Is Kipper safe?
Kipper's page-injected message listener accepts wallet and tip-reply commands from any website without checking the sender's origin.
Kipper injects a bridge script into web pages to relay tipping and wallet actions between the page and the extension's background service. While some message types (sending a tip, sending a transaction) check that the request came from x.com or kipper.money, others do not: any page can trigger a request that reads the user's saved wallet address, default tip settings and anonymous-tipping preference, open the wallet popup, generate a deposit address, or submit a reply that is posted to kipper.money/api/reply using the user's logged-in session cookie.
Part of this rating comes from analysis signals we haven't published as detailed findings yet.
Who publishes itDominant Energies - 1 other listing from the same operator, none carrying a finding
Dominant Energies - 1 other listing from the same operator, none carrying a finding
What this publisher told the store about itself, and the other listings that told it the same thing.
Same store account
1 other listing published from this account, 50k+ users between them, none of them carrying a finding.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Where it sends data
Destinations our analysis observed Kipper contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.
- kipper.money
Kipper sends data to kipper.money. No other extension we have analysed sends data here.