pull down to refresh
It make totally sense. Well is a small extension I build and I trust there's no malicious code. Either way I'm just using it to check other people addresses. Your feedback on the idea and what other info could be shown will be appreciated.
reply
Sorry to be negative. My feedback is: don't use extensions.
If you really want to pursue it - you probably will, I get it - please make sure you don't add any external dependencies and don't accept any pull requests where you don't know what every character in the new code does.
reply
Thank you, I'll definitely! I much appreciate your feedback.
reply
fetch
, you don't seem to have a supply chain outside the browser itself at a glance so in this particular extension the only way to inject the exploit would be to either introduce a dependency in a PR on your repo and then attack that, or introduce the first 4 lines of the exploit in an obscured way directly into your codebase.BAI++
which looks nicer and has the vulnerability and then, when I have 10k installs, I activate the exploit.