Is Easy Scraper - One-click web scraper safe?
Easy Scraper is medium risk. Signing in to Easy Scraper forwards your account ID and email to Amplitude and PostHog using hardcoded production keys. DA confirmed both transmissions with a marker value. Analytics can be disabled via analyticsEnabled, but defaults to on.
Who publishes itEasy Scraper - no other listings under this identity
Easy Scraper - no other listings under this identity
What this publisher told the store about itself, and the other listings that told it the same thing.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
Account ID and Email Sent to Amplitude and PostHog on Sign-In
Signing in to Easy Scraper forwards your account ID and email to Amplitude and PostHog using hardcoded production keys.
DA confirmed both transmissions with a marker value.
Analytics can be disabled via analyticsEnabled, but defaults to on.
You sign in to your Easy Scraper account through the extension popup.
The extension sends your account ID and email address to Amplitude and PostHog analytics using hardcoded production API keys.
Both identify calls fire within one second of sign-in and remain active as long as the analyticsEnabled storage key is true (the default).
| Field | Value | Why it matters | |
|---|---|---|---|
Your account ID | usr_a1b2c3d4e5f6 | The internal identifier assigned to your Easy Scraper account. Becomes the persistent user key in both analytics platforms. | |
Your email address | jane.smith@example.com | The email you registered with. Links your analytics profile to a real-world identity. |
| Content-Type | application/json |
{
"api_key": "31d8d26210941aeeb6ce60d058df53b1",
"events": [
{
"user_id": "<account_id>",
"event_type": "",
"user_properties": {
"": {
"email": "<email_address>"
}
}
}
]
}| Content-Type | application/octet-stream |
{
"event": "",
"properties": {
"distinct_id": "<account_id>",
"": {
"email": "<email_address>"
}
}
}Analytics identify calls in the shipped and deobfuscated extension source
identify: ({
user: t
}) => {
if (fO(t.id), t.email) {
const e = new oo;
e.set("email", t.email), cO(e)
}
},identify: ({
user: t
}) => {
jo.identify(t.id, {
email: t.email
})
},tn.analytics.posthogApiKey && Vf.init(), tn.analytics.amplitudeApiKey && Nd.init(), vC(async r => {
await s0() && (tn.analytics.posthogApiKey && Vf.identify({
user: r
}), tn.analytics.amplitudeApiKey && Nd.identify({
user: r
}))
});- api2.amplitude.com
Amplitude analytics, receives account ID as the persistent user identifier and email as a user property. Amplitude is owned by Amplitude, Inc. (San Francisco, CA).
- us.i.posthog.com
PostHog product analytics, receives account ID as distinct_id and email in the $set payload. PostHog is an open-source analytics platform; the US cloud is operated by PostHog, Inc.
What it can do
Permissions this extension asks for, as declared in version 1.4.1. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Act on the current tab, but only after you click the extension
activeTab
Run its own code inside the pages you visit
scripting
Store data in your browser
storage