Is JabRef Browser Extension safe?

Low risk

JabRef Browser Extension fetches translator scripts from repo.zotero.org and executes them in active tabs without integrity checks.

When the extension initializes or encounters a translator cache miss, it downloads JavaScript code from repo.zotero.org and passes the raw response to an eval pipeline that executes the code in the current tab via browser.tabs.executeScript. No hash, HMAC, or signature validation is performed at any step, meaning a compromised or malicious response from repo.zotero.org would run arbitrary code in the context of whatever page the user has open.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

20Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

What it can do

Permissions this extension asks for, as declared in version 2.5. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Read and change your data on every site you visit

    <all_urls>

  • Act on the current tab, but only after you click the extension

    activeTab

  • See the address and title of every tab you have open

    tabs

  • Store data in your browser

    storage

  • Talk to a program installed on your computer, outside the browser's sandbox

    nativeMessaging

Where it sends data

Destinations our analysis observed JabRef Browser Extension contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.

  • repo.zotero.org

    JabRef Browser Extension sends data to repo.zotero.org. One other extension we have analysed sends data here.

Updated 21 September 2026bifehkofibaamoeaopjglfkddgkijdlh