Is Edgen AI: Spot Market Moves Anywhere. Faster. safe?

Medium risk

Edgen AI: Spot Market Moves Anywhere. Faster. is medium risk. Code analysis shows Edgen AI's content script runs on every website, not just crypto pages, and sends each page's title and URL to Google Analytics, tagged with a client ID that persists for the life of the install.

Edgen AIv0.0.42Chrome Web Store
45Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

SeverityHIGH
ClassUNWANTED
TypeUnexpected
CWECWE-359
SourceAI FOUND

Edgen AI reports the title and URL of every page you visit to Google Analytics

Code analysis shows Edgen AI's content script runs on every website, not just crypto pages, and sends each page's title and URL to Google Analytics, tagged with a client ID that persists for the life of the install.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You load any webpage while Edgen AI is installed, whether or not the page mentions crypto.

The content script is injected on every site because its manifest scope is <all_urls>.

The extension did this

Edgen AI sends that page's exact title and URL to Google Analytics, tied to a persistent per-install ID.

This happens on every page load, not only on pages relevant to the extension's stated crypto-ticker purpose.

02EvidenceFIELD TABLE
What each page-view event contains
FieldValueWhy it matters
Page URL
https://www.reddit.com/r/personalfinance/comments/abc123/The full address of the page you were on, including query parameters.
Page title
My bank statement shows an unexpected charge - redditThe page's title text, which can reveal what you were reading or searching.
Client ID
e93f2b7a-1c4d-4a2e-9b8f-6d0a5c7e4f21A random ID generated once and stored by the extension, so Google can link all your page views to the same install.
03EvidenceCODE COMPARE
The code that does this

The load listener has no crypto-content gate

What it actually does
Unconditional page-view firing on every load (content.js)content.js
// Fire a page view event on load
window.addEventListener("load", () => {
  chrome.runtime.sendMessage(
    {
      action: "firePageViewEvent",
      data: { title: document.title, url: document.location.href },
    },
    function (response) {
      console.log(response);
    }
  );
});
Background forwards it straight to Analytics (background.js)background.js
} else if (message.action === 'firePageViewEvent') {
  console.log("firePageViewEvent",message.data.title, message.data.url)
  Analytics.firePageViewEvent(message.data.title, message.data.url);
  sendResponse({ status: 'success' });
}
The GA4 request itself (google-analytics-module.js)scripts/google-analytics-module.js
async fireEvent(name, params = {}) {
  if (!params.session_id) {
    params.session_id = await this.getOrCreateSessionId();
  }
  if (!params.engagement_time_msec) {
    params.engagement_time_msec = DEFAULT_ENGAGEMENT_TIME_MSEC;
  }
  const response = await fetch(
    `${this.debug ? GA_DEBUG_ENDPOINT : GA_ENDPOINT}?measurement_id=${MEASUREMENT_ID}&api_secret=${API_SECRET}`,
    {
      method: 'POST',
      body: JSON.stringify({
        client_id: await this.getOrCreateClientId(),
        events: [{ name, params }]
      })
    }
  );
}

async firePageViewEvent(pageTitle, pageLocation, additionalParams = {}) {
  return this.fireEvent('page_view', {
    page_title: pageTitle,
    page_location: pageLocation,
    ...additionalParams
  });
}
04EvidenceTHIRD PARTY LIST
Where the page-view data ends up
  • www.google-analytics.com

    Google's GA4 Measurement Protocol endpoint. Receives the page title, page URL and a persistent per-install client ID for every page load.

05EvidencePLAIN NOTE
Observation

Static analysis finding. This behaviour was identified by reading the shipped extension code and has not yet been reproduced in a live run. The trigger conditions and the exact data sent are read from the code, not from an observed capture.

What it can do

Permissions this extension asks for, as declared in version 0.0.42. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Store data in your browser

    storage

  • See the address and title of every tab you have open

    tabs

  • Schedule its own background tasks

    alarms

Updated 30 September 2026gjfilfmjjgkpjbdjohdndhinaonepgei