Is GIPHY for Chrome safe?

Medium risk

GIPHY is medium risk. Each GIPHY popup open beacons usage.trackjs.com with a hardcoded token. On a JS error, capture.trackjs.com gets your user agent, popup URL, a click/text-input log, console history, and nav events. Not disclosed in the store listing.

Giphy, Inc. v3.13Chrome Web Store
45Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

SeverityMEDIUM
ClassUNWANTED
TypeUnexpected
CWECWE-359
SourceAI SANDBOX

TrackJS error monitoring transmits popup diagnostics to third-party servers

Each GIPHY popup open beacons usage.trackjs.com with a hardcoded token.

On a JS error, capture.trackjs.com gets your user agent, popup URL, a click/text-input log, console history, and nav events.

Not disclosed in the store listing.

01EvidenceNETWORK CAPTURE
Captured request
GEThttps://usage.trackjs.com/usage.gif?token=00a54533935841dea5b9a1d9b7395dd3&correlationId=fc85caf8-b0ef-45e1-82ca-725245fd6bea&application=web-extension&x=cd6e47c1-d714-4728-b444-e4084361f515
02EvidenceCODE COMPARE
Unknown block kind: code_compare

The data has shipped a block kind this view doesn't render yet. Raw payload below.

{
  "kind": "code_compare",
  "language": "js",
  "shipped": [],
  "deobfuscated": []
}
03EvidenceFIELD TABLE
Unknown block kind: field_table

The data has shipped a block kind this view doesn't render yet. Raw payload below.

{
  "kind": "field_table",
  "caption": "Data included in a TrackJS error POST to capture.trackjs.com/capture",
  "fields": []
}
04EvidenceTHIRD PARTY LIST
Third-party destinations
  • usage.trackjs.com

    Session beacon, fires on every popup load; receives token, correlationId, session UUID

  • capture.trackjs.com

    Error reporting, receives diagnostic JSON payload on JS exceptions; includes user agent, console log, interaction log

Updated 17 September 2026jlleokkdhkflpmghiioglgmnminbekdi