Is Altair GraphQL Client safe?

Medium risk

Altair loads third-party plugin code from cdn.jsdelivr.net or a user URL and runs it with access to your GraphQL queries and auth headers.

When a user enables a plugin, Altair fetches its JavaScript from cdn.jsdelivr.net (npm or GitHub) or a raw URL and injects it into the app via a script tag with no integrity check, defaulting npm plugins to the mutable "latest" version. The loaded plugin runtime can read and rewrite the current GraphQL query, variables, and request headers, including Bearer tokens and API keys. This only applies to plugins the user has explicitly added to their plugin list.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

imolorhev8.5.7Chrome Web Store
45Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Data recipients

cdn.jsdelivr.netuser-supplied plugin URLs
Updated 17 September 2026flnheeellpciglgpaodhkhmapeljopja