Is GIPHY for Chrome safe?
GIPHY is medium risk. Each GIPHY popup open beacons usage.trackjs.com with a hardcoded token. On a JS error, capture.trackjs.com gets your user agent, popup URL, a click/text-input log, console history, and nav events. Not disclosed in the store listing.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
TrackJS error monitoring transmits popup diagnostics to third-party servers
Each GIPHY popup open beacons usage.trackjs.com with a hardcoded token.
On a JS error, capture.trackjs.com gets your user agent, popup URL, a click/text-input log, console history, and nav events.
Not disclosed in the store listing.
code_compareThe data has shipped a block kind this view doesn't render yet. Raw payload below.
{
"kind": "code_compare",
"language": "js",
"shipped": [],
"deobfuscated": []
}field_tableThe data has shipped a block kind this view doesn't render yet. Raw payload below.
{
"kind": "field_table",
"caption": "Data included in a TrackJS error POST to capture.trackjs.com/capture",
"fields": []
}- usage.trackjs.com
Session beacon, fires on every popup load; receives token, correlationId, session UUID
- capture.trackjs.com
Error reporting, receives diagnostic JSON payload on JS exceptions; includes user agent, console log, interaction log