Is Email Extractor: Scrape Emails From Websites safe?
Email Extractor is medium risk. Account features in Email Extractor: Scrape Emails From Websites post account and email-verification data, including credentials and page content, to myemailextractor.com endpoints, tied to signup, verification, exchange, or cancellation.…
Who publishes itsally - 3 other listings from the same operator, none carrying a finding
sally - 3 other listings from the same operator, none carrying a finding
What this publisher told the store about itself, and the other listings that told it the same thing.
Same store account
3 other listings published from this account, 7k+ users between them, none of them carrying a finding.
Shared hosts - 2 hostnames
Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
Account and email verification data sent to MyEmailExtractor API.
Account features in Email Extractor: Scrape Emails From Websites post account and email-verification data, including credentials and page content, to myemailextractor.com endpoints, tied to signup, verification, exchange, or cancellation.
The user takes an account-related action in the extension.
The extension posts account and email verification data to myemailextractor.com API endpoints.
| Field | Value | Why it matters | |
|---|---|---|---|
Account credential values | user@example.com (illustrative) | Email, user ID, verification code, or subscription ID values identify the account action being processed. | |
Page content context | example.com contact page (illustrative) | Page-derived email extraction context can connect browsing activity with the account workflow. |
Observed during dynamic analysis, these account API calls required prior Google OAuth login, so the session did not produce live traffic to myemailextractor.com. The confirmed database evidence records POST account API functions for adduser, verifier, exchange, and cancel subscription flows.
Extracted email page data sent to mapsscraper.ai endpoint.
When you use the email extraction feature, the extension sends collected page DOM content to mapsscraper.ai for email lookup and enrichment: a POST to https://mapsscraper.ai/api/getmails with JSON containing that content.
The user starts the email extraction feature.
The extension sends collected page DOM content to mapsscraper.ai for email lookup and enrichment.
| Field | Value | Why it matters | |
|---|---|---|---|
Page DOM content | <html><body>Contact us at team@example.com</body></html> (illustrative) | The page structure and text can include email addresses and surrounding page context collected for the lookup feature. |
Dynamic analysis previously could not exercise the network request because the feature required a logged-in account, but the claim is confirmed by the database evidence for the popup-to-background flow and POST request.
What it can do
Permissions this extension asks for, as declared in version 2.5.7. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Read and change your data on every site you visit
<all_urls>
Store data in your browser
storage
See the address and title of every tab you have open
tabs
Sign you in with your Google account
identity