Is GrowBot Automator for Instagram™ safe?
GrowBot is medium risk. When GrowBot finishes loading extra data for an Instagram account, it posts a completion record: viewer IG handle, target username, numeric ID, and lookup details. Dynamic analysis didn't observe this POST; the queue action never completed.…
Who publishes itGrowbot - no other listings under this identity, 3 shared hostnames
Growbot - no other listings under this identity, 3 shared hostnames
What this publisher told the store about itself, and the other listings that told it the same thing.
Shared hosts - 3 hostnames
Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
Profile lookups are logged to GrowBot
When GrowBot finishes loading extra data for an Instagram account, it posts a completion record: viewer IG handle, target username, numeric ID, and lookup details.
Dynamic analysis didn't observe this POST; the queue action never completed.
You process queued Instagram accounts with the option to load more profile data.
The queue handler calls the additional-info loader when that radio option is selected.
After each account's additional data loads, the extension posts a record to GrowBot's backend.
The record names both the viewer account and the target account.
| Field | Value | Why it matters | |
|---|---|---|---|
Viewer Instagram handle | alex.fit.studio (illustrative) | This identifies the Instagram account using the extension during the lookup. | |
Action type | additional_info | This describes the kind of activity completed through the extension. | |
Target Instagram username | fitness_influencer (illustrative) | This records which account you profiled through the extension. | |
Target numeric account ID | 17841400000000000 (illustrative) | This gives a stable identifier for the account you looked up, even if the username changes later. | |
Lookup details | profile_bundle, extended data on, version 2.8.2 (illustrative) | This adds context about the profile bundle request and extension version used for the lookup. |
The shipped queue path and action-log POST
function initProcessQueue() {
var todaysdate = new Date();
maxActionsDelayStartTime = todaysdate.getTime();
$('#btnProcessQueue').addClass('pulsing');
if (document.getElementById('radioFollow').checked === true) {
scheduleFollowingFromAcctsQueue();
} else if (document.getElementById('radioUnFollow').checked === true) {
// initUnfollowMyFollowers();
scheduleUnfollowingFromAcctsQueue();
} else if (document.getElementById('radioLikeOnly').checked === true) {
ajaxLikeAll();
} else if (document.getElementById('radioBlock').checked === true || document.getElementById('radioRemoveFromFollowers').checked === true) {
scheduleRemoveOrBlockFromAcctsQueue();
} else if (document.getElementById('radioGetMoreData').checked === true) {
var safeDelaySeconds = 1;
if (acctsQueue.length > 100) safeDelaySeconds = 2;
if (acctsQueue.length > 500) safeDelaySeconds = 3;
if (acctsQueue.length > 1000) safeDelaySeconds = 4;
if (acctsQueue.length > 2000) safeDelaySeconds = 5;
if (acctsQueue.length > 3000) safeDelaySeconds = 6;
if (acctsQueue.length > 4000) safeDelaySeconds = 10;
if (acctsQueue.length > 40 && (gblOptions.useTimeDelayAfterAdditionalInfo == false || document.getElementById('texttimeDelayAfterAdditionalInfo').value < safeDelaySeconds)) {
dialog({
no: "No",
yes: "Yes",
question: "WARNING: <br><br>Low or no delay set after loading data for each account. <br><br> Set " + safeDelaySeconds + " second delay?"
}, function () {
document.getElementById('cbuseTimeDelayAfterAdditionalInfo').checked = true;
document.getElementById('texttimeDelayAfterAdditionalInfo').value = safeDelaySeconds;
saveOptions();
populateAllQueueUsersInfo(acctsQueue);
}, function () {
populateAllQueueUsersInfo(acctsQueue);
})
} else {
populateAllQueueUsersInfo(acctsQueue);
}
} else if (document.getElementById('radioViewStory').checked === true) {
scheduleViewStoriesFromAcctsQueue();
}
}function postAdditionalInfoCompleted(acct) {
if (!sessionToken) return;
var viewer =
typeof user !== 'undefined' && user.viewer && user.viewer.username
? user.viewer.username
: '';
if (!viewer || !acct || !acct.username) return;
fetch('https://www.growbotforfollowers.com/actions/log_completed_action.php', {
method: 'POST',
headers: getAuthHeaders(),
body: JSON.stringify({
ig_username: viewer,
action_type: 'additional_info',
target_username: acct.username,
target_id: acct.id != null ? String(acct.id) : null,
details: {
subtype: 'profile_bundle',
getExtendedData: !!gblOptions.getExtendedData,
extension_version: growbotExtensionVersionHeaderValue()
}
})
}).catch(function (e) {
console.warn('postAdditionalInfoCompleted', e);
});
}- www.growbotforfollowers.com
Receives the additional-info completion record at /actions/log_completed_action.php.
Subscription lookup posts billing-reference fields
GrowBot's relinking form is serialized and posted to its subscription lookup endpoint.
The form holds an email, last four card digits, and expiration date.
Analysis did not capture this POST; the button was not clicked in testing.
You press Find Subscription in the relinking panel.
That button is bound to the relinkSubscription function in the content script.
The extension posts the relinking form fields to GrowBot's subscription lookup endpoint.
The source uses the form serializer, so every named field in the form is included.
| Field | Value | Why it matters | |
|---|---|---|---|
Email address | alex@example.com (illustrative) | This can identify the account holder used for the subscription lookup. | |
Payment card last four | 4242 (illustrative) | This is a billing-reference value that can help match a subscription record to you. | |
Card expiration month | 12 (illustrative) | This adds billing context to the subscription lookup. | |
Card expiration year | 2026 (illustrative) | This adds billing context to the subscription lookup. |
The shipped function that submits the relinking form
$('#btnFindSubscription').off('click.relinkSubscription').on('click.relinkSubscription', relinkSubscription);function relinkSubscription() {
$.post('https://www.growbotforfollowers.com/find_subscription2.php', $('#formRelinkSubscription').serialize()).done(function (data) {
if (data && data[0] && data[0].subscriptions && data[0].subscriptions.data && data[0].subscriptions.data.length > 0) {
var guidFromServer = data[0].id;
chrome.runtime.sendMessage({
"guidCookie": guidFromServer,
"forceGuidSync": true
}, function () {
$('#resultFindSubscription').text(gbGetMessage('SubscriptionUpdated'));
});
} else {
$('#resultFindSubscription').text(gbGetMessage('SubscriptionNotFound'));
}
});
}- www.growbotforfollowers.com
Receives the subscription relinking POST at /find_subscription2.php and returns a subscription lookup result used by the extension.