Is Easy Scraper - One-click web scraper safe?

Medium risk

Easy Scraper is medium risk. Signing in to Easy Scraper forwards your account ID and email to Amplitude and PostHog using hardcoded production keys. DA confirmed both transmissions with a marker value. Analytics can be disabled via analyticsEnabled, but defaults to on.

Easy Scraperv1.4.1Chrome Web Store
45Risk
Who publishes it

Easy Scraper - no other listings under this identity

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
Easy Scraper
Registered address
178 Rainbow Dr #7811, Livingston, TX 77399-1078, US
Registered contact
Road to Ramen LLC

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

SeverityMEDIUM
ClassUNWANTED
TypeUnexpected
CWECWE-359
SourceAI SANDBOX

Account ID and Email Sent to Amplitude and PostHog on Sign-In

Signing in to Easy Scraper forwards your account ID and email to Amplitude and PostHog using hardcoded production keys.

DA confirmed both transmissions with a marker value.

Analytics can be disabled via analyticsEnabled, but defaults to on.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You sign in to your Easy Scraper account through the extension popup.

The extension did this

The extension sends your account ID and email address to Amplitude and PostHog analytics using hardcoded production API keys.

Both identify calls fire within one second of sign-in and remain active as long as the analyticsEnabled storage key is true (the default).

02EvidenceFIELD TABLE
Data sent to both analytics platforms on sign-in:
FieldValueWhy it matters
Your account ID
usr_a1b2c3d4e5f6The internal identifier assigned to your Easy Scraper account. Becomes the persistent user key in both analytics platforms.
Your email address
jane.smith@example.comThe email you registered with. Links your analytics profile to a real-world identity.
03EvidenceNETWORK CAPTURE
Captured request
POSThttps://api2.amplitude.com/2/httpapi
Dynamic analysis confirmed: planted account ID and email appeared in the Amplitude request body. API key is hardcoded in the shipped extension.
Headers
Content-Typeapplication/json
Body
{
  "api_key": "31d8d26210941aeeb6ce60d058df53b1",
  "events": [
    {
      "user_id": "<account_id>",
      "event_type": "",
      "user_properties": {
        "": {
          "email": "<email_address>"
        }
      }
    }
  ]
}
04EvidenceNETWORK CAPTURE
Captured request
POSThttps://us.i.posthog.com/e/?ip=0&_=1780683970057&ver=1.270.1&compression=gzip-js
Dynamic analysis confirmed: the same planted account ID and email observed in the PostHog request (gzip-js decoded). Fired within 1 second of the Amplitude request.
Headers
Content-Typeapplication/octet-stream
Body
{
  "event": "",
  "properties": {
    "distinct_id": "<account_id>",
    "": {
      "email": "<email_address>"
    }
  }
}
05EvidenceCODE COMPARE
The code that does this

Analytics identify calls in the shipped and deobfuscated extension source

What it actually does
Amplitude identify — deobfuscated (background.js:11826-11832)background.js
identify: ({
  user: t
}) => {
  if (fO(t.id), t.email) {
    const e = new oo;
    e.set("email", t.email), cO(e)
  }
},
PostHog identify — deobfuscated (background.js:18394-18398)background.js
identify: ({
  user: t
}) => {
  jo.identify(t.id, {
    email: t.email
  })
},
Analytics listener wiring — deobfuscated (background.js:18428-18433)background.js
tn.analytics.posthogApiKey && Vf.init(), tn.analytics.amplitudeApiKey && Nd.init(), vC(async r => {
  await s0() && (tn.analytics.posthogApiKey && Vf.identify({
    user: r
  }), tn.analytics.amplitudeApiKey && Nd.identify({
    user: r
  }))
});
06EvidenceTHIRD PARTY LIST
Where account identity data is sent:
  • api2.amplitude.com

    Amplitude analytics, receives account ID as the persistent user identifier and email as a user property. Amplitude is owned by Amplitude, Inc. (San Francisco, CA).

  • us.i.posthog.com

    PostHog product analytics, receives account ID as distinct_id and email in the $set payload. PostHog is an open-source analytics platform; the US cloud is operated by PostHog, Inc.

What it can do

Permissions this extension asks for, as declared in version 1.4.1. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Act on the current tab, but only after you click the extension

    activeTab

  • Run its own code inside the pages you visit

    scripting

  • Store data in your browser

    storage

Updated 30 September 2026cljbfnedccphacfneigoegkiieckjndh