postMessage-tracker-f

Monitors postMessage usage (url, domain and stack) both by logging using CORS and also visually as an extension-icon. All credit goes to Frans Rosén.

postMessage-tracker-f is a Firefox extension designed to monitor postMessage listeners effectively. It provides a visual icon indicator displaying the number of active listeners in the current window, including all subframes, and highlights potentially vulnerable functions. This powerful tool logs detailed listener information—such as URL, domain, and call stack—via CORS to a configurable endpoint, enabling in-depth analysis of message event listeners, including short-lived and interaction-enabled ones.

Built as a super simple port of the original extension by Frans Rosén, postMessage-tracker-f supports unwrapping listeners wrapped by popular frameworks like Raven, New Relic, Rollbar, Bugsnag, and jQuery to reveal the actual listener functions. It also reroutes wrappers for clear DevTools console visibility. The extension aids developers and security professionals in auditing cross-window communication, detecting hidden or suspicious listeners, and enhancing web application security. Fully open-source, it encourages community contributions and bug reports through its GitHub repository.

By:
Hacks and Hops
Daily users:
142 6
Rating:
5.00
(1)
Version:
1.1.2 Last updated: 2024-01-24
Version code:
5682120
Creation date:
2024-01-18
Risk:
High risk impact Low risk likelihood
Permissions:
  • tabs
  • storage
  • <all_urls>
Size:
31.48K
URLs:
Website
Full description:
See detailed description
Source:
Firefox Browser Add-ons
Updated:
a day ago

Extension safety

Risk impact

postMessage-tracker-f requires some sensitive permissions that could impact your browser and data security. Exercise caution before installing.

Risk impact analysis details
  • Critical Grants access to browser tabs, which can be used to track user browsing habits and history, presenting a privacy concern.
  • Critical ****** ****** ** *** ********* ****** * *********** ******** **** ** ** *** ******* *** ****** **** **** *** ******* *****
  • High ******* ******* **** *** ****** ***** *** ***** ** ******* **** ********* ********* ** * *********** *****
Risk likelihood

postMessage-tracker-f has earned a fairly good reputation and likely can be trusted.

Risk likelihood analysis details
  • High This extension has low user count. Unpopular extensions may not be stable or safe.
  • Low **** ********* *** ******* **** **** * ****** **** ***** ******** *** **** ****** ** ** ****** *** *****
  • Low **** ********* *** ***** **** **** * ****** **** ***** ********** *** **** ****** ** ** ****** *** *****
  • Good **** ********* *** **** **** *******
Upgrade to see full risk analysis details

Compare add-ons

Similar add-ons

Here are some Firefox add-ons that are similar to postMessage-tracker-f:

Popular extensions / apps

Here are some popular extensions / apps that you might be interested in: