Pendo Launcher Chrome extension icon

Pendo Launcher

🔍 Security Report Available
👥 1M+ users
📦 v5.57.4
💾 2.6MiB
📅 2026-02-06
View on Chrome Web Store

Chrome will indicate if you already have this installed.

Overview

Pendo simplifies complex user experiences by bringing automated, personalized guidance to your employees within the software applications they use for work. Just-in-time resources help teams increase productivity and improve compliance, step-by-step guides boost your training efforts, and comprehensive analytics help you understand application usage and behaviors.

The Pendo Launcher browser extension facilitates quick mass deployment of digital adoption solutions to your full suite of employee-facing applications with just a few clicks:

Guidance:
In-app guides deliver training inside software, where work actually gets done
Train more effectively with personalized guidance for different roles
Improve change management and compliance with timely communication

Insights:
Understand application usage with comprehensive analytics
Analyze user behavior to understand causes of friction and increase productivity
Measure training completion and effectiveness to drive improvements

Feedback:
Collect actionable feedback about employee-facing software at scale
Identify common requests to prioritize changes and improve training
Prioritize investments in high-impact system updates

Learn more about Pendo’s digital adoption solutions at https://www.pendo.io/

Tags

Productivity/workflow productivity/workflow

Privacy Practices

Not being sold to third parties, outside of the approved use cases
Not being used or transferred for purposes that are unrelated to the item's core functionality
Not being used or transferred to determine creditworthiness or for lending purposes
✅ Version v5.59.2 was recently scanned.
v5.59.2 Info Scanned Mar 7, 2026

Security Analysis — Pendo Launcher

Analyzed v5.59.2 · Mar 7, 2026 · 17 JS files · 8616 KB scanned

Permissions

alarms contextMenus declarativeNetRequestWithHostAccess identity identity.email scripting sidePanel storage tabs webNavigation <all_urls>

Code Patterns Detected

Alternative to eval (execScript) charCodeAt (obfuscation) Creates script elements dynamically Potential hardcoded secret Creates iframe elements Uses postMessage for cross-origin comms Sets up event listeners

External Connections

www.w3.org cdn.pendo.io v3-migration.vuejs.org vuejs.org github.com support.pendo.io agent.pendo.io app.pendo.io app.au.pendo.io app.eu.pendo.io app.gov.pendo.io app.hsbc.pendo.io +8 more

Package Contents 34 files · 9.3MB

📁_metadata5KB
{}verified_contents.json5KB
📁agent2.6MB
📜debugger-plugin.min.js18KB
🎨guide.css16KB
📜pendo.debugger.min.js1.6MBlarge
📜pendo.preview.min.js1019KBlarge
📁fonts
📁icons15KB
🖼browser-action-discovery.png1KB
🖼browser-action-off.png1KB
🖼browser-action-on.png5KB
🖼browser-action-recording.png1KB
🖼logo.png5KB
📜agent-content.js897KBlarge
📜background.js157KBlarge
📜browser-ingest-content.js1KB
🎨configuration.css289KB
🌐configuration.html676B
📜configuration.js985KBlarge
🌐demo-loader.html1KB
📜demo-loader.js17KB
📜designer.js1.6MBlarge
📜double-agent.js808KBlarge
📜idp-metadata.js5KB
🎨idp.css280KB
🌐idp.html362B
📜idp.js632KBlarge
📜iframe-visibility-monitor.js139KBlarge
🎨initialize-pendo.css280KB
🌐initialize-pendo.html388B
📜initialize-pendo.js633KBlarge
{}managed_schema.json684B
{}manifest.json2KB
📜pendo-extensions.js40B
📜postmessage-safeguard.js1KB
📜public-identify.js151B
🎨resource-center-animation.css4KB

What This Extension Does

The Pendo Launcher browser extension facilitates quick mass deployment of digital adoption solutions to your full suite of employee-facing applications. It simplifies complex user experiences by bringing automated, personalized guidance to employees within software applications they use for work. This extension is suitable for organizations looking to improve productivity and compliance among their employees.

Permissions Explained

  • alarmsexpected: This permission allows the extension to display notifications on your browser.
    Technical: The extension can access Chrome's alarm system, which enables it to send notifications to the user. This could be used for legitimate purposes such as alerting users about new features or updates.
  • contextMenusexpected: This permission allows the extension to add custom menu items to your browser's context menu.
    Technical: The extension can access Chrome's context menus, which enables it to display additional options in the right-click menu. This could be used for legitimate purposes such as providing quick access to Pendo's features.
  • declarativeNetRequestWithHostAccessexpected: This permission allows the extension to modify network requests made by your browser.
    Technical: The extension can access Chrome's declarative net request API, which enables it to intercept and modify HTTP requests. This could be used for legitimate purposes such as optimizing network performance or blocking malicious content.
  • identityexpected: This permission allows the extension to access your Google account information.
    Technical: The extension can access Chrome's identity API, which enables it to retrieve user data such as email addresses and authentication tokens. This could be used for legitimate purposes such as authenticating users or personalizing their experience.
  • identity.emailexpected: This permission allows the extension to access your email address.
    Technical: The extension can access Chrome's identity API, which enables it to retrieve user data such as email addresses. This could be used for legitimate purposes such as authenticating users or sending notifications.
  • scriptingexpected: This permission allows the extension to execute scripts in your browser.
    Technical: The extension can access Chrome's scripting API, which enables it to run JavaScript code. This could be used for legitimate purposes such as enhancing user experience or providing additional features.
  • sidePanelexpected: This permission allows the extension to display a panel in your browser's sidebar.
    Technical: The extension can access Chrome's side panel API, which enables it to display additional content in the sidebar. This could be used for legitimate purposes such as providing quick access to Pendo's features or displaying notifications.
  • storageexpected: This permission allows the extension to store data locally on your device.
    Technical: The extension can access Chrome's storage API, which enables it to store user data such as preferences or authentication tokens. This could be used for legitimate purposes such as personalizing the user experience or authenticating users.
  • tabsexpected: This permission allows the extension to access and modify your browser's tabs.
    Technical: The extension can access Chrome's tab API, which enables it to retrieve or modify tab data such as URLs or titles. This could be used for legitimate purposes such as enhancing user experience or providing additional features.
  • webNavigationexpected: This permission allows the extension to intercept and modify your browser's navigation requests.
    Technical: The extension can access Chrome's web navigation API, which enables it to intercept and modify HTTP requests. This could be used for legitimate purposes such as optimizing network performance or blocking malicious content.
  • <all_urls>check this: This permission allows the extension to access all URLs visited by your browser.
    Technical: The extension can access Chrome's <all_urls> API, which enables it to intercept and modify HTTP requests for any URL. This could be used for malicious purposes such as tracking user activity or injecting malware. ⚠ 1

Your Data

The extension accesses your email address, stores data locally on your device, and sends data to Pendo's servers. It also intercepts and modifies network requests made by your browser.

Technical Details

The extension contacts the following domains: www.w3.org, cdn.pendo.io, v3-migration.vuejs.org, vuejs.org, github.com, support.pendo.io, agent.pendo.io, app.pendo.io, app.au.pendo.io, app.eu.pendo.io, app.gov.pendo.io, app.hsbc.pendo.io. It uses HTTPS encryption for most requests but may send unencrypted data in some cases.

Code Findings

Alternative to eval (execScript)Medium

The extension uses the execScript function instead of eval, which is a more secure way to execute JavaScript code.

Technical: The extension uses the execScript function in its background script to execute JavaScript code. This is a legitimate use case and does not pose any security risks.

💡 This pattern is commonly used in legitimate extensions to enhance user experience or provide additional features.

charCodeAt (obfuscation)Medium

The extension uses the charCodeAt function, which could be used for obfuscating code.

Technical: The extension uses the charCodeAt function in its background script to manipulate strings. This could potentially be used for obfuscating code or hiding malicious behavior.

💡 This pattern is commonly used in legitimate extensions to enhance user experience or provide additional features.

Creates script elements dynamicallyHigh

The extension creates script elements dynamically, which could be used for malicious purposes such as injecting malware.

Technical: The extension uses the document.createElement function to create script elements dynamically. This is a high-risk behavior and should be reviewed carefully.

💡 This pattern is commonly used in legitimate extensions to enhance user experience or provide additional features.

Potential hardcoded secretMedium

The extension contains a potential hardcoded secret, which could be used for malicious purposes such as authentication bypass.

Technical: The extension contains a string literal that appears to be a hardcoded secret. This should be reviewed carefully to ensure it is not being used for malicious purposes.

💡 This pattern is commonly used in legitimate extensions to enhance user experience or provide additional features.

Creates iframe elementsMedium

The extension creates iframe elements, which could be used for malicious purposes such as injecting malware.

Technical: The extension uses the document.createElement function to create iframe elements dynamically. This is a medium-risk behavior and should be reviewed carefully.

💡 This pattern is commonly used in legitimate extensions to enhance user experience or provide additional features.

Uses postMessage for cross-origin commsMedium

The extension uses the postMessage function for cross-origin communication, which could be used for malicious purposes such as data exfiltration.

Technical: The extension uses the postMessage function to communicate with other origins. This is a medium-risk behavior and should be reviewed carefully.

💡 This pattern is commonly used in legitimate extensions to enhance user experience or provide additional features.

Sets up event listenersInfo

The extension sets up event listeners, which could be used for malicious purposes such as tracking user activity.

Technical: The extension uses the addEventListener function to set up event listeners. This is a common pattern in legitimate extensions and does not pose any security risks.

💡 This pattern is commonly used in legitimate extensions to enhance user experience or provide additional features.

Bottom Line

The Pendo Launcher browser extension has some concerning behaviors, including the use of <all_urls> permission and potential hardcoded secrets. However, it also uses some secure practices such as using HTTPS encryption for most requests. Users should exercise caution when installing this extension and review its permissions carefully.

Do more in Google Chrome with Adobe Acrobat PDF tools. View, fill, comment, sign, and try convert and compress tools.
Productivity/workflow
Block ads on YouTube and your favorite sites for free
Productivity/workflow
Remove ads on YouTube and everywhere else you browse.
Productivity/workflow