Is Huntr - Job Search Tracker & Autofill safe?

Medium risk

Track job applications and autofill online application forms from your Huntr profile.

This extension lets you save job opportunities from websites and record details such as posting URLs, titles, salaries, locations, companies, notes, tasks, dates, contacts, and events. It also supports one-click application autofill on many job and ATS sites using information from your Huntr profile, with saved opportunities available in a dashboard and kanban board.

huntr-chrome-extensionv2.0.43Chrome Web Store
45Risk
Who publishes it

Huntr LLC - no other listings under this identity

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
huntr-chrome-extension
Declared legal entity
Huntr LLC
Registered address
809 North 47th Street, Unit C, Seattle, WA 98103, US
Registered contact
Rennie Haylock

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

SeverityMEDIUM
ClassUNWANTED
TypeUnexpected
CWECWE-200
SourceAI SANDBOX

Save Job uploads page URL and job-page content

Using Huntr's Save Job action sends the page URL, scraped job description, title, company, location, and parsing metadata to https://huntr.co/api/job.

DA didn't observe the POST, as no session or save action was performed.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You click Save Job while viewing a job listing.

The extension did this

The extension sends the job page URL and scraped job content to Huntr's job API.

02EvidenceFIELD TABLE
Fields built into the saved-job request
FieldValueWhy it matters
Current job page URL
https://jobs.example.com/software-engineer-remote-12345This identifies the listing page you saved.
Scraped job description
<div class="description">Build browser automation tools for recruiting teams.</div>This contains job-page content collected from the page, such as the description HTML or text.
Job title
Senior Software EngineerThis records the job title shown on the page you saved.
Company
Example RoboticsThis records the company associated with the saved listing.
Parsing metadata
domParsingData: { source: "json-ld", confidence: 0.94 }This can include page-derived details used to structure the saved job entry.
03EvidenceNETWORK CAPTURE
Captured request
POSThttps://huntr.co/api/job?id=64f1c2a73b8e4d0012a9c456
Not observed during unauthenticated dynamic analysis; the shipped save-job path constructs this POST.
Headers
Content-Typeapplication/json
AuthorizationBearer <redacted>
04EvidenceCODE COMPARE
The code that does this

Save Job maps page-derived fields into a Huntr API POST

What it actually does
Readable equivalent of the saved-job API methodbackground.bundle.js
addJob(company, listId, jobTitle, htmlDescription, location, url, domParsingData) {
  if (!token || !userId) return Promise.reject();

  const body = JSON.stringify({
    company,
    listId,
    jobTitle,
    htmlDescription,
    location,
    url,
    domParsingData,
    isFromChromeExtension: true,
  });

  return apiRequest(`/job?id=${userId}`, "POST", body);
}
Readable equivalent of the Save Job handlerbackground.bundle.js
SAVE_JOB(message) {
  const { company, listId, jobTitle, htmlDescription, location, postUrl, _sender } = message;

  return function (respond) {
    mixpanel.track("103 Chrome Ext Job Added", { url: postUrl });
    respond({ type: "SAVING_JOB", tabId: _sender.tab.id });

    api.addJob(company, listId, jobTitle, htmlDescription, location, postUrl)
      .then(function (result) {
        respond({
          type: "RECEIVE_SAVED_JOB",
          job: result.job,
          company: result.company,
          list: result.list,
          tabId: _sender.tab.id,
        });
      })
      .catch(function (error) {
        return respond(apiError(error, "add_job", _sender.tab.id));
      });
  };
}
Readable equivalent of the content-script Save buttoncontent.bundle.js
function JobFound({ parsedJob, onJobSaved, currentBoard, organization }) {
  const location = { address: parsedJob.address || "" };
  const jobTitle = parsedJob.title || "";
  const postUrl = window.location.href;
  const htmlDescription = parsedJob.description || "";

  function save(company) {
    if (!company.name) return;

    if (location && location.address) {
      getTopPlaceSuggestion(location.address).then(function (place) {
        return onJobSaved(company, jobTitle || "No Job Title", htmlDescription, place || location, postUrl);
      });
    } else {
      onJobSaved(company, jobTitle || "No Job Title", htmlDescription, location, postUrl);
    }
  }

  return renderSaveButton(save, currentBoard, organization);
}
05EvidenceTHIRD PARTY LIST
Destination in this claim
  • huntr.co

    Huntr API host receiving saved-job records from the extension.

What it can do

Permissions this extension asks for, as declared in version 2.0.44. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to. The current listed version is 2.0.43, which we have not unpacked yet.

  • Read and change your data on every site you visit

    http://*/*

  • Read and change your data on every secure site you visit

    https://*/*

  • Read and change your data on ajax.googleapis.com

    https://ajax.googleapis.com/

  • Read and change your data on app.huntr.co

    https://app.huntr.co/

  • Read and change your data on localhost:3000

    http://localhost:3000/*

  • Read and change your data on huntr.co

    https://huntr.co/*

  • Read and change your data on huntrstaging.com

    https://huntrstaging.com/*

  • Read and change your data on fonts.googleapis.com

    https://fonts.googleapis.com/css?family=Lato:300,400,700,900

  • Schedule its own background tasks

    alarms

  • Store data in your browser

    storage

  • See the address and title of every tab you have open

    tabs

  • See every page you navigate to, as you navigate to it

    webNavigation

  • Run its own code inside the pages you visit

    scripting

  • Store an unlimited amount of data in your browser

    unlimitedStorage

Where it sends data

Destinations our analysis observed Huntr contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.

  • Huntr

    Huntr sends data to Huntr. Named as a recipient in this extension's own analysis.

Updated 30 September 2026mihdfbecejheednfigjpdacgeilhlmnf