIOC detected Domain: async.auto
extracted_from_files
detected Domain: async.select XIOC detected Domain: async.select
extracted_from_files
detected Domain: async.map XIOC detected Domain: async.map
extracted_from_files
detected Domain: array.prototype.slice.call XIOC detected Domain: array.prototype.slice.call
extracted_from_files
detected Domain: arr.map XIOC detected Domain: arr.map
extracted_from_files
detected Domain: www.googleapis.com XIOC detected Domain: www.googleapis.com
extracted_from_files
detected Domain: accounts.draftback.com XIOC detected Domain: accounts.draftback.com
extracted_from_files
detected Domain: array.prototype.reverse.call XIOC detected Domain: array.prototype.reverse.call
extracted_from_files
detected Domain: async.info XIOC detected Domain: async.info
extracted_from_files
detected Domain: task.data XIOC detected Domain: task.data
extracted_from_files
detected Domain: fn.next XIOC detected Domain: fn.next
extracted_from_files
detected Domain: callback.call XIOC detected Domain: callback.call
extracted_from_files
detected Domain: docs.google.com XIOC detected Domain: docs.google.com
extracted_from_files
detected Domain: t.tab XIOC detected Domain: t.tab
extracted_from_files
detected Domain: e.indexeddb.open XIOC detected Domain: e.indexeddb.open
extracted_from_files
detected Domain: t.si XIOC detected Domain: t.si
extracted_from_files
detected Domain: e.si XIOC detected Domain: e.si
extracted_from_files
detected Domain: e.tab XIOC detected Domain: e.tab
extracted_from_files
detected Domain: e.windows XIOC detected Domain: e.windows
extracted_from_files
detected Domain: www.w3.org XIOC detected Domain: www.w3.org
extracted_from_files
detected Domain: e.data XIOC detected Domain: e.data
extracted_from_files
detected Domain: e.map XIOC detected Domain: e.map
extracted_from_files
detected Domain: e.email XIOC detected Domain: e.email
extracted_from_files
detected Domain: indexeddb.open XIOC detected Domain: indexeddb.open
extracted_from_files
detected Domain: e.id XIOC detected Domain: e.id
extracted_from_files
detected Domain: t.ei-t.si XIOC detected Domain: t.ei-t.si
extracted_from_files
detected Domain: o.error.call XIOC detected Domain: o.error.call
extracted_from_files
detected Domain: bo.style XIOC detected Domain: bo.style
extracted_from_files
detected Domain: mo.select XIOC detected Domain: mo.select
extracted_from_files
detected Domain: e.call XIOC detected Domain: e.call
extracted_from_files
detected Domain: r.call XIOC detected Domain: r.call
extracted_from_files
detected Domain: n.space XIOC detected Domain: n.space
extracted_from_files
detected Domain: u.target XIOC detected Domain: u.target
extracted_from_files
detected Domain: n.next XIOC detected Domain: n.next
extracted_from_files
detected Domain: xa.next XIOC detected Domain: xa.next
extracted_from_files
detected Domain: date.now XIOC detected Domain: date.now
extracted_from_files
detected Domain: o.beforesend.call XIOC detected Domain: o.beforesend.call
extracted_from_files
detected Domain: c.open XIOC detected Domain: c.open
extracted_from_files
detected Domain: o.progress.call XIOC detected Domain: o.progress.call
extracted_from_files
detected Domain: o.load.call XIOC detected Domain: o.load.call
extracted_from_files
detected Domain: r.map XIOC detected Domain: r.map
extracted_from_files
detected Domain: t.center XIOC detected Domain: t.center
extracted_from_files
detected Domain: t.stream XIOC detected Domain: t.stream
extracted_from_files
detected Domain: this.stream XIOC detected Domain: this.stream
extracted_from_files
detected Domain: u.next XIOC detected Domain: u.next
extracted_from_files
detected Domain: s.next XIOC detected Domain: s.next
extracted_from_files
detected Domain: t.next XIOC detected Domain: t.next
extracted_from_files
detected Domain: i.cx XIOC detected Domain: i.cx
extracted_from_files
detected Domain: n.py XIOC detected Domain: n.py
extracted_from_files
detected Domain: trigger.call XIOC detected Domain: trigger.call
extracted_from_files
detected Domain: inst.options.snap.snap.call XIOC detected Domain: inst.options.snap.snap.call
extracted_from_files
detected Domain: sortable.offset.click XIOC detected Domain: sortable.offset.click
extracted_from_files
detected Domain: u.call XIOC detected Domain: u.call
extracted_from_files
detected Domain: n.target XIOC detected Domain: n.target
extracted_from_files
detected Domain: b.call XIOC detected Domain: b.call
extracted_from_files
detected Domain: x.call XIOC detected Domain: x.call
extracted_from_files
detected Domain: o.call XIOC detected Domain: o.call
extracted_from_files
detected Domain: t.map XIOC detected Domain: t.map
extracted_from_files
detected Domain: n.cy XIOC detected Domain: n.cy
extracted_from_files
detected Domain: n.cx XIOC detected Domain: n.cx
extracted_from_files
detected Domain: i.cy XIOC detected Domain: i.cy
extracted_from_files
detected Domain: ao.call XIOC detected Domain: ao.call
extracted_from_files
detected Domain: ko.call XIOC detected Domain: ko.call
extracted_from_files
detected Domain: yo.call XIOC detected Domain: yo.call
extracted_from_files
detected Domain: o.event.end.call XIOC detected Domain: o.event.end.call
extracted_from_files
detected Domain: o.event.start.call XIOC detected Domain: o.event.start.call
extracted_from_files
detected Domain: n.id XIOC detected Domain: n.id
extracted_from_files
detected Domain: w.call XIOC detected Domain: w.call
extracted_from_files
detected Domain: po.call XIOC detected Domain: po.call
extracted_from_files
detected Domain: i.map XIOC detected Domain: i.map
extracted_from_files
detected Domain: mo.map XIOC detected Domain: mo.map
extracted_from_files
detected Domain: mo.zip XIOC detected Domain: mo.zip
extracted_from_files
detected Domain: n.call XIOC detected Domain: n.call
extracted_from_files
detected Domain: t.call XIOC detected Domain: t.call
extracted_from_files
detected Domain: to.call XIOC detected Domain: to.call
extracted_from_files
detected Domain: ro.call XIOC detected Domain: ro.call
extracted_from_files
detected Domain: this.property XIOC detected Domain: this.property
extracted_from_files
detected Domain: ro.data XIOC detected Domain: ro.data
extracted_from_files
detected Domain: this.select XIOC detected Domain: this.select
extracted_from_files
detected Domain: ro.property XIOC detected Domain: ro.property
extracted_from_files
detected Domain: ro.style XIOC detected Domain: ro.style
extracted_from_files
detected Domain: ro.select XIOC detected Domain: ro.select
extracted_from_files
detected Domain: u.map XIOC detected Domain: u.map
extracted_from_files
detected Domain: n.center XIOC detected Domain: n.center
extracted_from_files
detected Domain: z.call XIOC detected Domain: z.call
extracted_from_files
detected Domain: mo.event.target XIOC detected Domain: mo.event.target
extracted_from_files
detected Domain: ro.insert.call XIOC detected Domain: ro.insert.call
extracted_from_files
detected Domain: io.select XIOC detected Domain: io.select
extracted_from_files
detected Domain: io.call XIOC detected Domain: io.call
extracted_from_files
detected Domain: mo.geo.circle XIOC detected Domain: mo.geo.circle
extracted_from_files
detected Domain: a.stream XIOC detected Domain: a.stream
extracted_from_files
detected Domain: o.stream XIOC detected Domain: o.stream
extracted_from_files
detected Domain: i.stream XIOC detected Domain: i.stream
extracted_from_files
detected Domain: n.stream XIOC detected Domain: n.stream
extracted_from_files
detected Domain: mo.geo.stream XIOC detected Domain: mo.geo.stream
extracted_from_files
detected Domain: ma.next XIOC detected Domain: ma.next
extracted_from_files
detected Domain: n.data XIOC detected Domain: n.data
extracted_from_files
detected Domain: i.call XIOC detected Domain: i.call
extracted_from_files
detected Domain: a.map XIOC detected Domain: a.map
extracted_from_files
detected Domain: l.call XIOC detected Domain: l.call
extracted_from_files
detected Domain: c.call XIOC detected Domain: c.call
extracted_from_files
detected Domain: v.call XIOC detected Domain: v.call
extracted_from_files
detected Domain: d.call XIOC detected Domain: d.call
extracted_from_files
detected Domain: f.call XIOC detected Domain: f.call
extracted_from_files
detected Domain: s.py XIOC detected Domain: s.py
extracted_from_files
detected Domain: s.target XIOC detected Domain: s.target
extracted_from_files
detected Domain: a.py XIOC detected Domain: a.py
extracted_from_files
detected Domain: a.target XIOC detected Domain: a.target
extracted_from_files
detected Domain: t.cy XIOC detected Domain: t.cy
extracted_from_files
detected Domain: t.cx XIOC detected Domain: t.cx
extracted_from_files
detected Domain: this.id XIOC detected Domain: this.id
extracted_from_files
detected Domain: uc.select XIOC detected Domain: uc.select
extracted_from_files
detected Domain: uc.call XIOC detected Domain: uc.call
extracted_from_files
detected Domain: c.map XIOC detected Domain: c.map
extracted_from_files
detected Domain: a.call XIOC detected Domain: a.call
extracted_from_files
detected Domain: l.map XIOC detected Domain: l.map
extracted_from_files
detected Domain: h.call XIOC detected Domain: h.call
extracted_from_files
detected Domain: p.select XIOC detected Domain: p.select
extracted_from_files
detected Domain: m.select XIOC detected Domain: m.select
extracted_from_files
detected Domain: d.select XIOC detected Domain: d.select
extracted_from_files
detected Domain: this.style XIOC detected Domain: this.style
extracted_from_files
detected Domain: uc.style XIOC detected Domain: uc.style
extracted_from_files
detected Domain: u.space XIOC detected Domain: u.space
extracted_from_files
detected Domain: a.space XIOC detected Domain: a.space
extracted_from_files
detected Domain: cloud.githubusercontent.com XIOC detected Domain: cloud.githubusercontent.com
extracted_from_files
detected Domain: unit.name XIOC detected Domain: unit.name
extracted_from_files
detected Domain: wc.day XIOC detected Domain: wc.day
extracted_from_files
detected Domain: s.style XIOC detected Domain: s.style
extracted_from_files
detected Domain: n.select XIOC detected Domain: n.select
extracted_from_files
detected Domain: a.style XIOC detected Domain: a.style
extracted_from_files
detected Domain: m.call XIOC detected Domain: m.call
extracted_from_files
detected Domain: e.so XIOC detected Domain: e.so
extracted_from_files
detected Domain: e.detail.email XIOC detected Domain: e.detail.email
extracted_from_files
detected Domain: e.name XIOC detected Domain: e.name
extracted_from_files
detected Domain: t.name XIOC detected Domain: t.name
extracted_from_files
detected Domain: draftback.email XIOC detected Domain: draftback.email
extracted_from_files
detected Domain: example.com XIOC detected Domain: example.com
extracted_from_files
detected Domain: draftback.com XIOC detected Domain: draftback.com
extracted_from_files
detected Domain: initialdata.info XIOC detected Domain: initialdata.info
extracted_from_files
detected Domain: purl.org XIOC detected Domain: purl.org
extracted_from_files
detected Domain: c.cv XIOC detected Domain: c.cv
extracted_from_files
detected Domain: k.ne XIOC detected Domain: k.ne
extracted_from_files
detected Domain: l.mw XIOC detected Domain: l.mw
extracted_from_files
detected Domain: ns.adobe.com XIOC detected Domain: ns.adobe.com
extracted_from_files
detected Domain: ajaxload.info XIOC detected Domain: ajaxload.info
extracted_from_files
detected Domain: map.name XIOC detected Domain: map.name
extracted_from_files
detected Domain: bugs.jqueryui.com XIOC detected Domain: bugs.jqueryui.com
extracted_from_files
detected Domain: bugs.jquery.com XIOC detected Domain: bugs.jquery.com
extracted_from_files
detected Domain: api.jqueryui.com XIOC detected Domain: api.jqueryui.com
extracted_from_files
detected Domain: docs.jquery.com XIOC detected Domain: docs.jquery.com
extracted_from_files
detected Domain: jquery.org XIOC detected Domain: jquery.org
extracted_from_files
detected Domain: jqueryui.com XIOC detected Domain: jqueryui.com
extracted_from_files
detected Domain: foo.bar XIOC detected Domain: foo.bar
extracted_from_files
detected Domain: element.style XIOC detected Domain: element.style
extracted_from_files
detected Domain: event.target XIOC detected Domain: event.target
extracted_from_files
detected Domain: slice.call XIOC detected Domain: slice.call
extracted_from_files
detected Domain: fn.call XIOC detected Domain: fn.call
extracted_from_files
detected Domain: ui.ie XIOC detected Domain: ui.ie
extracted_from_files
detected Domain: removedata.call XIOC detected Domain: removedata.call
extracted_from_files
detected Domain: style.top XIOC detected Domain: style.top
extracted_from_files
detected Domain: a.elem.style XIOC detected Domain: a.elem.style
extracted_from_files
detected IP: :: XIOC detected IP: ::
extracted_from_files
detected Domain: this.margins.top XIOC detected Domain: this.margins.top
extracted_from_files
detected Domain: this.positionabs.top XIOC detected Domain: this.positionabs.top
extracted_from_files
detected Domain: this.handleelement.is XIOC detected Domain: this.handleelement.is
extracted_from_files
detected Domain: mousedownevent.target XIOC detected Domain: mousedownevent.target
extracted_from_files
detected Domain: po.top XIOC detected Domain: po.top
extracted_from_files
detected Domain: obj.top XIOC detected Domain: obj.top
extracted_from_files
detected Domain: this.offset.click.top XIOC detected Domain: this.offset.click.top
extracted_from_files
detected Domain: this.helper.is XIOC detected Domain: this.helper.is
extracted_from_files
detected Domain: mouseup.call XIOC detected Domain: mouseup.call
extracted_from_files
detected Domain: this.options.revert.call XIOC detected Domain: this.options.revert.call
extracted_from_files
detected Domain: this.position.top XIOC detected Domain: this.position.top
extracted_from_files
detected Domain: ui.plugin.call XIOC detected Domain: ui.plugin.call
extracted_from_files
detected Domain: co.top XIOC detected Domain: co.top
extracted_from_files
detected Domain: this.offset.scroll.top XIOC detected Domain: this.offset.scroll.top
extracted_from_files
detected Domain: pos.top XIOC detected Domain: pos.top
extracted_from_files
detected Domain: this.offset.parent.top XIOC detected Domain: this.offset.parent.top
extracted_from_files
detected Domain: this.offset.relative.top XIOC detected Domain: this.offset.relative.top
extracted_from_files
detected Domain: p.top XIOC detected Domain: p.top
extracted_from_files
detected Domain: draggable.offset.parent.top XIOC detected Domain: draggable.offset.parent.top
extracted_from_files
detected Domain: sortable.offset.parent.top XIOC detected Domain: sortable.offset.parent.top
extracted_from_files
detected Domain: draggable.offset.click.top XIOC detected Domain: draggable.offset.click.top
extracted_from_files
detected Domain: sortable.offset.click.top XIOC detected Domain: sortable.offset.click.top
extracted_from_files
detected Domain: draggable.offset.click XIOC detected Domain: draggable.offset.click
extracted_from_files
detected URL: http://prototypejs.org/learn/class-inheritance). XIOC detected URL: http://prototypejs.org/learn/class-inheritance).
extracted_from_files
detected URL: https://cloud.githubusercontent.com/assets/21294/4967993/00bf782e-682d-11e4-93e7-106fcf26f6a0.gif XIOC detected URL: https://cloud.githubusercontent.com/assets/21294/4967993/00bf782e-682d-11e4-93e7-106fcf26f6a0.gif
extracted_from_files
detected URL: https://github.com/Jakobo/PTClass XIOC detected URL: https://github.com/Jakobo/PTClass
extracted_from_files
detected Domain: ui.position.top XIOC detected Domain: ui.position.top
extracted_from_files
detected Domain: inst.options.snap.release.call XIOC detected Domain: inst.options.snap.release.call
extracted_from_files
detected Domain: inst.margins.top XIOC detected Domain: inst.margins.top
extracted_from_files
detected Domain: ui.offset.top XIOC detected Domain: ui.offset.top
extracted_from_files
detected Domain: o.top XIOC detected Domain: o.top
extracted_from_files
detected Domain: i.overflowoffset.top XIOC detected Domain: i.overflowoffset.top
extracted_from_files
detected Domain: data.top XIOC detected Domain: data.top
extracted_from_files
detected Domain: props.top XIOC detected Domain: props.top
extracted_from_files
detected Domain: this.prevposition.top XIOC detected Domain: this.prevposition.top
extracted_from_files
detected Domain: that.originalposition.top XIOC detected Domain: that.originalposition.top
extracted_from_files
detected Domain: that.position.top XIOC detected Domain: that.position.top
extracted_from_files
detected Domain: smp.top XIOC detected Domain: smp.top
extracted_from_files
detected Domain: handles.show XIOC detected Domain: handles.show
extracted_from_files
detected Domain: cop.top XIOC detected Domain: cop.top
extracted_from_files
detected Domain: that.parentdata.top XIOC detected Domain: that.parentdata.top
extracted_from_files
detected Domain: that.offset.top XIOC detected Domain: that.offset.top
extracted_from_files
detected Domain: cp.top XIOC detected Domain: cp.top
extracted_from_files
detected Domain: sp.top XIOC detected Domain: sp.top
extracted_from_files
detected Domain: this.elementoffset.top XIOC detected Domain: this.elementoffset.top
extracted_from_files
detected Domain: cpos.top XIOC detected Domain: cpos.top
extracted_from_files
detected Domain: jquery.com XIOC detected Domain: jquery.com
extracted_from_files
detected Domain: ui.keycode.page XIOC detected Domain: ui.keycode.page
extracted_from_files
detected Domain: clickoffset.top XIOC detected Domain: clickoffset.top
extracted_from_files
detected Domain: offset.top XIOC detected Domain: offset.top
extracted_from_files
detected Domain: op.top XIOC detected Domain: op.top
extracted_from_files
detected Domain: el.data XIOC detected Domain: el.data
extracted_from_files
detected Domain: that.prevposition.top XIOC detected Domain: that.prevposition.top
extracted_from_files
detected Domain: e.fn.attr.call XIOC detected Domain: e.fn.attr.call
extracted_from_files
detected Domain: f.data XIOC detected Domain: f.data
extracted_from_files
detected Domain: h.fire XIOC detected Domain: h.fire
extracted_from_files
detected Domain: h.data XIOC detected Domain: h.data
extracted_from_files
detected Domain: h.events XIOC detected Domain: h.events
extracted_from_files
detected Domain: g.events XIOC detected Domain: g.events
extracted_from_files
detected Domain: f.now XIOC detected Domain: f.now
extracted_from_files
detected Domain: this.data XIOC detected Domain: this.data
extracted_from_files
detected Domain: g.style.top XIOC detected Domain: g.style.top
extracted_from_files
detected Domain: f.support XIOC detected Domain: f.support
extracted_from_files
detected Domain: e.fn.init.call XIOC detected Domain: e.fn.init.call
extracted_from_files
detected Domain: j.call XIOC detected Domain: j.call
extracted_from_files
detected Domain: a.eval.call XIOC detected Domain: a.eval.call
extracted_from_files
detected Domain: h.id XIOC detected Domain: h.id
extracted_from_files
detected Domain: f.event.global XIOC detected Domain: f.event.global
extracted_from_files
detected Domain: s.add.call XIOC detected Domain: s.add.call
extracted_from_files
detected Domain: s.setup.call XIOC detected Domain: s.setup.call
extracted_from_files
detected Domain: c.id XIOC detected Domain: c.id
extracted_from_files
detected Domain: f.attrhooks.style XIOC detected Domain: f.attrhooks.style
extracted_from_files
detected Domain: f.support.style XIOC detected Domain: f.support.style
extracted_from_files
detected Domain: f.map XIOC detected Domain: f.map
extracted_from_files
detected Domain: s.data XIOC detected Domain: s.data
extracted_from_files
detected Domain: c.data XIOC detected Domain: c.data
extracted_from_files
detected Domain: n.is XIOC detected Domain: n.is
extracted_from_files
detected Domain: i.predispatch.call XIOC detected Domain: i.predispatch.call
extracted_from_files
detected Domain: c.target XIOC detected Domain: c.target
extracted_from_files
detected Domain: p.teardown.call XIOC detected Domain: p.teardown.call
extracted_from_files
detected Domain: p.remove.call XIOC detected Domain: p.remove.call
extracted_from_files
detected Domain: i.id XIOC detected Domain: i.id
extracted_from_files
detected Domain: o.filter.id XIOC detected Domain: o.filter.id
extracted_from_files
detected Domain: o.find.id XIOC detected Domain: o.find.id
extracted_from_files
detected Domain: this.click XIOC detected Domain: this.click
extracted_from_files
detected Domain: this.off XIOC detected Domain: this.off
extracted_from_files
detected Domain: f.event.dispatch.call XIOC detected Domain: f.event.dispatch.call
extracted_from_files
detected Domain: i.postdispatch.call XIOC detected Domain: i.postdispatch.call
extracted_from_files
detected Domain: this.name XIOC detected Domain: this.name
extracted_from_files
detected Domain: f.style XIOC detected Domain: f.style
extracted_from_files
detected Domain: b.events XIOC detected Domain: b.events
extracted_from_files
detected Domain: this.map XIOC detected Domain: this.map
extracted_from_files
detected Domain: b.map XIOC detected Domain: b.map
extracted_from_files
detected Domain: bg.td XIOC detected Domain: bg.td
extracted_from_files
detected Domain: bg.th XIOC detected Domain: bg.th
extracted_from_files
detected Domain: a.global XIOC detected Domain: a.global
extracted_from_files
detected Domain: b.data XIOC detected Domain: b.data
extracted_from_files
detected Domain: d.beforesend.call XIOC detected Domain: d.beforesend.call
extracted_from_files
detected Domain: d.global XIOC detected Domain: d.global
extracted_from_files
detected Domain: d.data XIOC detected Domain: d.data
extracted_from_files
detected Domain: v.fail XIOC detected Domain: v.fail
extracted_from_files
detected Domain: b.name XIOC detected Domain: b.name
extracted_from_files
detected Domain: this.now XIOC detected Domain: this.now
extracted_from_files
detected Domain: this.options.step.call XIOC detected Domain: this.options.step.call
extracted_from_files
detected Domain: d.old.call XIOC detected Domain: d.old.call
extracted_from_files
detected Domain: f.fx.off XIOC detected Domain: f.fx.off
extracted_from_files
detected Domain: b.complete.call XIOC detected Domain: b.complete.call
extracted_from_files
detected URL: https://cloud.githubusercontent.com/assets/21294/4969053/0b7748bc-6857-11e4-9985-89b361f919f8.gif XIOC detected URL: https://cloud.githubusercontent.com/assets/21294/4969053/0b7748bc-6857-11e4-9985-89b361f919f8.gif
extracted_from_files
detected URL: https://cloud.githubusercontent.com/assets/21294/4968082/0933ba06-6832-11e4-9039-f5877fca316b.gif XIOC detected URL: https://cloud.githubusercontent.com/assets/21294/4968082/0933ba06-6832-11e4-9039-f5877fca316b.gif
extracted_from_files
detected Domain: a.now XIOC detected Domain: a.now
extracted_from_files
detected Domain: i.show XIOC detected Domain: i.show
extracted_from_files
detected Domain: h.style XIOC detected Domain: h.style
extracted_from_files
detected Domain: this.options.show XIOC detected Domain: this.options.show
extracted_from_files
detected Domain: e.options.show XIOC detected Domain: e.options.show
extracted_from_files
detected Domain: this.elem.style XIOC detected Domain: this.elem.style
extracted_from_files
detected Domain: c.top XIOC detected Domain: c.top
extracted_from_files
detected Domain: b.using.call XIOC detected Domain: b.using.call
extracted_from_files
detected Domain: b.top-g.top XIOC detected Domain: b.top-g.top
extracted_from_files
detected Domain: k.top XIOC detected Domain: k.top
extracted_from_files
detected Domain: b.top XIOC detected Domain: b.top
extracted_from_files
detected Domain: l.top XIOC detected Domain: l.top
extracted_from_files
detected Domain: d.top XIOC detected Domain: d.top
extracted_from_files
detected Domain: clients2.google.com XIOC detected Domain: clients2.google.com
extracted_from_files
detected Domain: targ.style XIOC detected Domain: targ.style
extracted_from_files
detected Domain: targ.is XIOC detected Domain: targ.is
extracted_from_files
detected Domain: elem.is XIOC detected Domain: elem.is
extracted_from_files
detected Domain: flesler.blogspot.com XIOC detected Domain: flesler.blogspot.com
extracted_from_files
detected Domain: b.style XIOC detected Domain: b.style
extracted_from_files
detected Domain: c.top-d.top XIOC detected Domain: c.top-d.top
extracted_from_files
detected Domain: en.wikipedia.org XIOC detected Domain: en.wikipedia.org
extracted_from_files
detected Domain: stackoverflow.com XIOC detected Domain: stackoverflow.com
extracted_from_files
detected Domain: jsperf.com XIOC detected Domain: jsperf.com
extracted_from_files
detected Domain: docs.closure-library.googlecode.com XIOC detected Domain: docs.closure-library.googlecode.com
extracted_from_files
detected Domain: userinfo.email XIOC detected Domain: userinfo.email
extracted_from_files
detected Domain: 7880305128-lop765nj8hb572bhqngtloi8ek4n314h.apps.googleusercontent.com XIOC detected Domain: 7880305128-lop765nj8hb572bhqngtloi8ek4n314h.apps.googleusercontent.com
extracted_from_files
detected Domain: identity.email XIOC detected Domain: identity.email
extracted_from_files
detected Domain: func.call XIOC detected Domain: func.call
extracted_from_files
detected Domain: hasownproperty.call XIOC detected Domain: hasownproperty.call
extracted_from_files
detected Domain: this.zone XIOC detected Domain: this.zone
extracted_from_files
detected Domain: this.day XIOC detected Domain: this.day
extracted_from_files
detected Domain: this.date XIOC detected Domain: this.date
extracted_from_files
detected Domain: asp.net XIOC detected Domain: asp.net
extracted_from_files
detected Domain: momentjs.com XIOC detected Domain: momentjs.com
extracted_from_files
detected Domain: mom.day XIOC detected Domain: mom.day
extracted_from_files
detected Domain: duration.as XIOC detected Domain: duration.as
extracted_from_files
detected Domain: w.gg XIOC detected Domain: w.gg
extracted_from_files
detected Domain: m.day XIOC detected Domain: m.day
extracted_from_files
detected Domain: method.call XIOC detected Domain: method.call
extracted_from_files
detected Domain: object.prototype.tostring.call XIOC detected Domain: object.prototype.tostring.call
extracted_from_files
detected Domain: normalizedinput.day XIOC detected Domain: normalizedinput.day
extracted_from_files
detected Domain: moment.fn.day XIOC detected Domain: moment.fn.day
extracted_from_files
detected Domain: moment.fn.date XIOC detected Domain: moment.fn.date
extracted_from_files
detected Domain: mom.date XIOC detected Domain: mom.date
extracted_from_files
detected Domain: that.zone XIOC detected Domain: that.zone
extracted_from_files
detected Domain: m.date XIOC detected Domain: m.date
extracted_from_files
detected Domain: duration.ms XIOC detected Domain: duration.ms
extracted_from_files
detected Domain: duration.to XIOC detected Domain: duration.to
extracted_from_files
detected Domain: a.tz XIOC detected Domain: a.tz
extracted_from_files
detected Domain: 8.kh XIOC detected Domain: 8.kh
extracted_from_files
detected Domain: g.no XIOC detected Domain: g.no
extracted_from_files
detected Domain: t.il XIOC detected Domain: t.il
extracted_from_files
detected Domain: he.ls XIOC detected Domain: he.ls
extracted_from_files
detected Domain: this.as XIOC detected Domain: this.as
extracted_from_files
detected Domain: goog.date XIOC detected Domain: goog.date
extracted_from_files
detected Domain: pasteevents.map XIOC detected Domain: pasteevents.map
extracted_from_files
detected Domain: slideroffset.top XIOC detected Domain: slideroffset.top
extracted_from_files
detected Domain: l.mr XIOC detected Domain: l.mr
extracted_from_files
detected Domain: n.si XIOC detected Domain: n.si
extracted_from_files
detected Domain: wo.ad XIOC detected Domain: wo.ad
extracted_from_files
detected Domain: 9.kz XIOC detected Domain: 9.kz
extracted_from_files
detected Domain: 2.at XIOC detected Domain: 2.at
extracted_from_files
detected Domain: s.name XIOC detected Domain: s.name
extracted_from_files
detected Domain: d3.select XIOC detected Domain: d3.select
extracted_from_files
detected Domain: strtrim.call XIOC detected Domain: strtrim.call
extracted_from_files
detected Domain: arrindexof.call XIOC detected Domain: arrindexof.call
extracted_from_files
detected Domain: purl.eligrey.com XIOC detected Domain: purl.eligrey.com
extracted_from_files
detected Domain: prototypejs.org XIOC detected Domain: prototypejs.org
extracted_from_files
detected Domain: eloffset.top XIOC detected Domain: eloffset.top
extracted_from_files
detected Domain: d.name XIOC detected Domain: d.name
extracted_from_files
detected Domain: args.data XIOC detected Domain: args.data
extracted_from_files
detected Domain: this.schemes.cool XIOC detected Domain: this.schemes.cool
extracted_from_files
detected Domain: this.renderer.name XIOC detected Domain: this.renderer.name
extracted_from_files
detected Domain: renderer.name XIOC detected Domain: renderer.name
extracted_from_files
detected Domain: data.map XIOC detected Domain: data.map
extracted_from_files
detected Domain: this.series.map XIOC detected Domain: this.series.map
extracted_from_files
detected Domain: item.style.top XIOC detected Domain: item.style.top
extracted_from_files
detected Domain: series.name XIOC detected Domain: series.name
extracted_from_files
detected Domain: line.series.name XIOC detected Domain: line.series.name
extracted_from_files
detected Domain: domain.map XIOC detected Domain: domain.map
extracted_from_files
detected Domain: this.element.style.top XIOC detected Domain: this.element.style.top
extracted_from_files
detected Domain: args.auto XIOC detected Domain: args.auto
extracted_from_files
detected Domain: self.data XIOC detected Domain: self.data
extracted_from_files
detected Domain: d3.event.target XIOC detected Domain: d3.event.target
extracted_from_files
detected Domain: drag.target XIOC detected Domain: drag.target
extracted_from_files
detected Domain: parent.renderer.name XIOC detected Domain: parent.renderer.name
extracted_from_files
detected Domain: this.svg.style XIOC detected Domain: this.svg.style
extracted_from_files
detected Domain: this.build XIOC detected Domain: this.build
extracted_from_files
detected Domain: this.show XIOC detected Domain: this.show
extracted_from_files
detected Domain: dot.style.top XIOC detected Domain: dot.style.top
extracted_from_files
detected Domain: item.data XIOC detected Domain: item.data
extracted_from_files
detected Domain: item.name XIOC detected Domain: item.name
extracted_from_files
detected Domain: domains.map XIOC detected Domain: domains.map
extracted_from_files
detected Domain: array.prototype.foreach.call XIOC detected Domain: array.prototype.foreach.call
extracted_from_files
detected Domain: rickshaw.graph.renderer.bar XIOC detected Domain: rickshaw.graph.renderer.bar
extracted_from_files
detected Domain: this.padding.top XIOC detected Domain: this.padding.top
extracted_from_files
detected Domain: element.select XIOC detected Domain: element.select
extracted_from_files
detected URL: https://www.googleapis.com/oauth2/v3/userinfo', XIOC detected URL: https://www.googleapis.com/oauth2/v3/userinfo',
extracted_from_files
detected URL: https://accounts.draftback.com/check-entitlement', XIOC detected URL: https://accounts.draftback.com/check-entitlement',
extracted_from_files
detected URL: https://github.com/caolan/async XIOC detected URL: https://github.com/caolan/async
extracted_from_files
detected Email: placeholder='[email protected] XIOC detected Email: placeholder='[email protected]
extracted_from_files
detected Domain: series.map XIOC detected Domain: series.map
extracted_from_files
detected URL: https://draftback.com/#pricing XIOC detected URL: https://draftback.com/#pricing
extracted_from_files
detected URL: https://draftback.com/#paid XIOC detected URL: https://draftback.com/#paid
extracted_from_files
detected Domain: d.style XIOC detected Domain: d.style
extracted_from_files
detected Domain: h.open XIOC detected Domain: h.open
extracted_from_files
detected Domain: n.map XIOC detected Domain: n.map
extracted_from_files
detected Domain: this.offset.click XIOC detected Domain: this.offset.click
extracted_from_files
Security Analysis Summary
Security Analysis Overview
Draftback is a Chrome Web Store extension published by [email protected]. Version 0.0.27 has been analyzed by the Risky Plugins security platform, receiving a risk score of 64.99/100 (MEDIUM risk) based on 495 security findings.
Risk Assessment
This extension presents high security risk. Significant concerns were identified during analysis. It is not recommended for use in sensitive or production environments without thorough review.
Findings Breakdown
- High: 50 finding(s)
- Medium: 445 finding(s)
What Was Analyzed
The security assessment covers multiple analysis categories:
- Malware Detection: YARA rule matching against 2,400+ malware signatures
- Secret Detection: Scanning for exposed API keys, tokens, and credentials
- Static Analysis: Code-level security analysis for common vulnerability patterns
- Network Analysis: Detection of suspicious network communications and endpoints
- Obfuscation Detection: Identification of code obfuscation techniques
Developer Information
Draftback is published by [email protected] on the Chrome Web Store marketplace. The extension has approximately 400K users.
Recommendation
This extension is not recommended for installation without thorough manual review. Consider alternatives with lower risk scores, or contact the developer to address the identified security concerns.
Source Code Not Available
Source code is not available for this version of the extension.
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace
KPN Password Manager
[email protected]
MAGgie - An AI Assistant
[email protected]
Aintivirus Privacy and Wallet
[email protected]
BugZap — Visual Bug Reporter
[email protected]
FormGenieAI
[email protected]
OmniChat
[email protected]