Is CrossPilot safe?

Low risk

CrossPilot fetches and executes code from third-party URLs on every web page every 30 minutes.

Every 30 minutes, CrossPilot contacts an update URL stored at install time (from crosspilot.io) with no domain allow-list restriction. The downloaded ZIP is unpacked and injected as content scripts into all pages (http://*/* https://*/*) in the MAIN world, allowing remotely-served code to run with full page access. Additionally, on each startup the extension sends a persistent device UUID along with the installed sub-app name, version, and appId to Google Analytics.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

crosspilot.iov2.3.0Chrome Web Store
20Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Data recipients

crosspilot.iowww.google-analytics.com
Updated 10 September 2026migomhggnppjdijnfkiimcpjgnhmnale