Is Hunter - Email Finder Extension safe?
Hunter sends the domain of every website you visit to extension-api.hunter.io on each tab change and navigation.
On every tab update and tab switch, the extension extracts the current tab's hostname and silently queries extension-api.hunter.io to check whether Hunter has data for that domain. This means Hunter receives a record of every domain you browse, tied to your session, regardless of whether you interact with the extension. A separate tracker also sends an event to hunter.io when you open the popup.
Who publishes itHunter Web Services, Inc - no other listings under this identity, 2 shared hostnames
Hunter Web Services, Inc - no other listings under this identity, 2 shared hostnames
What this publisher told the store about itself, and the other listings that told it the same thing.
Shared hosts - 2 hostnames
Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
Sends Every Visited Site's Domain to Hunter.io Automatically
Hunter's worker watches every page you load and tab you switch to, sending that domain to extension-api.hunter.io with no click needed. example.com, wikipedia.org and amazon.com each hit extension-api.hunter.io/data-for-domain on load.
You load a page or switch to a different browser tab.
No interaction with the Hunter extension icon or popup is needed.
The background service worker extracts the active tab's domain and sends it to extension-api.hunter.io to decide whether to light up the toolbar icon.
This runs on every chrome.tabs.onUpdated and chrome.tabs.onActivated event, so it fires for every site you browse, not just ones you search on Hunter for.
LaunchColorChange(), fires the lookup on every tab event
// Fires on every completed navigation
chrome.tabs.onUpdated.addListener((tabId, changeInfo, tab) => {
if (tab && tab.url !== undefined && changeInfo.status === "complete") {
LaunchColorChange(); // sends the new domain to hunter.io
}
});
// Fires on every tab switch
chrome.tabs.onActivated.addListener(() => {
LaunchColorChange(); // sends the newly-active tab's domain to hunter.io
});function dataFoundForDomain(domain, callback) {
const url = `https://extension-api.hunter.io/data-for-domain?domain=${domain}`;
fetch(url)
.then(response => response.json())
.then(result => callback(result === 1))
.catch(() => callback(false));
}| Field | Value | Why it matters | |
|---|---|---|---|
Domain of the page you're viewing | en.wikipedia.org | The hostname of your active tab, sent every load or tab switch, even for sites unrelated to email-finding. |
- extension-api.hunter.io
Hunter.io's API. Receives the domain of every page you visit via the toolbar lookup, regardless of whether you open the extension.
What it can do
Permissions this extension asks for, as declared in version 3.1.4. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to. The current listed version is 3.2.0, which we have not unpacked yet.
Read and change your data on hunter.io
https://*.hunter.io/
See the address and title of every tab you have open
tabs
Store data in your browser
storage
Where it sends data
Destinations our analysis observed Hunter contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.
- extension-api.hunter.io
Hunter sends data to extension-api.hunter.io. 2 other extensions we have analysed send data here.
- hunter.io
Hunter sends data to hunter.io. No other extension we have analysed sends data here.