Is Bitly | Short links and QR Codes safe?
Bitly | Short links and QR Codes ships a hardcoded OAuth client_secret in its extension bundle.
The extension includes a Bitly OAuth client ID and client_secret directly in its background script, accessible to anyone who extracts the extension package. The credentials are used to exchange authorization codes for access tokens via the Bitly API. The redirect URI is tied to the extension's specific Chrome ID, which limits the practical impact of the exposure.
Part of this rating comes from analysis signals we haven't published as detailed findings yet.
Who publishes itBitly Inc - no other listings under this identity, 4 shared hostnames
Bitly Inc - no other listings under this identity, 4 shared hostnames
What this publisher told the store about itself, and the other listings that told it the same thing.
Shared hosts - 4 hostnames
Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Where it sends data
Destinations our analysis observed Bitly contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.
- api-ssl.bitly.com
Bitly sends data to api-ssl.bitly.com. 6 other extensions we have analysed send data here.