Is CrossPilot safe?
CrossPilot fetches and executes code from third-party URLs on every web page every 30 minutes.
Every 30 minutes, CrossPilot contacts an update URL stored at install time (from crosspilot.io) with no domain allow-list restriction. The downloaded ZIP is unpacked and injected as content scripts into all pages (http://*/* https://*/*) in the MAIN world, allowing remotely-served code to run with full page access. Additionally, on each startup the extension sends a persistent device UUID along with the installed sub-app name, version, and appId to Google Analytics.
Part of this rating comes from analysis signals we haven't published as detailed findings yet.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.