Is GrowBot Automator for Instagram™ safe?

Medium risk

GrowBot is medium risk. When GrowBot finishes loading extra data for an Instagram account, it posts a completion record: viewer IG handle, target username, numeric ID, and lookup details. Dynamic analysis didn't observe this POST; the queue action never completed.…

Growbotv2.9.6Chrome Web Store
45Risk
Who publishes it

Growbot - no other listings under this identity, 3 shared hostnames

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
Growbot
Declared legal entity
Growbot
Registered address
Box 241, Glenwood Landing, NY 11547, US

Shared hosts - 3 hostnames

Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.

growbotforfollowers.com
Also called by 1 other listing: GrowBot Automator for Instagram
mydatabase.com
Also called by 2 other listings: GrowBot Automator for Instagram, AMZ Seller Browser
kellegous.com
Also called by 6 other listings, including GrowBot Automator for Instagram, AMZ Seller Browser, Research Notes

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

SeverityMEDIUM
ClassUNWANTED
TypeUnexpected
CWECWE-359
SourceAI SANDBOX

Profile lookups are logged to GrowBot

When GrowBot finishes loading extra data for an Instagram account, it posts a completion record: viewer IG handle, target username, numeric ID, and lookup details.

Dynamic analysis didn't observe this POST; the queue action never completed.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You process queued Instagram accounts with the option to load more profile data.

The queue handler calls the additional-info loader when that radio option is selected.

The extension did this

After each account's additional data loads, the extension posts a record to GrowBot's backend.

The record names both the viewer account and the target account.

02EvidenceFIELD TABLE
Fields assembled for the action log
FieldValueWhy it matters
Viewer Instagram handle
alex.fit.studio (illustrative)This identifies the Instagram account using the extension during the lookup.
Action type
additional_infoThis describes the kind of activity completed through the extension.
Target Instagram username
fitness_influencer (illustrative)This records which account you profiled through the extension.
Target numeric account ID
17841400000000000 (illustrative)This gives a stable identifier for the account you looked up, even if the username changes later.
Lookup details
profile_bundle, extended data on, version 2.8.2 (illustrative)This adds context about the profile bundle request and extension version used for the lookup.
03EvidenceNETWORK CAPTURE
Captured request
POSThttps://www.growbotforfollowers.com/actions/log_completed_action.php
Dynamic analysis did not capture this request body; source verification confirms the POST target and JSON fields.
04EvidenceCODE COMPARE
The code that does this

The shipped queue path and action-log POST

What it actually does
Queue option calls the additional-info loaderdeobfuscated/contentscript.js
function initProcessQueue() {
    var todaysdate = new Date();
    maxActionsDelayStartTime = todaysdate.getTime();

    $('#btnProcessQueue').addClass('pulsing');

    if (document.getElementById('radioFollow').checked === true) {
        scheduleFollowingFromAcctsQueue();
    } else if (document.getElementById('radioUnFollow').checked === true) {
        // initUnfollowMyFollowers();
        scheduleUnfollowingFromAcctsQueue();
    } else if (document.getElementById('radioLikeOnly').checked === true) {
        ajaxLikeAll();
    } else if (document.getElementById('radioBlock').checked === true || document.getElementById('radioRemoveFromFollowers').checked === true) {
        scheduleRemoveOrBlockFromAcctsQueue();
    } else if (document.getElementById('radioGetMoreData').checked === true) {

        var safeDelaySeconds = 1;

        if (acctsQueue.length > 100) safeDelaySeconds = 2;
        if (acctsQueue.length > 500) safeDelaySeconds = 3;
        if (acctsQueue.length > 1000) safeDelaySeconds = 4;
        if (acctsQueue.length > 2000) safeDelaySeconds = 5;
        if (acctsQueue.length > 3000) safeDelaySeconds = 6;
        if (acctsQueue.length > 4000) safeDelaySeconds = 10;



        if (acctsQueue.length > 40 && (gblOptions.useTimeDelayAfterAdditionalInfo == false || document.getElementById('texttimeDelayAfterAdditionalInfo').value < safeDelaySeconds)) {

            dialog({
                no: "No",
                yes: "Yes",
                question: "WARNING: <br><br>Low or no delay set after loading data for each account. <br><br> Set " + safeDelaySeconds + " second delay?"
            }, function () {
                document.getElementById('cbuseTimeDelayAfterAdditionalInfo').checked = true;
                document.getElementById('texttimeDelayAfterAdditionalInfo').value = safeDelaySeconds;
                saveOptions();

                populateAllQueueUsersInfo(acctsQueue);

            }, function () {
                populateAllQueueUsersInfo(acctsQueue);
            })
        } else {
            populateAllQueueUsersInfo(acctsQueue);
        }



    } else if (document.getElementById('radioViewStory').checked === true) {
        scheduleViewStoriesFromAcctsQueue();
    }
}
Completion record POSTdeobfuscated/contentscript.js
function postAdditionalInfoCompleted(acct) {
    if (!sessionToken) return;
    var viewer =
        typeof user !== 'undefined' && user.viewer && user.viewer.username
            ? user.viewer.username
            : '';
    if (!viewer || !acct || !acct.username) return;
    fetch('https://www.growbotforfollowers.com/actions/log_completed_action.php', {
        method: 'POST',
        headers: getAuthHeaders(),
        body: JSON.stringify({
            ig_username: viewer,
            action_type: 'additional_info',
            target_username: acct.username,
            target_id: acct.id != null ? String(acct.id) : null,
            details: {
                subtype: 'profile_bundle',
                getExtendedData: !!gblOptions.getExtendedData,
                extension_version: growbotExtensionVersionHeaderValue()
            }
        })
    }).catch(function (e) {
        console.warn('postAdditionalInfoCompleted', e);
    });
}
05EvidenceTHIRD PARTY LIST
Destination for the profile action log
  • www.growbotforfollowers.com

    Receives the additional-info completion record at /actions/log_completed_action.php.

SeverityMEDIUM
ClassUNWANTED
TypeUnexpected
CWECWE-359
SourceAI SANDBOX

Subscription lookup posts billing-reference fields

GrowBot's relinking form is serialized and posted to its subscription lookup endpoint.

The form holds an email, last four card digits, and expiration date.

Analysis did not capture this POST; the button was not clicked in testing.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You press Find Subscription in the relinking panel.

That button is bound to the relinkSubscription function in the content script.

The extension did this

The extension posts the relinking form fields to GrowBot's subscription lookup endpoint.

The source uses the form serializer, so every named field in the form is included.

02EvidenceFIELD TABLE
Fields in the relinking form
FieldValueWhy it matters
Email address
alex@example.com (illustrative)This can identify the account holder used for the subscription lookup.
Payment card last four
4242 (illustrative)This is a billing-reference value that can help match a subscription record to you.
Card expiration month
12 (illustrative)This adds billing context to the subscription lookup.
Card expiration year
2026 (illustrative)This adds billing context to the subscription lookup.
03EvidenceNETWORK CAPTURE
Captured request
POSThttps://www.growbotforfollowers.com/find_subscription2.php
Dynamic analysis did not capture this request body; source verification confirms the POST target and form serialization.
04EvidenceCODE COMPARE
The code that does this

The shipped function that submits the relinking form

What it actually does
Button bindingdeobfuscated/contentscript.js
$('#btnFindSubscription').off('click.relinkSubscription').on('click.relinkSubscription', relinkSubscription);
Relinking POSTdeobfuscated/contentscript.js
function relinkSubscription() {
    $.post('https://www.growbotforfollowers.com/find_subscription2.php', $('#formRelinkSubscription').serialize()).done(function (data) {
        if (data && data[0] && data[0].subscriptions && data[0].subscriptions.data && data[0].subscriptions.data.length > 0) {
            var guidFromServer = data[0].id;
            chrome.runtime.sendMessage({
                "guidCookie": guidFromServer,
                "forceGuidSync": true
            }, function () {
                $('#resultFindSubscription').text(gbGetMessage('SubscriptionUpdated'));
            });
        } else {
            $('#resultFindSubscription').text(gbGetMessage('SubscriptionNotFound'));
        }

    });
}
05EvidenceTHIRD PARTY LIST
Destination for the relinking lookup
  • www.growbotforfollowers.com

    Receives the subscription relinking POST at /find_subscription2.php and returns a subscription lookup result used by the extension.

Updated 30 September 2026abhcgokmndbiegmmbjffdlpihgdmeejf