Is Ground News - Bias Checker safe?

Medium risk

Shows how other news outlets cover the article you are reading.

This extension displays related coverage from news outlets worldwide so you can compare reporting on the same story. It also shows bias and factuality ratings for sources, works with listed social media sites, and can save articles for later with in-text citations.

Ground Newsv3.2.1Chrome Web Store
45Risk
Who publishes it

Ground News - no other listings under this identity, 4 shared hostnames

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
Ground News

Shared hosts - 4 hostnames

Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.

extension.ground.news
Also called by 2 other listings, including Ground News Bias Checker
groundnews.b-cdn.net
Also called by 2 other listings, including Ground News Bias Checker
production.checkitt.news
Also called by 2 other listings, including Ground News Bias Checker
ground.news
Also called by 3 other listings, including Ground News Bias Checker

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

SeverityMEDIUM
ClassUNWANTED
TypeUnexpected
CWECWE-200
SourceAI SANDBOX

Navigation URLs are sent to Ground News search

Opening or updating a page sends the tab URL to `extension.ground.news/search` as a query parameter.

Captured GET requests covered example.com, Google, Amazon, and Reddit; the code also appends page title when available.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You open or update a web page in a tab.

The behavior is tied to normal browsing, not to pressing the extension button.

The extension did this

The extension sends that page URL to the Ground News search endpoint.

When the helper receives a title, it appends the title to the same request.

02EvidenceFIELD TABLE
Fields carried in the search request
FieldValueWhy it matters
Visited page URL
https://www.example.com/Shows the exact page you opened, which can reveal browsing history and reading interests.
Page title
Example Domain (illustrative)Adds readable page context when the request helper is called with a title.
03EvidenceNETWORK CAPTURE
Captured request
GEThttps://extension.ground.news/search?url=https%3A%2F%2Fwww.example.com%2F
Observed during dynamic analysis; additional navigations to Google, Amazon, and Reddit produced the same search endpoint pattern.
04EvidenceCODE COMPARE
The code that does this

The helper builds the request and the tab-update listener calls it for tab URLs

What it actually does
Readable request helper in js/background.jsjs/background.js
const t = async (e, r) => {
  try {
    let s = `https://extension.ground.news/search?url=${encodeURIComponent(e)}`;
    r && (s = `${s}&title=${encodeURIComponent(r)}`);
    const t = await fetch(s);
    return await (null == t ? void 0 : t.json())
  } catch (e) {}
}
Readable tab update listener in js/background.jsjs/background.js
r.tabs.onUpdated.addListener((async (s, t, i) => {
  try {
    if (!i.url) return;
    let t = a.get(i.url);
    if (!t) {
      if (!(!!(o = i.url) && !o.includes("http://") && !o.includes("newtab"))) return t = {
        status: "invalid",
        timestamp: Date.now()
      }, void a.set(i.url, t);
      t = await n(i.url)
    }
    if ("processing" === t.status) return;
    if (Date.now() - t.timestamp > 3e5 && (t = await n(i.url)), "invalid" === t.status) return;
    const g = t.payload;
    if (!(null == g ? void 0 : g.event)) return;
    const m = await (async e => await r.tabs.sendMessage(e, {
      action: "CHECK_IF_FRAME_EXISTS"
    }))(s);
    if (m) return;
    await (async (s, t) => {
      await r.tabs.sendMessage(s, {
        action: e.OpenPopup,
        event: t.event,
        source: t.source
      })
    })(s, {
      event: g.event,
      source: g.source
    });
    const {
      sessionID: l
    } = await r.storage.local.get("sessionID");
    l && g.refId && await (async (e, r) => {
      try {
        await fetch(`https://production.checkitt.news/api/v04/article/trackOpen/${e}`, {
          headers: {
            Authorization: r
          }
        })
      } catch (e) {}
    })(g.refId, l), g.event.sourceCount && await r.action.setBadgeText({
      text: g.event.sourceCount.toString(),
      tabId: s
    })
  } catch (e) {}
  var o
}))
05EvidenceTHIRD PARTY LIST
Remote host receiving the browsing context
  • extension.ground.news

    Receives the URL-encoded page URL through the `/search` endpoint and can receive the page title when the helper is called with one.

What it can do

Permissions this extension asks for, as declared in version 3.2.1. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Read and change your data on extension.ground.news

    https://extension.ground.news/*

  • Read and change your data on production.checkitt.news

    https://production.checkitt.news/api/*

  • See the address and title of every tab you have open

    tabs

  • Store data in your browser

    storage

Where it sends data

Destinations our analysis observed Ground News contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.

  • Ground News

    Ground News sends data to Ground News. Named as a recipient in this extension's own analysis.

Updated 30 September 2026agleiimpggapjekcdhdjbmegjbbkleie