Is "aprico: Free Password Manager" on Chrome Web Store Safe to Install?

[email protected] · chrome · v0.2.0

Are you still using the same password for every website/app you sign up for? In your workplace lan there is a “Passwords.docx” file full of sensitive data? You heard about password managers but they are no way easy to setup and use? At the same time Google, Twitter et all are telling you to use a mix of numbers, symbols and letters and at least 8-10 characters long passwords. I know, our human brain was not programmed to remember all this things… Introducing Aprico: the dead easy yet secure password manager. Aprico deterministically generates for you a different secure password for every account you’ll ever need. And you just need to remember an ID and a Master Password. Aprico also doesn’t need to sync any vault or any other kind of data. You don’t even need to create an account in order to use it. - Dead Simple Aprico UX was designed from its inception to be as simple and frictionless as possible. - Privacy Oriented Aprico works 100% in your browser. No data will ever be sent to any server or cloud owned by us or by third parties. Read more in our privacy policy: https://aprico.org/privacy.html - Works everywhere You can use Aprico online, with your smartphone and directly in your browser with this web extension. - Secure Aprico generates your password using “scrypt”, one of the strongest cryptography algorithm out there. - Open Source Aprico is free and open-source software. Everyone is free to review, audit, and contribute to it.

Risk Assessment

Analyzed
39.98
out of 100
LOW

82 security findings detected across all analyzers

Chrome extension requesting 3 permissions

Severity Breakdown

0
Critical
13
High
69
Medium
0
Low
0
Info

Finding Categories

13
Malware Signatures
66
IoC Indicators

YARA Rules Matched

9 rules(13 hits)
postinstall system command postinstall network communication postinstall file download NoUseWeakRandom postinstall crypto operations postinstall obfuscation credential env files LocalStorageShouldNotBeUsed postinstall file manipulation

Requested Permissions

3 permissions
activeTab
Medium
storage
Low
clipboardWrite
Low

About This Extension

Are you still using the same password for every website/app you sign up for? In your workplace lan there is a “Passwords.docx” file full of sensitive data? You heard about password managers but they are no way easy to setup and use? At the same time Google, Twitter et all are telling you to use a mix of numbers, symbols and letters and at least 8-10 characters long passwords. I know, our human brain was not programmed to remember all this things… Introducing Aprico: the dead easy yet secure password manager. Aprico deterministically generates for you a different secure password for every account you’ll ever need. And you just need to remember an ID and a Master Password. Aprico also doesn’t need to sync any vault or any other kind of data. You don’t even need to create an account in order to use it. - Dead Simple Aprico UX was designed from its inception to be as simple and frictionless as possible. - Privacy Oriented Aprico works 100% in your browser. No data will ever be sent to any server or cloud owned by us or by third parties. Read more in our privacy policy: https://aprico.org/privacy.html - Works everywhere You can use Aprico online, with your smartphone and directly in your browser with this web extension. - Secure Aprico generates your password using “scrypt”, one of the strongest cryptography algorithm out there. - Open Source Aprico is free and open-source software. Everyone is free to review, audit, and contribute to it.

Detailed Findings

13 total

YARA Rule Matches

9 rules

Indicators of Compromise

Network indicators, suspicious strings, and potential IoCs extracted during analysis

URLs
24
IP Addresses
4
Domains
40
Strings
66

All Indicators · 66

Domain
detected Domain: clearfn.call

XIOC detected Domain: clearfn.call

extracted_from_files

Domain
detected Domain: window.chrome

XIOC detected Domain: window.chrome

extracted_from_files

URL
detected URL: https://github.com/dchest/scrypt-async-js

XIOC detected URL: https://github.com/dchest/scrypt-async-js

extracted_from_files

URL
detected URL: http://jsperf.com/call-apply-segu

XIOC detected URL: http://jsperf.com/call-apply-segu

extracted_from_files

URL
detected URL: https://clients2.google.com/service/update2/crx

XIOC detected URL: https://clients2.google.com/service/update2/crx

extracted_from_files

URL
detected URL: https://aprico.org

XIOC detected URL: https://aprico.org

extracted_from_files

URL
detected URL: https://bugzilla.mozilla.org/show_bug.cgi?id=1012662#c51

XIOC detected URL: https://bugzilla.mozilla.org/show_bug.cgi?id=1012662#c51

extracted_from_files

URL
detected URL: https://stackoverflow.com/questions/34045777/copy-to-clipboard-using-javascript-in-ios

XIOC detected URL: https://stackoverflow.com/questions/34045777/copy-to-clipboard-using-javascript-in-ios

extracted_from_files

URL
detected URL: http://github.com/stewartlord/identicon.js

XIOC detected URL: http://github.com/stewartlord/identicon.js

extracted_from_files

URL
detected URL: http://www.xarg.org/download/pnglib.js

XIOC detected URL: http://www.xarg.org/download/pnglib.js

extracted_from_files

URL
detected URL: http://www.opensource.org/licenses/bsd-license.php

XIOC detected URL: http://www.opensource.org/licenses/bsd-license.php

extracted_from_files

URL
detected URL: https://gist.github.com/aemkei/1325937

XIOC detected URL: https://gist.github.com/aemkei/1325937

extracted_from_files

URL
detected URL: http://www.w3.org/2000/svg'

XIOC detected URL: http://www.w3.org/2000/svg'

extracted_from_files

URL
detected URL: https://developer.microsoft.com/en-us/microsoft-edge/platform/issues/9421085/

XIOC detected URL: https://developer.microsoft.com/en-us/microsoft-edge/platform/issues/9421085/

extracted_from_files

URL
detected URL: https://aprico.org/privacy.html

XIOC detected URL: https://aprico.org/privacy.html

extracted_from_files

URL
detected URL: https://addons.mozilla.org/firefox/addon/aprico-free-password-manager/

XIOC detected URL: https://addons.mozilla.org/firefox/addon/aprico-free-password-manager/

extracted_from_files

URL
detected URL: https://chrome.google.com/webstore/detail/aprico-free-password-mana/anghijfdmgonjcmljokbndedjcjdldbk

XIOC detected URL: https://chrome.google.com/webstore/detail/aprico-free-password-mana/anghijfdmgonjcmljokbndedjcjdldbk

extracted_from_files

Domain
detected Domain: github.com

XIOC detected Domain: github.com

extracted_from_files

URL
detected URL: http://hansifer.com/clipboardCopyTest.html

XIOC detected URL: http://hansifer.com/clipboardCopyTest.html

extracted_from_files

URL
detected URL: http://www.w3.org/2000/svg

XIOC detected URL: http://www.w3.org/2000/svg

extracted_from_files

URL
detected URL: http://www.w3.org/1999/xlink

XIOC detected URL: http://www.w3.org/1999/xlink

extracted_from_files

URL
detected URL: http://basscss.com

XIOC detected URL: http://basscss.com

extracted_from_files

URL
detected URL: https://rot47.net/base.html)

XIOC detected URL: https://rot47.net/base.html)

extracted_from_files

URL
detected URL: https://github.com/mozilla/webextension-polyfill/issues/3

XIOC detected URL: https://github.com/mozilla/webextension-polyfill/issues/3

extracted_from_files

Domain
detected Domain: apply.call

XIOC detected Domain: apply.call

extracted_from_files

IP
detected IP: ::

XIOC detected IP: ::

extracted_from_files

Domain
detected Domain: slice.call

XIOC detected Domain: slice.call

extracted_from_files

Domain
detected Domain: fn.call

XIOC detected Domain: fn.call

extracted_from_files

Domain
detected Domain: clients2.google.com

XIOC detected Domain: clients2.google.com

extracted_from_files

Other
detected Email: [email protected]

XIOC detected Email: [email protected]

extracted_from_files

URL
detected URL: http://www.w3.org/Graphics/SVG/1.1/DTD/svg11.dtd

XIOC detected URL: http://www.w3.org/Graphics/SVG/1.1/DTD/svg11.dtd

extracted_from_files

Domain
detected Domain: platform.android

XIOC detected Domain: platform.android

extracted_from_files

Domain
detected Domain: this.data

XIOC detected Domain: this.data

extracted_from_files

Domain
detected Domain: cachedsettimeout.call

XIOC detected Domain: cachedsettimeout.call

extracted_from_files

Domain
detected Domain: cachedcleartimeout.call

XIOC detected Domain: cachedcleartimeout.call

extracted_from_files

Domain
detected Domain: this.fun

XIOC detected Domain: this.fun

extracted_from_files

Domain
detected Domain: item.prototype.run

XIOC detected Domain: item.prototype.run

extracted_from_files

Domain
detected Domain: process.off

XIOC detected Domain: process.off

extracted_from_files

Domain
detected Domain: platform.mobile

XIOC detected Domain: platform.mobile

extracted_from_files

Domain
detected Domain: window.open

XIOC detected Domain: window.open

extracted_from_files

Domain
detected Domain: website.com

XIOC detected Domain: website.com

extracted_from_files

Domain
detected Domain: el.select

XIOC detected Domain: el.select

extracted_from_files

Domain
detected Domain: e.target

XIOC detected Domain: e.target

extracted_from_files

Domain
detected Domain: browser.runtime.id

XIOC detected Domain: browser.runtime.id

extracted_from_files

Domain
detected Domain: chrome.runtime.id

XIOC detected Domain: chrome.runtime.id

extracted_from_files

Domain
detected Domain: www.opensource.org

XIOC detected Domain: www.opensource.org

extracted_from_files

Domain
detected Domain: gist.github.com

XIOC detected Domain: gist.github.com

extracted_from_files

Domain
detected Domain: jsperf.com

XIOC detected Domain: jsperf.com

extracted_from_files

Domain
detected Domain: xarg.org

XIOC detected Domain: xarg.org

extracted_from_files

URL
detected URL: http://www.xarg.org/2010/03/generate-client-side-png-files-using-javascript/

XIOC detected URL: http://www.xarg.org/2010/03/generate-client-side-png-files-using-javascript/

extracted_from_files

Domain
detected Domain: section.id

XIOC detected Domain: section.id

extracted_from_files

Domain
detected Domain: array.prototype.slice.call

XIOC detected Domain: array.prototype.slice.call

extracted_from_files

Domain
detected Domain: developer.microsoft.com

XIOC detected Domain: developer.microsoft.com

extracted_from_files

Domain
detected Domain: addons.mozilla.org

XIOC detected Domain: addons.mozilla.org

extracted_from_files

Domain
detected Domain: chrome.google.com

XIOC detected Domain: chrome.google.com

extracted_from_files

Domain
detected Domain: hansifer.com

XIOC detected Domain: hansifer.com

extracted_from_files

Domain
detected Domain: bugzilla.mozilla.org

XIOC detected Domain: bugzilla.mozilla.org

extracted_from_files

Domain
detected Domain: stackoverflow.com

XIOC detected Domain: stackoverflow.com

extracted_from_files

Domain
detected Domain: www.xarg.org

XIOC detected Domain: www.xarg.org

extracted_from_files

Domain
detected Domain: www.w3.org

XIOC detected Domain: www.w3.org

extracted_from_files

Domain
detected Domain: basscss.com

XIOC detected Domain: basscss.com

extracted_from_files

Domain
detected Domain: btn-primary.is

XIOC detected Domain: btn-primary.is

extracted_from_files

Domain
detected Domain: btn-outline.is

XIOC detected Domain: btn-outline.is

extracted_from_files

Domain
detected Domain: aprico.org

XIOC detected Domain: aprico.org

extracted_from_files

Domain
detected Domain: rot47.net

XIOC detected Domain: rot47.net

extracted_from_files

URL
detected URL: https://developer.microsoft.com/en-us/microsoft-edge/platform/issues/7728456/

XIOC detected URL: https://developer.microsoft.com/en-us/microsoft-edge/platform/issues/7728456/

extracted_from_files

Security Analysis Summary

Security Analysis Overview

aprico: Free Password Manager is a Chrome Web Store extension published by [email protected]. Version 0.2.0 has been analyzed by the Risky Plugins security platform, receiving a risk score of 39.98/100 (LOW risk) based on 82 security findings.

Risk Assessment

This extension presents low security risk. Some minor findings were detected, but nothing that would prevent typical usage. Reviewing the detailed findings below is recommended before use in sensitive environments.

Findings Breakdown

  • High: 13 finding(s)
  • Medium: 69 finding(s)

What Was Analyzed

The security assessment covers multiple analysis categories:

  • Malware Detection: YARA rule matching against 2,400+ malware signatures
  • Secret Detection: Scanning for exposed API keys, tokens, and credentials
  • Static Analysis: Code-level security analysis for common vulnerability patterns
  • Network Analysis: Detection of suspicious network communications and endpoints
  • Obfuscation Detection: Identification of code obfuscation techniques

Developer Information

aprico: Free Password Manager is published by [email protected] on the Chrome Web Store marketplace. The extension has approximately 12 users.

Recommendation

Exercise caution with this extension. Review the detailed findings and ensure the requested permissions align with the extension's stated functionality before installation.

Frequently Asked Questions