Is Edgen AI: Spot Market Moves Anywhere. Faster. safe?
Edgen AI: Spot Market Moves Anywhere. Faster. is medium risk. Code analysis shows Edgen AI's content script runs on every website, not just crypto pages, and sends each page's title and URL to Google Analytics, tagged with a client ID that persists for the life of the install.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
Edgen AI reports the title and URL of every page you visit to Google Analytics
Code analysis shows Edgen AI's content script runs on every website, not just crypto pages, and sends each page's title and URL to Google Analytics, tagged with a client ID that persists for the life of the install.
You load any webpage while Edgen AI is installed, whether or not the page mentions crypto.
The content script is injected on every site because its manifest scope is <all_urls>.
Edgen AI sends that page's exact title and URL to Google Analytics, tied to a persistent per-install ID.
This happens on every page load, not only on pages relevant to the extension's stated crypto-ticker purpose.
| Field | Value | Why it matters | |
|---|---|---|---|
Page URL | https://www.reddit.com/r/personalfinance/comments/abc123/ | The full address of the page you were on, including query parameters. | |
Page title | My bank statement shows an unexpected charge - reddit | The page's title text, which can reveal what you were reading or searching. | |
Client ID | e93f2b7a-1c4d-4a2e-9b8f-6d0a5c7e4f21 | A random ID generated once and stored by the extension, so Google can link all your page views to the same install. |
The load listener has no crypto-content gate
// Fire a page view event on load
window.addEventListener("load", () => {
chrome.runtime.sendMessage(
{
action: "firePageViewEvent",
data: { title: document.title, url: document.location.href },
},
function (response) {
console.log(response);
}
);
});} else if (message.action === 'firePageViewEvent') {
console.log("firePageViewEvent",message.data.title, message.data.url)
Analytics.firePageViewEvent(message.data.title, message.data.url);
sendResponse({ status: 'success' });
}async fireEvent(name, params = {}) {
if (!params.session_id) {
params.session_id = await this.getOrCreateSessionId();
}
if (!params.engagement_time_msec) {
params.engagement_time_msec = DEFAULT_ENGAGEMENT_TIME_MSEC;
}
const response = await fetch(
`${this.debug ? GA_DEBUG_ENDPOINT : GA_ENDPOINT}?measurement_id=${MEASUREMENT_ID}&api_secret=${API_SECRET}`,
{
method: 'POST',
body: JSON.stringify({
client_id: await this.getOrCreateClientId(),
events: [{ name, params }]
})
}
);
}
async firePageViewEvent(pageTitle, pageLocation, additionalParams = {}) {
return this.fireEvent('page_view', {
page_title: pageTitle,
page_location: pageLocation,
...additionalParams
});
}- www.google-analytics.com
Google's GA4 Measurement Protocol endpoint. Receives the page title, page URL and a persistent per-install client ID for every page load.
Static analysis finding. This behaviour was identified by reading the shipped extension code and has not yet been reproduced in a live run. The trigger conditions and the exact data sent are read from the code, not from an observed capture.
What it can do
Permissions this extension asks for, as declared in version 0.0.42. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Store data in your browser
storage
See the address and title of every tab you have open
tabs
Schedule its own background tasks
alarms