ExtensionPedia
1Password – Password Manager

1Password – Password Manager

The best way to experience 1Password in your browser. Easily sign in to sites, generate passwords, and store secure information.

Risk Summary

4.8 /10

Medium Risk

For extension version 8.12.8.26

View latest version
Critical Permissions Severity
No CVEs
Updated Version Age
Manifest V3
Fair Engagement Rate
CVEs

This extension version has not been scanned for CVEs yet

Behavioral Detections

Behavioral Detections

Unlock the full MITRE ATT&CK matrix

Request a Demo
Permissions (18)
Name Severity
Management

Extensions with the management permission can manage your installed apps, extensions, and themes. If the extension is force-installed, it can disable other extensions.

Critical
Request Read

Access to network traffic

Critical
Scripting

Extensions with the scripting permission can inject and execute code in web pages, which can potentially be used for data exfiltration or session hijacking (requires host permissions, available since Manifest V3).

Critical
declarativeNetRequestWithHostAccess

Requires host permissions for actions using the chrome.declarativeNetRequest API.

High
Privacy

Extensions with the privacy permission can manage browser features that may affect user privacy and safety, for example turn off phishing protection (safeBrowsingEnabled).

High
Tabs

Extensions with the tabs permission can query the url, pendingUrl, title, and favIconUrl of any tab.

High
Web Navigation

Extensions with the webNavigation permission can track websites the user visits by listening to navigation events.

High
Alarms

Extensions with the alarms permission can schedule code to run periodically or at a specified time in the future.

Medium
Bookmarks

Extensions with the bookmarks permission can create, organize, and otherwise manipulate bookmarks.

Medium
Context Menus

Extensions with the contextMenus permission can add items to the browser's context menu (also known as the right-click menu).

Medium
Downloads

Extensions with the downloads permission can programmatically initiate, monitor, manipulate, and search for downloads. This can be used to download scripts.

Medium
Idle

Extensions with the idle permission can detect whether the machine is idle, in use, or locked.

Medium
Native Messaging

Extensions with the nativeMessaging permission can communicate with cooperating applications installed on the user's machine.

Medium
Off Screen

Use the offscreen API to create and manage offscreen documents.

Medium
Storage

Extensions with the storage permission can store and retrieve user data, which can persist even after clearing the cache and browsing history.

Medium
Web Request Auth Provider

Enables browser extensions to handle HTTP authentication requests and provide authentication credentials automatically

Medium
Favicon

Grants access to the Favicon API.

Low
Notifications

Extensions with the notifications permission can display notifications on the user's desktop.

Low
Host Permissions (1)
<all_urls>
Secrets (6)
Secret Type Secret (Redacted)
CloudflareApiToken ? Cloudflare is a web infrastructure and website security company, providing content delivery network services, DDoS mitigation, Internet security, and distributed domain name server services. Cloudflare API tokens can be used to manage and interact with Cloudflare services.

lhpp********************ast-

CloudflareApiToken ? Cloudflare is a web infrastructure and website security company, providing content delivery network services, DDoS mitigation, Internet security, and distributed domain name server services. Cloudflare API tokens can be used to manage and interact with Cloudflare services.

lhpp********************ast-

URI ? This detector identifies URLs with embedded credentials, which can be used to access web resources without explicit user interaction.

https://4f3669ef553b434e86845ecd15a92e28:********@b5x-sentry.1passwordservices.com/4505427098533888

URI ? This detector identifies URLs with embedded credentials, which can be used to access web resources without explicit user interaction.

https://4f3669ef553b434e86845ecd15a92e28:********@b5x-sentry.1passwordservices.com/4505427098533888

CloudflareApiToken ? Cloudflare is a web infrastructure and website security company, providing content delivery network services, DDoS mitigation, Internet security, and distributed domain name server services. Cloudflare API tokens can be used to manage and interact with Cloudflare services.

lhpp********************ast-

CloudflareApiToken ? Cloudflare is a web infrastructure and website security company, providing content delivery network services, DDoS mitigation, Internet security, and distributed domain name server services. Cloudflare API tokens can be used to manage and interact with Cloudflare services.

lhpp********************ast-

Privacy Policy

Privacy Policy

Unlock privacy policy risk assessment

Request a Demo