Is Datanyze Chrome Extension safe?

Medium risk

Datanyze is medium risk. Clicking reveal on a matched profile prepares a POST to Datanyze's my-data service with the person's ID, company ID, a fixed source label, and profile URL from page data. The capture did not reach this flow, so no request body was recorded.

Datanyzev6.8.12Chrome Web Store
45Risk
Who publishes it

ZoomInfo Technologies Inc. - 3 other listings from the same operator, none carrying a finding

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
Datanyze
Declared legal entity
ZoomInfo Technologies Inc.
Registered address
805 Broadway St Ste 900, Vancouver, WA 98660-3506, US
Registered contact
DataNyze

Same operator - 3 listings

Published under a different store account, but sharing the registered address, contact or declared legal entity this one gave the store.

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

SeverityMEDIUM
ClassUNWANTED
TypeUnexpected
CWECWE-200
SourceAI SANDBOX

Reveal button posts matched profile identifiers to Datanyze

Clicking reveal on a matched profile prepares a POST to Datanyze's my-data service with the person's ID, company ID, a fixed source label, and profile URL from page data.

The capture did not reach this flow, so no request body was recorded.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You click the reveal button for a matched person.

The button handler runs only when the reveal control is enabled and has not already been clicked.

The extension did this

The extension dispatches the matched person record together with profile data from the page.

A later service method maps those records into the POST body for Datanyze's reveal endpoint.

02EvidenceFIELD TABLE
Fields the reveal service maps into the request
FieldValueWhy it matters
Matched person ID
personId: 41879231 (illustrative)This identifies the person record you asked the extension to reveal.
Matched company ID
companyId: 872645 (illustrative)This links the revealed person record to a company record.
Request source
EXTENSIONThis marks the request as coming from the browser extension rather than another Datanyze surface.
Social profile URL
https://www.linkedin.com/in/jordan-rivera-312a87 (illustrative)This ties the reveal request to the profile page associated with the matched person.
03EvidenceNETWORK CAPTURE
Captured request
POSThttps://api.datanyze.com/my-data/reveal-data
No request body or response was recorded because the traffic capture did not reach the successful reveal flow.
04EvidenceCODE COMPARE
The code that does this

The click handler and reveal service in shipped and deobfuscated code

What it actually does
Deobfuscated click handler and action dispatchdeobfuscated/987.js
function Zt(n, s) {
  if (1 & n) {
    const e = t.RV6();
    t.j41(0, "div", 11)(1, "dn-primary-btn", 12), t.bIt("click", function() {
      t.eBV(e);
      const o = t.XpG();
      return t.Njj(o.onRevealDetails())
    }), t.k0s()()
  }
  if (2 & n) {
    const e = t.XpG();
    t.R7$(), t.Y8G("text", e.primaryButtonText)("size", "medium")("disabled", e.isDisabled)("loading", e.loading)
  }
}

onRevealDetails() {
  this.isDisabled || this.isRevealButtonClicked || (this.isRevealButtonClicked = !0, this.loading = !0, this.sendEventToGa(N.Q), this.store.select(w.BH).pipe((0, x.s)(1)).subscribe(e => {
    this.store.dispatch((0, b.lx)({
      payload: {
        matchedData: [this._personDetails],
        scrapedData: (0, l.A)(e, "organizedScrapedData")
      }
    }))
  }))
}
Deobfuscated mapping and POSTdeobfuscated/main.js
const e = {
  env: "production",
  production: !0,
  COOKIE_TOKEN: "dn-tk",
  COOKIE_VERIFICATION_ID: "dn-verification-id",
  DN_NOTI_COOKIE_TOKEN: "dn-noti",
  DEVICE_ID: "deviceId",
  MATCH_MS_URL: "https://api.datanyze.com/match",
  MY_DATA_MS_URL: "https://api.datanyze.com/my-data",
  PAYMENT_MS_URL: "https://api.datanyze.com/payment",
  WEBSITE_URL: "https://www.datanyze.com",
  IDENTITY_MS_URL: "https://api.datanyze.com/identity",
  USER_SETTINGS_MS_URL: "https://api.datanyze.com/user-settings",
  CONFIG_MS_URL: "https://api.datanyze.com/config",
  DIRECTORIES_SITE_URL: "https://www.datanyze.com/people",
  PLATFORM_SITE_URL: "https://app.datanyze.com",
  DIRECTORY_MS_URL: "https://api.datanyze.com/directory/person"
}

revealData(g) {
  const b = function Ut(o, S) {
    return o.map(g => ({
      personId: (0, E.A)(g, "personId"),
      companyId: (0, E.A)(g, "companyId"),
      requestSource: ut.EXTENSION,
      ...S.find(lA => (0, E.A)(lA, "socialUrl") === (0, E.A)(g, "socialUrlId"))
    }))
  }((0, E.A)(g, "matchedData"), (0, E.A)(g, "scrapedData"));
  return this.httpClient.post(`${this.MY_DATA_ENDPOINT}/reveal-data`, b)
}

this.RevealMatchedPersonData$ = (0, D.EH)(() => this.actions$.pipe((0, D.gp)(IA.lx), (0, x.M)(() => this.nyzeService.update(wA.BT)), (0, eA.Z)(rA => this.myDataService.revealData(rA.payload).pipe((0, s.T)(sA => {
  const [UA] = sA || [], et = ot(UA);
  return this.sendEventToGa(Et, UA.personId || et.personId), (0, IA.kw)({
    payload: [et]
  })
}), (0, U.W)(sA => (0, MA.of)((0, IA.Nj)(sA)))))))
05EvidenceTHIRD PARTY LIST
Destination reached by the reveal flow
  • api.datanyze.com

    Datanyze API host that receives the reveal-data POST constructed by the extension.

Updated 30 September 2026mlholfadgbpidekmhdibonbjhdmpmafd