Is Adminer - Capturar anúncios e produtos grátis safe?

Medium risk

Adminer is medium risk. Using this extension on Facebook sends a record of your actions to Mixpanel, tied to a persistent device ID, on every page load, including events like opening the Ad Library. It embeds the full Mixpanel SDK with a hardcoded project token.

adminer-extensionv10.5Chrome Web Store
45Risk
Who publishes it

adminer-extension - no other listings under this identity

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
adminer-extension

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

SeverityMEDIUM
ClassUNWANTED
TypeUnexpected
CWECWE-359
SourceAI SANDBOX

Mixpanel analytics tracks Facebook behavior without disclosure

Using this extension on Facebook sends a record of your actions to Mixpanel, tied to a persistent device ID, on every page load, including events like opening the Ad Library.

It embeds the full Mixpanel SDK with a hardcoded project token.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You open any Facebook page with the extension installed.

The extension's content script runs automatically on facebook.com, www.facebook.com, and web.facebook.com.

The extension did this

The extension sends a record of your action to Mixpanel's servers.

The embedded Mixpanel SDK POSTs an event (e.g. 'facebook_library_opened') along with a persistent device identifier to api-js.mixpanel.com.

02EvidenceNETWORK CAPTURE
Captured request
POSThttps://api-js.mixpanel.com/track/?verbose=1&ip=1
Mixpanel returns {"status": 1, "error": null} confirming the event was recorded.
Headers
Content-Typeapplication/x-www-form-urlencoded
Body
data=%7B%22event%22%3A%22facebook_library_opened%22%2C%22properties%22%3A%7B%22token%22%3A%220af857f7a94003c0783978582c67ee0c%22%2C%22distinct_id%22%3A%22%24device%3A19e9b4205a92f4-0ec4263bf8b2ed8-19525631-140000-19e9b4205a92f4%22%2C%22%24current_url%22%3A%22https%3A%2F%2Fwww.facebook.com%2F%22%7D%7D
03EvidenceFIELD TABLE
Data fields sent to Mixpanel per event
FieldValueWhy it matters
Device identifier
$device:19e9b4205a92f4-0ec4263bf8b2ed8-19525631-140000-19e9b4205a92f4A persistent ID assigned to your browser that links all events across every session, even without an account.
Event name
facebook_library_openedDescribes what action you took on Facebook (e.g. opening the Ad Library).
Current page URL
https://www.facebook.com/ads/libraryThe full URL of the Facebook page you were on when the event fired.
Mixpanel project token
0af857f7a94003c0783978582c67ee0cHardcoded identifier that routes all events to the extension developer's private Mixpanel dashboard.
04EvidenceCODE COMPARE
The code that does this

Mixpanel initialisation and event tracking in content.js

What it actually does
Readable equivalentcontent.js
// Initialise Mixpanel with the developer's private project token
mixpanel.init("0af857f7a94003c0783978582c67ee0c", { track_pageview: false });

// Helper: optionally tie the event to a known user ID, then track
function trackEvent(eventName, props, userId) {
  if (userId) mixpanel.identify(userId);
  mixpanel.track(eventName, props);
}

// Fire when the user opens the Facebook Ad Library
if (isFacebookLibrary()) trackEvent("facebook_library_opened", {});
05EvidenceTHIRD PARTY LIST
External host receiving data
  • api-js.mixpanel.com

    Mixpanel event ingestion endpoint. Receives event names, device ID, and page URL from every tracked Facebook interaction. Accessible to the developer on their Mixpanel dashboard.

What it can do

Permissions this extension asks for, as declared in version 10.5. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • See the address and title of every tab you have open

    tabs

Updated 30 September 2026amolhiihcpdbkjimhlffamgieibhfapi