Item logo image for Walilock

Walilock

ExtensionPrivacy & Security
Item media 3 (screenshot) for Walilock
Item media 1 (screenshot) for Walilock
Item media 2 (screenshot) for Walilock
Item media 3 (screenshot) for Walilock
Item media 1 (screenshot) for Walilock
Item media 1 (screenshot) for Walilock
Item media 2 (screenshot) for Walilock
Item media 3 (screenshot) for Walilock

Overview

Walilock — fill saved logins and use passkeys from your desktop vault, and be warned if a site is reported for phishing.

Walilock keeps your passwords and passkeys in a vault on your own computer. This extension is the browser half of that: it fills a saved login when you ask it to, signs you in with a passkey, and warns you if the site you are about to use a saved credential on has been reported for phishing. It requires the Walilock desktop app, which holds the vault and does the encryption. Without the app installed and unlocked, this extension can do nothing at all. FILLING A SAVED LOGIN Click the Walilock button in your browser's toolbar and pick the login you want. A web page cannot start this — there is no way for a site to ask the extension for a password, to request the list of what you have saved, or to trigger a fill. The only thing that begins it is your click on the toolbar button. Which logins match is decided by the desktop app, from the site's domain. The password is read out of your vault by the app at the moment you choose it, passed straight into the form, and kept nowhere else. It is never written to browser storage. PASSKEYS When a site asks your browser to create or use a passkey, this extension hands that request to the desktop app, which holds the keys and signs with them. Your vault is opened and decrypted on your own device, and only the answer to that one request comes back. On a site where you already have a saved login but no passkey yet, it lets you know the site supports passkeys, so you can add one in that site's account settings and Walilock will store it. Choose "Not for this site" and it stops mentioning it there for thirty days. THE PHISHING WARNING Where you have a saved login for a site, the extension asks the desktop app whether that exact address appears on a list of addresses reported as phishing, and warns you before you fill. It warns; it does not block, and it is not a general site scanner — a site you have no saved login for is never checked at all, because the question exists to protect a credential you are about to use. That list is downloaded, never queried. Your computer fetches a signed copy and checks addresses against it locally. Nobody is told which site you are on. WHAT LEAVES YOUR COMPUTER Nothing. This extension has no account, no server, and no network access of its own. Everything it does, it does by asking the Walilock desktop app over a local channel on the same machine. Privacy policy: https://www.walilock.com/privacy

Details

  • Version
    0.3.0
  • Updated
    September 17, 2026
  • Size
    116KiB
  • Languages
    English (United States)
  • Developer
    Website
    Email
    support@walilock.com
  • Non-trader
    This developer has not identified itself as a trader. For consumers in the European Union, please note that consumer rights do not apply to contracts between you and this developer.

Privacy

Manage extensions and learn how they're being used in your organization

Walilock has disclosed the following information regarding the collection and usage of your data. More detailed information can be found in the developer's privacy policy.

Walilock handles the following:

Personally identifiable information
Authentication information
Web history

This developer declares that your data is

  • Not being sold to third parties, outside of the approved use cases
  • Not being used or transferred for purposes that are unrelated to the item's core functionality
  • Not being used or transferred to determine creditworthiness or for lending purposes

Support

For help with questions, suggestions, or problems, visit the developer's support site

Google apps