Is "SynthPass" on Chrome Web Store Safe to Install?
SynthPass is a different kind of password manager: it is a password synthesizer. With SynthPass, there is no "vault" that has to be protected from hackers because your passwords are synthesized on the fly, just as you need them. SynthPass-made passwords are always high strength and comprise letters, numbers, and special characters. Passwords for different websites are guaranteed to be totally different. You never have to change your Master Password. When a website forces you to change its password, simply change the optional serial that is used to synthesize that password. SynthPass will remember the serial, as well as your user ID. Your Master Password will never be stored, and it disappears from memory after five minutes not using it. And, if you absolutely must use a certain password, SynthPass can use that too! It is encrypted for storage and synced with the browser's own files so no third parties need to be involved. Unlike conventional password managers, SynthPass - won't pop up and interrupt your flow; it is activated only when you click its icon on the browser toolbar - won't store anything secret, only user IDs and optional serials, if you allow it - is always available, because it does not have to connect to "the Cloud" - makes only strong passwords - won't ask you for money - won't show ads SynthPass is based on the WiseHash key-stretching algorithm, which evaluates the information entropy of your Master Password and subjects it to a variable number of rounds of SCRYPT key-stretching. The weaker the password, the more stretching. This forces would-be hackers to spend an inordinate amount of computer time testing weak passwords before they can get to yours. SynthPass displays an accurate measurement of your Master Password's entropy to help you come up with a strong one. This is the same algorithm stretching the user password in PassLok Privacy and PassLok for Email, also in this web store. When there is no password to be filled, SynthPass displays a box where you can store securely encrypted notes for that particular website. Good place for extra login instructions, your first pet's name, or whatnot. Like everything else, the notes sync with the browser without a need for extra servers. There's also a button for moving the current page into an isolation cage similar to Incognito Mode, but within the same set of tabs as the regular pages. This is also accessible via the right-click menu. This is a browser extension, and therefore is poorly supported on mobile devices. There is, however, a web app that includes the same password-making engine and runs well on mobile devices. It can be found at: https://synthpass.com/app
Risk Assessment
Analyzed97 security findings detected across all analyzers
Chrome extension requesting 6 permissions
Severity Breakdown
Finding Categories
YARA Rules Matched
6 rules(29 hits)Requested Permissions
6 permissionsRead and modify your browsing history
About This Extension
Detailed Findings
29 totalYARA Rule Matches
6 rulesIndicators of Compromise
Network indicators, suspicious strings, and potential IoCs extracted during analysis
All Indicators · 61
detected Domain: result.name XIOC detected Domain: result.name
extracted_from_files
detected Domain: addons.mozilla.org XIOC detected Domain: addons.mozilla.org
extracted_from_files
detected URL: https://github.com/fruiz500/whisehash XIOC detected URL: https://github.com/fruiz500/whisehash
extracted_from_files
detected URL: http://snippetrepo.com/snippets/bignum-base-conversion, XIOC detected URL: http://snippetrepo.com/snippets/bignum-base-conversion,
extracted_from_files
detected URL: https://clients2.google.com/service/update2/crx XIOC detected URL: https://clients2.google.com/service/update2/crx
extracted_from_files
detected URL: https://chrome.google.com/webstore/detail/ignore-x-frame-headers/gleekbfjekiniecknbkamfmkohkpodhe XIOC detected URL: https://chrome.google.com/webstore/detail/ignore-x-frame-headers/gleekbfjekiniecknbkamfmkohkpodhe
extracted_from_files
detected URL: https://addons.mozilla.org/en-US/firefox/addon/ignore-x-frame-options-header/ XIOC detected URL: https://addons.mozilla.org/en-US/firefox/addon/ignore-x-frame-options-header/
extracted_from_files
detected URL: http://tweetnacl.cr.yp.to/ XIOC detected URL: http://tweetnacl.cr.yp.to/
extracted_from_files
detected URL: https://github.com/floodyberry/poly1305-donna XIOC detected URL: https://github.com/floodyberry/poly1305-donna
extracted_from_files
detected URL: https://github.com/dchest/scrypt-async-js XIOC detected URL: https://github.com/dchest/scrypt-async-js
extracted_from_files
detected URL: https://xato.net/passwords/more-top-worst-passwords, XIOC detected URL: https://xato.net/passwords/more-top-worst-passwords,
extracted_from_files
detected URL: https://github.com/first20hours/google-10000-english. XIOC detected URL: https://github.com/first20hours/google-10000-english.
extracted_from_files
detected URL: https://synthpass.com/app XIOC detected URL: https://synthpass.com/app
extracted_from_files
detected URL: https://synthpass.com XIOC detected URL: https://synthpass.com
extracted_from_files
detected URL: https://github.com/fruiz500/synthpass XIOC detected URL: https://github.com/fruiz500/synthpass
extracted_from_files
detected Domain: qwant.com XIOC detected Domain: qwant.com
extracted_from_files
detected URL: http://www.w3.org/1999/xhtml XIOC detected URL: http://www.w3.org/1999/xhtml
extracted_from_files
detected URL: https://github.com/dchest/scrypt-async-js-- XIOC detected URL: https://github.com/dchest/scrypt-async-js--
extracted_from_files
detected URL: https://www.youtube.com/watch?v=RLGScvETOEc XIOC detected URL: https://www.youtube.com/watch?v=RLGScvETOEc
extracted_from_files
detected URL: https://www.youtube.com/watch?v=96pSh4h1CAU XIOC detected URL: https://www.youtube.com/watch?v=96pSh4h1CAU
extracted_from_files
detected URL: https://www.youtube.com/watch?v=Y5jwImGkzCc XIOC detected URL: https://www.youtube.com/watch?v=Y5jwImGkzCc
extracted_from_files
detected URL: https://passlok.com/seeonce XIOC detected URL: https://passlok.com/seeonce
extracted_from_files
detected URL: https://passlok.com/ursa XIOC detected URL: https://passlok.com/ursa
extracted_from_files
detected URL: https://passlok.com/stego XIOC detected URL: https://passlok.com/stego
extracted_from_files
detected URL: https://passlok.com/human XIOC detected URL: https://passlok.com/human
extracted_from_files
detected URL: https://passlok.com/lockdir XIOC detected URL: https://passlok.com/lockdir
extracted_from_files
detected URL: https://github.com/fruiz500/wisehash-- XIOC detected URL: https://github.com/fruiz500/wisehash--
extracted_from_files
detected URL: https://github.com/dchest/tweetnacl-js-- XIOC detected URL: https://github.com/dchest/tweetnacl-js--
extracted_from_files
detected Domain: xato.net XIOC detected Domain: xato.net
extracted_from_files
detected Domain: range.select XIOC detected Domain: range.select
extracted_from_files
detected Domain: snippetrepo.com XIOC detected Domain: snippetrepo.com
extracted_from_files
detected Domain: box.select XIOC detected Domain: box.select
extracted_from_files
detected Domain: clients2.google.com XIOC detected Domain: clients2.google.com
extracted_from_files
detected URL: https://passlok.com/app XIOC detected URL: https://passlok.com/app
extracted_from_files
detected URL: https://passlok.com/learn XIOC detected URL: https://passlok.com/learn
extracted_from_files
detected Domain: wolframalpha.com XIOC detected Domain: wolframalpha.com
extracted_from_files
detected Domain: gigablast.com XIOC detected Domain: gigablast.com
extracted_from_files
detected Domain: swisscows.ch XIOC detected Domain: swisscows.ch
extracted_from_files
detected Domain: metager.de XIOC detected Domain: metager.de
extracted_from_files
detected Domain: oscobo.co.uk XIOC detected Domain: oscobo.co.uk
extracted_from_files
detected Domain: pageurl.click XIOC detected Domain: pageurl.click
extracted_from_files
detected Domain: document.location.host XIOC detected Domain: document.location.host
extracted_from_files
detected Domain: duckduckgo.com XIOC detected Domain: duckduckgo.com
extracted_from_files
detected Domain: search.disconnect.me XIOC detected Domain: search.disconnect.me
extracted_from_files
detected Domain: gibiru.com XIOC detected Domain: gibiru.com
extracted_from_files
detected Domain: startpage.com XIOC detected Domain: startpage.com
extracted_from_files
detected Domain: findx.com XIOC detected Domain: findx.com
extracted_from_files
detected Domain: searx.me XIOC detected Domain: searx.me
extracted_from_files
detected Domain: tweetnacl.cr.yp.to XIOC detected Domain: tweetnacl.cr.yp.to
extracted_from_files
detected Domain: nacl.secretbox.open XIOC detected Domain: nacl.secretbox.open
extracted_from_files
detected Domain: nacl.box XIOC detected Domain: nacl.box
extracted_from_files
detected Domain: nacl.box.open XIOC detected Domain: nacl.box.open
extracted_from_files
detected Domain: nacl.sign.open XIOC detected Domain: nacl.sign.open
extracted_from_files
detected Domain: array.prototype.slice.call XIOC detected Domain: array.prototype.slice.call
extracted_from_files
detected Domain: activetab.id XIOC detected Domain: activetab.id
extracted_from_files
detected Domain: passlok.com XIOC detected Domain: passlok.com
extracted_from_files
detected Domain: github.com XIOC detected Domain: github.com
extracted_from_files
detected Domain: www.youtube.com XIOC detected Domain: www.youtube.com
extracted_from_files
detected Domain: synthpass.com XIOC detected Domain: synthpass.com
extracted_from_files
detected Domain: www.w3.org XIOC detected Domain: www.w3.org
extracted_from_files
detected Domain: chrome.google.com XIOC detected Domain: chrome.google.com
extracted_from_files
Security Analysis Summary
Security Analysis Overview
SynthPass is a Chrome Web Store extension published by [email protected]. Version 0.2.9 has been analyzed by the Risky Plugins security platform, receiving a risk score of 39.95/100 (LOW risk) based on 97 security findings.
Risk Assessment
This extension presents low security risk. Some minor findings were detected, but nothing that would prevent typical usage. Reviewing the detailed findings below is recommended before use in sensitive environments.
Findings Breakdown
- High: 29 finding(s)
- Medium: 68 finding(s)
What Was Analyzed
The security assessment covers multiple analysis categories:
- Malware Detection: YARA rule matching against 2,400+ malware signatures
- Secret Detection: Scanning for exposed API keys, tokens, and credentials
- Static Analysis: Code-level security analysis for common vulnerability patterns
- Network Analysis: Detection of suspicious network communications and endpoints
- Obfuscation Detection: Identification of code obfuscation techniques
Developer Information
SynthPass is published by [email protected] on the Chrome Web Store marketplace. The extension has approximately 41 users.
Recommendation
Exercise caution with this extension. Review the detailed findings and ensure the requested permissions align with the extension's stated functionality before installation.
Source Code Not Available
Source code is not available for this version of the extension.
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace
PassLok Universal
[email protected]
PassLok for Email
[email protected]
PassLok Privacy
[email protected]
KyberLock
[email protected]
PassLok Image Steganography
[email protected]
SeeOnce Privacy
[email protected]