Chrome Web Store Verified

Open Headers

by [email protected] · 68 users · 5.0 rating
68fb4ca9-4340-5c89-a640-8dd8717280d2 | v2026.9.2
86/ 100
CRITICAL risk
+1 since v2026.9.0
Analyst verdict
Benign but powerful

From the RiskyPlugins AI security review of the observed evidence.

Analysis record

Analysed
2 weeks ago
Version
v2026.9.2
Artifact
SHA256 194…5C9
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

551 detail rows

YARA Rule Matches

22 rules
SeverityRuleHitsFilesMetadata
HIGHsupply chain sourcemap appended iife 1
assets/ts.worker-Dr8d31wG.js
-
LOWpostinstall obfuscation 63
sandbox.htmljs/offscreen/index.jsjs/chunks/EncodedValueModal.js +60 more
-
LOWpostinstall network communication 67
js/content/perf-observer/index.jsjs/chunks/formatters.jsjs/chunks/index2.js +64 more
-
LOWOriginsNotVerified 8
js/chunks/monaco.jsassets/ts.worker-Dr8d31wG.jsassets/html.worker-jGRfbVbX.js +5 more
-
LOWpostinstall crypto operations 41
js/background/index.jsjs/chunks/report.jsassets/css.worker-D_Nnd8Tb.js +38 more
-
LOWpostinstall system command 70
js/delay/index.jsjs/offscreen/index.jscss/popup.css +67 more
-
LOWUsingShellInterpreterWhenExecutingOSCommands 1
assets/ts.worker-Dr8d31wG.js
-
LOWpostinstall file manipulation 78
js/chunks/surface-identity-resolvers.jsjs/chunks/bootstrap.jsjs/chunks/IdbRecordEditorTab.js +75 more
-
LOWpostinstall registry modification 22
js/chunks/codec.jsjs/chunks/TerminalPanel.jsjs/chunks/GitLogPanel.js +19 more
-
LOWpostinstall environment access 47
js/chunks/client.jsjs/chunks/index4.jsjs/chunks/TrafficMonitorPanel.js +44 more
-
LOWLocalStorageShouldNotBeUsed 5
js/chunks/surface-identity-resolvers.jsjs/chunks/GitLogPanel.jsjs/chunks/CommitToolPanel.js +2 more
-
LOWDebuggerStatementsShouldNotBeUsed 13
assets/json.worker-BEDp5blR.jsassets/html.worker-jGRfbVbX.jsassets/ts.worker-Dr8d31wG.js +10 more
-
LOWNoUseEval 2
js/devtools/index.jsassets/ts.worker-Dr8d31wG.js
-
LOWNoUseWeakRandom 10
js/chunks/use-rules-lookup.jsjs/chunks/postcss.jsjs/background/index.js +7 more
-
LOWcredential generic tokens 10
js/chunks/index4.jsjs/chunks/index6.jsjs/chunks/index7.js +7 more
-
LOWpostinstall file download 51
assets/json.worker-BEDp5blR.jsjs/chunks/live-fallback-priority-sync-mirror.jsjs/chunks/telemetry-storage.js +48 more
-
LOWcredential git credentials 1
js/chunks/monaco.js
-
LOWUntrustedContentShouldNotBeIncluded 1
js/chunks/monaco.js
-
LOWSQLInjection 5
js/chunks/GitLogPanel.jsjs/chunks/codec.jsjs/chunks/dock-layout.js +2 more
-
LOWRedirectToUnknownPath 2
assets/ts.worker-Dr8d31wG.jsjs/chunks/standalone.js
-
LOWpostinstall persistence mechanism 22
assets/html.worker-jGRfbVbX.jsjs/chunks/index3.jsjs/chunks/index2.js +19 more
-
LOWcredential env files 24
js/chunks/index7.jsjs/chunks/index3.jsjs/chunks/monaco.js +21 more
-

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

741 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Publisher Evidence

Limited evidence

[email protected]

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

Chrome does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.

42
Noisy-finding weight
x1.00
Publisher domain
openheaders.io
Observed
Store verification signal
Limited signal
Limited
Extension portfolio
2
Portfolio

13 evidence rows available.

Finding Categories

1
Malware Signatures
3
Obfuscation
2
Network
741
IoC Indicators

YARA Rules Matched

22 rules(544 hits)
supply chain sourcemap appended iife postinstall obfuscation postinstall network communication OriginsNotVerified postinstall crypto operations postinstall system command UsingShellInterpreterWhenExecutingOSCommands postinstall file manipulation postinstall registry modification postinstall environment access LocalStorageShouldNotBeUsed DebuggerStatementsShouldNotBeUsed NoUseEval NoUseWeakRandom credential generic tokens postinstall file download +6 more

Requested Permissions

24 permissions
debugger

Full access to Chrome DevTools debugging protocol

Dangerous
proxy

Control the browser's proxy settings

Dangerous
nativeMessaging

Exchange messages with programs outside the browser

Dangerous
<all_urls>

Access and modify data on every website you visit

Dangerous
webRequest

Intercept, modify, and block all network requests

High
cookies

Read and modify cookies on all sites

High
identity

Access your identity and sign-in tokens

High
tabs
Medium
activeTab
Medium
browsingData
Medium
storage
Low
alarms
Low
declarativeNetRequest
Low
declarativeNetRequestWithHostAccess
Low
declarativeNetRequestFeedback
Low
tabGroups
Low
webNavigation
Low
scripting
Low
userScripts
Low
windows
Low
sidePanel
Low
offscreen
Low
favicon
Low
file:///*
Low

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality strong.

This extension identifies itself as a local development tool ('Record your browser tab... Modify HTTP Traffic... Everything local'). Based on the provided evidence bundle, there are zero findings across all categories, including no indicators of compromise (IoCs), no malicious code signatures, and no obfuscation flags.

The primary risk assessment for this extension shifts from 'malicious intent' to 'capability trust'. The capability to record tabs and modify HTTP traffic is functionally similar to a Man-in-the-Middle (MitM) proxy, which is a standard requirement for web debugging (similar to Burp Suite or Fiddler). However, this power requires a high degree of trust in the publisher. The extension lists a specific developer contact ([email protected]) and claims to operate locally ("Everything local"), which aligns with the threat model of a privacy-focused dev-tool.

Recommendation: The lack of automated detection signals suggests the code is transparent and does not use obfuscation to hide logic. However, because the extension has the technical capability to intercept sensitive data, it should only be installed by developers who understand and trust the source. It is not suitable for deployment in managed enterprise environments without explicit approval.

Key Reasons

  • Zero automated findings across all categories (IoCs, YARA, Obfuscation).
  • Explicit functionality (HTTP modification) matches the developer tool threat profile, not malware profiles.
  • Publisher provides a direct contact email rather than remaining anonymous.

Reviewed 2026-04-20; recommended action: no action; model confidence 90%.

Chrome version history

Risk trend by version

12 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
86
Change since first
+33
Change from previous
+1
Versions:
First analyzed version
2.1.0
Mar 10, 2026
Risk range
53 to 86
Across analyzed versions
Latest analyzed version
2026.9.2
Sep 17, 2026
Selected version
critical
Version
v2026.9.2
2 weeks ago
Risk score
86
Findings
1293
Change vs previous
+1

Pick any point on the chart to explore that version's code below.

About This Extension

Local-first: no account, no cloud, your data stays on your machine. BROWSER INTERCEPTOR • Rewrite headers, block, redirect, delay, mock responses, edit bodies and query strings, merge, inject CSS/JS, modify WebSocket and SSE messages • Static rules compile into the browser's own network layer and catch every request: pages, frames, fetch, XHR, images, fonts, scripts • No proxy port and no CA certificate: rules run with the page's own permissions, nothing man-in-the-middles your traffic • DevTools-grade network panel with request and response inspection • Five variable scopes in every rule: vault, environment, collection, workspace, live API CLIENT • HTTP, GraphQL with schema introspection, WebSocket, Socket.IO and SSE right in the browser; gRPC and MQTT through the desktop companion • Collections with folders, environments, OAuth 2.0 with PKCE and refresh, multipart file uploads • Pre- and post-response scripts and assertions • Workflows: chain and schedule requests with dependencies, AND/OR run conditions and parallel steps; every response value lands in a live variable any rule can inject into real traffic • Import from cURL, HAR, Postman, Insomnia and OpenAPI • Encrypted vault for secrets and tokens, referenced by name, never exposed TEAM COLLABORATION • Multi-workspace: your personal workspace and the team's shared one side by side, each in its own tab • Sync through back-ends you control: the desktop app, a box on your LAN, or a self-hosted server • Self-hosted server with SSO, RBAC user management and audit logs • Optional Git back-end for durable workspace history: a new device bootstraps from Git and auto-syncs from there • Concurrent multi-user editing • Work offline, auto-sync when back online Our vision: a platform where everyone can use local tools to generate their own local data and own it, not a cloud vendor middleman. Everything is free to use and free to self-host. Like it should be.

Frequently Asked Questions