Version 990.106.106 View in Chrome Web Store
The extension has a substantial user base of 1 million users, which suggests some level of adoption. However, the extremely low rating of 1.6 out of 5 stars from 140 reviews is a major red flag indicating widespread user dissatisfaction or potential malicious behavior. The lack of clear author and developer information further undermines trust and accountability.
The extension exhibits an alarming combination of dangerous permissions that far exceed what's necessary for typical web protection. The webRequest and webRequestBlocking permissions allow complete interception and modification of all web traffic, while the identity permission can access personal information. The broad host permissions and content script injection capabilities mean this extension can monitor and manipulate every website you visit. The downloads permission adds another vector for potential data exfiltration. Most concerning is that these extensive permissions, combined with the poor user ratings, suggest the extension may be functioning as malware disguised as security software.
Do not install or immediately remove this extension. The combination of critical security findings, poor user ratings, and excessive permissions creates an unacceptable risk profile. If web protection is needed, choose a reputable security vendor with transparent developer information and positive user feedback. Consider using built-in browser security features or well-established security extensions from verified companies instead.
| https://google.com/search | https://www.google.com/search | |
| https://www.perplexity.ai/b/home | https://cloudinfra-gw.portal.checkpoint.com/auth/external | |
| https://rep.checkpoint.com/rep-auth/service/v1.0/request | http://www.w3.org/2001/XMLSchema-instance | |
| https://gwevents.checkpoint.com/gwstats/services/antimalware/1_0_0/log | https://web-rep.iaas.checkpoint.com/web-rep/feedback | |
| https://web-rep.checkpoint.com/web-rep/query | https://rep.checkpoint.com/url-rep/service/v2.0/query?resource= | |
| https://api-iam.intercom.io/messenger/web/ping | https://api.openai.com/auth | |
| https://api.openai.com/profile | https://chatgpt.com/backend-api/ | |
| https://www.surveymonkey.com/r/web-secure-uninstall-survey | https://clients2.google.com/service/update2/crx | |
| https://www.checkpoint.com/products/advanced-endpoint-protection/ | https://www.zonealarm.com/ | |
| https://www.zonealarm.com/anti-phishing | https://www.zonealarm.com/software/web-secure-free | |
| https://url-rep.kube1.iaas.checkpoint.com/url-rep-ioc/service/v2.0/query?resource= | https://file-rep.kube1.iaas.checkpoint.com/file-rep-ioc/service/v2.0/query?resource= | |
| https://url-rep.iaas.checkpoint.com/url-rep-ioc/service/v2.0/query?resource= | https://file-rep.iaas.checkpoint.com/file-rep-ioc/service/v2.0/query?resource= | |
| https://fonts.googleapis.com/css2?family=Open+Sans&display=swap | https://sc1.checkpoint.com/sba/ff/stg.json | |
| https://sc1.checkpoint.com/sba/ff/prod.json | http://www.w3.org/TR/html4/strict.dtd | |
| http://172.23.57.148/UserCheck/PortalMain?IID=BC15F7FD-B352-1DC9-BCFF-3BA462E295F5&origUrl=aHR0cDovL2FtYXpvbi5jb20v | https://www.checkpoint.com/privacy/ | |
| https://fonts.googleapis.com/css?family=Inter | https://sc1.checkpoint.com/www/images/layout/duke/check-point-logo.png | |
| https://fonts.gstatic.com/s/opensans/v13/DXI1ORHCpsQm3Vp6mXoaTRsxEYwM7FgeyaSgU71cLG0.woff | https://fonts.gstatic.com/s/opensans/v13/uYKcPVoh6c5R0NpdEY5A-Q.woff | |
| https://fonts.gstatic.com/s/opensans/v13/MTP_ySUJH_bn48VBG8sNShsxEYwM7FgeyaSgU71cLG0.woff | https://fonts.gstatic.com/s/opensans/v13/k3k702ZOKiLJc3WVjuplzBsxEYwM7FgeyaSgU71cLG0.woff | |
| https://fonts.gstatic.com/s/opensans/v13/EInbV5DfGHOiMmvb1Xr-hhsxEYwM7FgeyaSgU71cLG0.woff | https://fonts.gstatic.com/s/opensans/v13/PRmiXeptR36kaC0GEAetxv25ds880Du_gFZbUlZlsbg.woff | |
| https://fonts.gstatic.com/s/opensans/v13/O4NhV7_qs9r9seTo7fnsVD8E0i7KZn-EPnyo3HZu7kw.woff | https://fonts.gstatic.com/s/opensans/v13/PRmiXeptR36kaC0GEAetxsUW6j0fiq4_bYOAoMNnBhA.woff | |
| https://fonts.gstatic.com/s/opensans/v13/PRmiXeptR36kaC0GEAetxpXMLUeV6_io0G3F6eXSVcg.woff | https://fonts.gstatic.com/s/opensans/v13/PRmiXeptR36kaC0GEAetxjZJchHK-lPtiIaM3GRtbZU.woff | |
| https://www.w3.org/TR/xml/#dt-charref | http://www.w3.org/2000/svg | |
| http://www.w3.org/1999/xlink | https://jquery.com/ | |
| https://sizzlejs.com/ | https://jquery.org/license | |
| https://github.com/eslint/eslint/issues/6125 | http://jquery.org/license | |
| https://jsperf.com/thor-indexof-vs-for/5 | http://www.w3.org/TR/css3-selectors/#whitespace | |
| http://www.w3.org/TR/CSS21/syndata.html#value-def-identifier | http://www.w3.org/TR/selectors/#attribute-selectors | |
| http://www.w3.org/TR/CSS21/syndata.html#escaped-characters | https://drafts.csswg.org/cssom/#common-serializing-idioms | |
| https://html.spec.whatwg.org/multipage/scripting.html#selector-enabled | https://html.spec.whatwg.org/multipage/scripting.html#selector-disabled | |
| https://html.spec.whatwg.org/multipage/forms.html#category-listed | https://html.spec.whatwg.org/multipage/forms.html#concept-fe-disabled | |
| https://html.spec.whatwg.org/multipage/forms.html#concept-option-disabled | https://bugs.jquery.com/ticket/13378 | |
| https://bugs.jquery.com/ticket/12359 | https://msdn.microsoft.com/en-us/library/ie/hh465388.aspx#attribute_section | |
| http://www.w3.org/TR/2011/REC-css3-selectors-20110929/#checked | https://bugs.webkit.org/show_bug.cgi?id=136851 | |
| https://github.com/jquery/sizzle/pull/225 | http://www.w3.org/TR/selectors/#pseudo-classes | |
| http://www.w3.org/TR/selectors/#lang-pseudo | http://www.w3.org/TR/selectors/#empty-pseudo | |
| https://msdn.microsoft.com/en-us/library/ms536429%28VS.85%29.aspx | https://promisesaplus.com/#point-59 | |
| https://promisesaplus.com/#point-48 | https://promisesaplus.com/#point-54 | |
| https://promisesaplus.com/#point-75 | https://promisesaplus.com/#point-64 | |
| https://promisesaplus.com/#point-61 | https://promisesaplus.com/#point-57 | |
| https://bugs.chromium.org/p/chromium/issues/detail?id=378607 | https://www.w3.org/TR/DOM-Level-3-Events/#event-type-click |
{ "name": "Harmony Web Protection Advanced MV3", "icons": { "16": "data/icons/CheckPointLogo_16.png", "48": "data/icons/CheckPointLogo_48.png", "128": "data/icons/CheckPointLogo_128.png" }, "action": { "default_icon": { "19": "data/icons/CheckPointLogo_19.png" }, "default_title": "Harmony Web Protection" }, "storage": { "managed_schema": "schema.json" }, "version": "990.106.106", "incognito": "split", "background": { "matches": [ "<all_urls>" ], "service_worker": "background.js" }, "short_name": "Harmony", "update_url": "https://clients2.google.com/service/update2/crx", "description": "Protects users from advanced malware, phishing and zero-day attacks", "permissions": [ "webRequest", "webRequestBlocking", "downloads", "downloads.open", "downloads.ui", "storage", "unlimitedStorage", "notifications", "tabs", "activeTab", "history", "webNavigation", "contextMenus", "background", "identity", "identity.email", "alarms" ], "homepage_url": "https://www.checkpoint.com/products/advanced-endpoint-protection//", "default_locale": "en", "content_scripts": [ { "js": [ "data/cryptoJS-sha1.js", "data/cryptoJS-sha256.js", "data/cryptoJS-md5.js", "data/cryptoJS-aes.js", "data/cryptoJS-lib-typedarrays-min.js", "data/homoglyph.js", "data/utils.js", "data/password_reuse_contentscript.js", "data/url_reputation_contentscript.js", "data/zero_phishing_contentscript.js", "data/upload_protection_contentscript.js", "data/dlp_contentscript.js", "data/dlp_contentscript_async.js", "data/contentscript_utils.js", "data/toast_notification_contentscript.js", "data/prompt_notification_contentscript.js", "data/dlp_prompt_notification_contentscript.js", "data/dlp_common.js", "data/notification_contentscript.js", "data/mutation_observer.js", "data/favicon_fetcher.js", "data/favicon_fetcher_wrapper.js", "data/common.js", "data/global_types.js", "data/ssdeep.js", "data/hooks.js", "data/feature_flags.js", "data/manage_storage.js", "data/clickfix_utils_cs.js", "data/content_script.js" ], "run_at": "document_end", "matches": [ "<all_urls>" ], "all_frames": true, "match_about_blank": false } ], "host_permissions": [ "<all_urls>" ], "manifest_version": 3, "content_security_policy": { "extension_pages": "script-src 'self' ; object-src 'self'" }, "web_accessible_resources": [ { "matches": [ "<all_urls>" ], "resources": [ "verifying_image.png", "data/BlockSite.html", "data/BlockSite-PR.html", "data/BlockSite-ZP.html", "data/BlockSite-Local-html.html", "data/downloader.html", "data/icons/errorIcon.svg", "data/icons/Harmony.svg", "data/icons/OKicon.svg", "data/icons/warningIcon.svg", "data/one_time_link.js", "data/iframe_download.js", "data/json_read.js", "data/css/Toast.css", "data/css/Prompt.css", "data/css/DLPPrompt.css", "data/notify_events.js", "data/broken_links.js", "data/track_input_creation.js", "data/icons/info_status_icon.svg", "data/icons/success_status_icon.svg", "data/icons/warning_status_icon.svg", "data/icons/error_status_icon.svg", "data/icons/ext_icon.svg", "data/icons/toast_arrow.gif", "data/icons/toast_cb_checked.svg", "data/icons/prompt_close_button.svg", "data/icons/prompt_company_icon.svg", "data/downloader.js", "data/shadow_root_detection.js", "data/focus_handler.js", "data/show_file_picker.js", "data/notify_clipboard_change.js", "data/spa_navigation_handler.js", "data/lexical_editor_input.js" ] } ] }
ⓘ CRXaminer has partnered with our friends at Secure Annex to provide additional findings unique to their platform.
Secure Annex also analyzes extensions from other browsers, IDEs, and can continuously monitor.
This extension may not yet be analyzed by Secure Annex.