Is "VibeSec - Web Security Scanner" on Chrome Web Store Safe to Install?
VibeSec - Web Security Scanner is a comprehensive security analysis tool that instantly scans any website to detect security vulnerabilities, misconfigurations, and best practice violations. KEY FEATURES: ๐ HTTP Security Headers Analysis - Validates HSTS, X-Content-Type-Options, X-Frame-Options, CSP, Referrer-Policy, CORP, and other critical security headers ๐ TLS/SSL Verification - Confirms HTTPS protocol usage and modern encryption standards ๐ช Cookie Security Checks - Validates secure flags, HttpOnly attributes, and cookie configurations โก Input Validation Detection - Identifies XSS protection and CSP implementations โ๏ธ Environment Configuration - Checks for debug mode, server information exposure, and dangerous configurations ๐ CORS Analysis - Validates cross-origin resource sharing policies ๐ก๏ธ Cross-Origin Protection - Verifies CORP headers and clickjacking protections ๐ Technology Detection - Identifies server software and web frameworks BENEFITS: โ One-click website security analysis โ Pass/Fail status for each security check โ Must-Have and Overall security scores (0-100) โ Severity levels for each vulnerability โ Dark/Light mode with persistent preferences โ Download security reports as TXT files โ AI-powered fix recommendations with code examples โ Scan history tracking (last 20 scans) โ Works on any website - current page or custom URLs PERFECT FOR: - Web developers ensuring security best practices - Security professionals conducting assessments - DevOps teams verifying server configurations - Website owners checking security posture - Students learning web security All analysis is performed locally in your browser. No data is sent to external servers.
Risk Assessment
Analyzed25 security findings detected across all analyzers
Chrome extension requesting 4 permissions
Severity Breakdown
Finding Categories
YARA Rules Matched
6 rules(10 hits)Requested Permissions
4 permissionsAccess and modify data on every website you visit
About This Extension
Detailed Findings
13 totalYARA Rule Matches
6 rulesIndicators of Compromise
Network indicators, suspicious strings, and potential IoCs extracted during analysis
All Indicators ยท 12
detected Domain: 4.tj XIOC detected Domain: 4.tj
extracted_from_files
detected Domain: issue.name XIOC detected Domain: issue.name
extracted_from_files
detected URL: https://clients2.google.com/service/update2/crx XIOC detected URL: https://clients2.google.com/service/update2/crx
extracted_from_files
detected URL: https://example.com) XIOC detected URL: https://example.com)
extracted_from_files
detected URL: https://example.com/ XIOC detected URL: https://example.com/
extracted_from_files
detected Domain: clients2.google.com XIOC detected Domain: clients2.google.com
extracted_from_files
detected Domain: example.com XIOC detected Domain: example.com
extracted_from_files
detected Domain: asp.net XIOC detected Domain: asp.net
extracted_from_files
detected Domain: check.name XIOC detected Domain: check.name
extracted_from_files
detected Domain: prompt.name XIOC detected Domain: prompt.name
extracted_from_files
detected Domain: link.download XIOC detected Domain: link.download
extracted_from_files
detected Domain: link.click XIOC detected Domain: link.click
extracted_from_files
Security Analysis Summary
Security Analysis Overview
VibeSec - Web Security Scanner is a Chrome Web Store extension published by [email protected]. Version 1.0.0 has been analyzed by the Risky Plugins security platform, receiving a risk score of 84.84/100 (HIGH risk) based on 25 security findings.
Risk Assessment
This extension presents critical security risk. Severe issues were detected, potentially including malware indicators, exposed secrets, or dangerous behaviors. Installation is strongly discouraged until these issues are addressed.
Findings Breakdown
- High: 10 finding(s)
- Medium: 15 finding(s)
What Was Analyzed
The security assessment covers multiple analysis categories:
- Malware Detection: YARA rule matching against 2,400+ malware signatures
- Secret Detection: Scanning for exposed API keys, tokens, and credentials
- Static Analysis: Code-level security analysis for common vulnerability patterns
- Network Analysis: Detection of suspicious network communications and endpoints
- Obfuscation Detection: Identification of code obfuscation techniques
Developer Information
VibeSec - Web Security Scanner is published by [email protected] on the Chrome Web Store marketplace. The extension has approximately 13 users.
Recommendation
This extension is not recommended for installation without thorough manual review. Consider alternatives with lower risk scores, or contact the developer to address the identified security concerns.
Source Code Not Available
Source code is not available for this version of the extension.
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace
Web Crawler & Sitemap Generator
[email protected]
ShortRio - Link Shortener
[email protected]
SessionMaster
[email protected]
Image Downloader - Download All Images
[email protected]
SmartBookmark Plus
[email protected]
Send to NotebookLM
[email protected]