Version 0.23 View in Chrome Web Store
The extension has very limited adoption with only 175 users and lacks basic transparency indicators such as developer information, ratings, or reviews. The absence of these trust signals makes it difficult to verify the legitimacy and reliability of the extension. The specific focus on Gmail integration suggests a targeted functionality, but the minimal user base raises questions about its maturity and testing.
The primary concern is the use of Manifest V2, which provides fewer security protections compared to the newer V3 standard. This older framework allows for more permissive security policies and potentially riskier extension behaviors. The permission to access mail.google.com grants the extension significant access to your Gmail account, including the ability to read, modify, and potentially extract email content. The lack of developer transparency, combined with low user adoption, creates uncertainty about the extension's true purpose and data handling practices.
Consider running this extension in a separate Chrome profile to isolate it from your main browsing environment and other sensitive accounts. Before installation, verify the extension's functionality matches your specific needs for secure messaging. Monitor your Gmail account for any unusual activity after installation. Given the low user base and lack of transparency, consider looking for alternative secure messaging solutions with better established reputations and Manifest V3 compliance. If you must use this extension, regularly review its permissions and remove it if no longer needed.
| https://chrome.google.com/webstore/detail/secure-mail-for-gmail-by/jngdnjdobadbdemillgljnnbpomnfokn/reviews?hl=en&gl=US | https://chrome.google.com/webstore/detail/message-secure-send/ilgobmalecajfdmdbeonojopeglcfgpg | |
| http://developer.chrome.com/extensions/contentSecurityPolicy.html | https://clients2.google.com/service/update2/crx | |
| https://mail.google.com/ | http://crypto-js.googlecode.com/svn/tags/3.1.2/build/rollups/aes.js |
{ "name": "Message Secure Send", "icons": { "16": "icon_unread_16.png", "48": "icon_unread_48.png", "128": "icon_unread_128.png" }, "version": "0.23", "short_name": "Message Secure", "update_url": "https://clients2.google.com/service/update2/crx", "description": "This extension securely encrypts/decrypts Gmail™", "permissions": [ "https://mail.google.com/" ], "browser_action": { "default_icon": "icon_unread_16.png", "default_popup": "popup.html" }, "manifest_version": 2 }
ⓘ CRXaminer has partnered with our friends at Secure Annex to provide additional findings unique to their platform.
Secure Annex also analyzes extensions from other browsers, IDEs, and can continuously monitor.
This extension may not yet be analyzed by Secure Annex.