Starting analysis...
Version 990.106.88 View in Chrome Web Store
The extension has a substantial user base of 1 million users, which suggests some level of adoption. However, the extremely low rating of 1.6 out of 5 stars from 140 reviews is a major red flag, indicating widespread user dissatisfaction or potential issues. The lack of clear developer information and company details further undermines trust. While the name suggests it's a security product ("Web Protection Advanced"), the poor ratings contradict this positioning.
The extension exhibits an alarming combination of invasive permissions that far exceed what most legitimate security tools require. The ability to intercept, modify, and block all web requests combined with access to browsing history, downloads, and identity information creates a perfect storm for data theft or malicious activity. The broad host permissions and content script injection capabilities mean this extension can monitor and manipulate every website you visit. The dangerous permission combination of webRequest and webRequestBlocking is particularly concerning as it allows real-time traffic manipulation. The poor user ratings strongly suggest the extension may not be functioning as advertised or may be causing problems.
Do not install this extension. The critical risk level, poor user ratings, and excessive permissions make it unsuitable for use. If web protection is needed, choose a well-established security vendor with transparent company information and positive user reviews. If already installed, remove it immediately and scan your system for potential security issues.
| https://google.com/search | https://www.google.com/search | |
| https://www.perplexity.ai/b/home | https://cloudinfra-gw.portal.checkpoint.com/auth/external | |
| https://rep.checkpoint.com/rep-auth/service/v1.0/request | http://www.w3.org/2001/XMLSchema-instance | |
| https://gwevents.checkpoint.com/gwstats/services/antimalware/1_0_0/log | https://web-rep.iaas.checkpoint.com/web-rep/feedback | |
| https://web-rep.checkpoint.com/web-rep/query | https://rep.checkpoint.com/url-rep/service/v2.0/query?resource= | |
| https://api-iam.intercom.io/messenger/web/ping | https://api.openai.com/auth | |
| https://api.openai.com/profile | https://chatgpt.com/backend-api/ | |
| https://www.surveymonkey.com/r/web-secure-uninstall-survey | https://clients2.google.com/service/update2/crx | |
| https://www.checkpoint.com/products/advanced-endpoint-protection/ | https://www.zonealarm.com/ | |
| https://www.zonealarm.com/anti-phishing | https://www.zonealarm.com/software/web-secure-free | |
| https://url-rep.kube1.iaas.checkpoint.com/url-rep-ioc/service/v2.0/query?resource= | https://file-rep.kube1.iaas.checkpoint.com/file-rep-ioc/service/v2.0/query?resource= | |
| https://url-rep.iaas.checkpoint.com/url-rep-ioc/service/v2.0/query?resource= | https://file-rep.iaas.checkpoint.com/file-rep-ioc/service/v2.0/query?resource= | |
| https://fonts.googleapis.com/css2?family=Open+Sans&display=swap | https://sc1.checkpoint.com/sba/ff/stg.json | |
| https://sc1.checkpoint.com/sba/ff/prod.json | http://www.w3.org/TR/html4/strict.dtd | |
| http://172.23.57.148/UserCheck/PortalMain?IID=BC15F7FD-B352-1DC9-BCFF-3BA462E295F5&origUrl=aHR0cDovL2FtYXpvbi5jb20v | https://www.checkpoint.com/privacy/ | |
| https://fonts.googleapis.com/css?family=Inter | https://sc1.checkpoint.com/www/images/layout/duke/check-point-logo.png | |
| https://fonts.gstatic.com/s/opensans/v13/DXI1ORHCpsQm3Vp6mXoaTRsxEYwM7FgeyaSgU71cLG0.woff | https://fonts.gstatic.com/s/opensans/v13/uYKcPVoh6c5R0NpdEY5A-Q.woff | |
| https://fonts.gstatic.com/s/opensans/v13/MTP_ySUJH_bn48VBG8sNShsxEYwM7FgeyaSgU71cLG0.woff | https://fonts.gstatic.com/s/opensans/v13/k3k702ZOKiLJc3WVjuplzBsxEYwM7FgeyaSgU71cLG0.woff | |
| https://fonts.gstatic.com/s/opensans/v13/EInbV5DfGHOiMmvb1Xr-hhsxEYwM7FgeyaSgU71cLG0.woff | https://fonts.gstatic.com/s/opensans/v13/PRmiXeptR36kaC0GEAetxv25ds880Du_gFZbUlZlsbg.woff | |
| https://fonts.gstatic.com/s/opensans/v13/O4NhV7_qs9r9seTo7fnsVD8E0i7KZn-EPnyo3HZu7kw.woff | https://fonts.gstatic.com/s/opensans/v13/PRmiXeptR36kaC0GEAetxsUW6j0fiq4_bYOAoMNnBhA.woff | |
| https://fonts.gstatic.com/s/opensans/v13/PRmiXeptR36kaC0GEAetxpXMLUeV6_io0G3F6eXSVcg.woff | https://fonts.gstatic.com/s/opensans/v13/PRmiXeptR36kaC0GEAetxjZJchHK-lPtiIaM3GRtbZU.woff | |
| https://www.w3.org/TR/xml/#dt-charref | http://www.w3.org/2000/svg | |
| http://www.w3.org/1999/xlink | https://jquery.com/ | |
| https://sizzlejs.com/ | https://jquery.org/license | |
| https://github.com/eslint/eslint/issues/6125 | http://jquery.org/license | |
| https://jsperf.com/thor-indexof-vs-for/5 | http://www.w3.org/TR/css3-selectors/#whitespace | |
| http://www.w3.org/TR/CSS21/syndata.html#value-def-identifier | http://www.w3.org/TR/selectors/#attribute-selectors | |
| http://www.w3.org/TR/CSS21/syndata.html#escaped-characters | https://drafts.csswg.org/cssom/#common-serializing-idioms | |
| https://html.spec.whatwg.org/multipage/scripting.html#selector-enabled | https://html.spec.whatwg.org/multipage/scripting.html#selector-disabled | |
| https://html.spec.whatwg.org/multipage/forms.html#category-listed | https://html.spec.whatwg.org/multipage/forms.html#concept-fe-disabled | |
| https://html.spec.whatwg.org/multipage/forms.html#concept-option-disabled | https://bugs.jquery.com/ticket/13378 | |
| https://bugs.jquery.com/ticket/12359 | https://msdn.microsoft.com/en-us/library/ie/hh465388.aspx#attribute_section | |
| http://www.w3.org/TR/2011/REC-css3-selectors-20110929/#checked | https://bugs.webkit.org/show_bug.cgi?id=136851 | |
| https://github.com/jquery/sizzle/pull/225 | http://www.w3.org/TR/selectors/#pseudo-classes | |
| http://www.w3.org/TR/selectors/#lang-pseudo | http://www.w3.org/TR/selectors/#empty-pseudo | |
| https://msdn.microsoft.com/en-us/library/ms536429%28VS.85%29.aspx | https://promisesaplus.com/#point-59 | |
| https://promisesaplus.com/#point-48 | https://promisesaplus.com/#point-54 | |
| https://promisesaplus.com/#point-75 | https://promisesaplus.com/#point-64 | |
| https://promisesaplus.com/#point-61 | https://promisesaplus.com/#point-57 | |
| https://bugs.chromium.org/p/chromium/issues/detail?id=378607 | https://www.w3.org/TR/DOM-Level-3-Events/#event-type-click |
{ "name": "Harmony Web Protection Advanced MV3", "icons": { "16": "data/icons/CheckPointLogo_16.png", "48": "data/icons/CheckPointLogo_48.png", "128": "data/icons/CheckPointLogo_128.png" }, "action": { "default_icon": { "19": "data/icons/CheckPointLogo_19.png" }, "default_title": "Harmony Web Protection" }, "storage": { "managed_schema": "schema.json" }, "version": "990.106.88", "incognito": "split", "background": { "matches": [ "<all_urls>" ], "service_worker": "background.js" }, "short_name": "Harmony", "update_url": "https://clients2.google.com/service/update2/crx", "description": "Protects users from advanced malware, phishing and zero-day attacks", "permissions": [ "webRequest", "webRequestBlocking", "downloads", "downloads.open", "downloads.ui", "storage", "unlimitedStorage", "notifications", "tabs", "activeTab", "history", "webNavigation", "contextMenus", "background", "identity", "identity.email", "alarms" ], "homepage_url": "https://www.checkpoint.com/products/advanced-endpoint-protection//", "default_locale": "en", "content_scripts": [ { "js": [ "data/cryptoJS-sha1.js", "data/cryptoJS-sha256.js", "data/cryptoJS-md5.js", "data/cryptoJS-aes.js", "data/cryptoJS-lib-typedarrays-min.js", "data/homoglyph.js", "data/utils.js", "data/password_reuse_contentscript.js", "data/url_reputation_contentscript.js", "data/zero_phishing_contentscript.js", "data/upload_protection_contentscript.js", "data/dlp_contentscript.js", "data/dlp_contentscript_async.js", "data/contentscript_utils.js", "data/toast_notification_contentscript.js", "data/prompt_notification_contentscript.js", "data/dlp_prompt_notification_contentscript.js", "data/dlp_common.js", "data/notification_contentscript.js", "data/mutation_observer.js", "data/favicon_fetcher.js", "data/common.js", "data/global_types.js", "data/ssdeep.js", "data/hooks.js", "data/feature_flags.js", "data/manage_storage.js", "data/content_script.js" ], "run_at": "document_end", "matches": [ "<all_urls>" ], "all_frames": true, "match_about_blank": false } ], "host_permissions": [ "<all_urls>" ], "manifest_version": 3, "content_security_policy": { "extension_pages": "script-src 'self' ; object-src 'self'" }, "web_accessible_resources": [ { "matches": [ "<all_urls>" ], "resources": [ "verifying_image.png", "data/BlockSite.html", "data/BlockSite-PR.html", "data/BlockSite-ZP.html", "data/BlockSite-Local-html.html", "data/downloader.html", "data/icons/errorIcon.svg", "data/icons/Harmony.svg", "data/icons/OKicon.svg", "data/icons/warningIcon.svg", "data/one_time_link.js", "data/iframe_download.js", "data/json_read.js", "data/css/Toast.css", "data/css/Prompt.css", "data/css/DLPPrompt.css", "data/notify_events.js", "data/broken_links.js", "data/track_input_creation.js", "data/icons/info_status_icon.svg", "data/icons/success_status_icon.svg", "data/icons/warning_status_icon.svg", "data/icons/error_status_icon.svg", "data/icons/ext_icon.svg", "data/icons/toast_arrow.gif", "data/icons/toast_cb_checked.svg", "data/icons/prompt_close_button.svg", "data/icons/prompt_company_icon.svg", "data/downloader.js", "data/shadow_root_detection.js", "data/focus_handler.js", "data/show_file_picker.js", "data/notify_clipboard_change.js", "data/spa_navigation_handler.js", "data/lexical_editor_input.js" ] } ] }
ⓘ CRXaminer has partnered with our friends at Secure Annex to provide additional findings unique to their platform.
Secure Annex also analyzes extensions from other browsers, IDEs, and can continuously monitor.
This extension may not yet be analyzed by Secure Annex.