Is Imagus safe?

Medium risk

Imagus downloads an update-able rule file from tiny.cc and runs rules written as JavaScript on any page you hover an image on.

Imagus periodically fetches a JSON rule list from tiny.cc/Imagus-sieve and stores it without any signature or checksum check. Some of these rules are written as raw JavaScript, which the extension's content script (active on every page) compiles with `new Function()` and runs whenever you hover over a matching image, giving that code access to the page's DOM. Dozens of the rules Imagus ships by default already use this JavaScript format, so the code path runs during normal browsing.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

Deathamnsv0.9.9.1Chrome Web Store
45Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

What it can do

Permissions this extension asks for, as declared in version 0.9.9.1. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Read and change your data on every site you visit

    *://*/*

  • Start, monitor and manage your downloads

    downloads

  • Read and change your full browsing history

    history

  • Store data in your browser

    storage

Where it sends data

Destinations our analysis observed Imagus contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.

  • tiny.cc

    Imagus sends data to tiny.cc. No other extension we have analysed sends data here.

Updated 21 September 2026immpkjjlgappgfkkfieppnmlhakdmaab