Is Mobile simulator - responsive testing tool safe?
Mobile simulator - responsive testing tool sends paid subscribers' email and account identifiers to PostHog analytics, bypassing the analytics opt-out setting.
Once per day, the extension verifies a paid subscriber's account and then POSTs usage analytics to PostHog including the user's email address, user ID, device ID, browser, OS, and user-agent string. A force flag in the analytics call overrides the user-facing analytics opt-out preference, meaning paid subscribers cannot prevent this transmission. The data is sent to us.i.posthog.com using a hardcoded API key.
Who publishes itMobile FIRST - 5 other listings from the same operator, none carrying a finding
Mobile FIRST - 5 other listings from the same operator, none carrying a finding
What this publisher told the store about itself, and the other listings that told it the same thing.
Same operator - 5 listings
Published under a different store account, but sharing the registered address, contact or declared legal entity this one gave the store.
Shared hosts - 1 hostname
Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
Paid subscriber email transmitted to PostHog, bypassing analytics opt-out
Dynamic analysis captured a POST from the background worker to us.i.posthog.com/capture with the subscriber's email, user ID, and device ID, fired right after subscription confirmed.
Bypasses the opt-out via force=true, at most once/day.
You log in with a paid subscription account and the extension verifies your subscription.
The background service worker calls Supabase to confirm your subscription is active and loads your profile, including your registered email address.
The extension posts your account email address to PostHog analytics, regardless of your analytics setting.
sendEvent is invoked with force=true, which bypasses the analytics_enabled preference gate. Your email, user ID, and a persistent device UUID are included in the request body.
| Content-Type | application/json |
{
"api_key": "phc_yObZ9Y7kcPWkhvNtSflXm0gdkDuRBvOFsps03KXgxRH",
"distinct_id": "a8f2e91b-3c47-4d2e-b9f1-2e5c8d4a6b13",
"event": "extension_usage",
"properties": {
"$process_person_profile": true,
"device_id": "550e8400-e29b-41d4-a716-446655440000",
"user_id": "a8f2e91b-3c47-4d2e-b9f1-2e5c8d4a6b13",
"email": "alice@example.com",
"platform": "extension",
"$browser": "Chrome",
"$browser_language": "en-US",
"$os": "Linux",
"$raw_user_agent": "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36",
"environment": "production",
"version": "4.18.0"
}
}| Field | Value | Why it matters | |
|---|---|---|---|
Account email | alice@example.com | Your registered email address for webmobilefirst.com, sent explicitly in the request body. It directly identifies your account to PostHog. | |
Account user ID | a8f2e91b-3c47-4d2e-b9f1-2e5c8d4a6b13 | Your unique account identifier from the extension's backend, which links all PostHog events back to your profile. | |
Device ID | 550e8400-e29b-41d4-a716-446655440000 | A persistent UUID stored in the extension's local storage and sent with every analytics event to track your device across sessions. | |
Browser and OS | Chrome / Linux | Your browser name and operating system, included as environment context with every event. | |
Raw user agent | Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36 | The full browser user agent string, which can be used to fingerprint your specific browser configuration. |
The analytics gate and call site, shipped vs deobfuscated
async function s(t, r, s) {
// s = force argument; when true, bypasses analytics_enabled check
(n["a"].getters["settings/analytics_enabled"] || s) &&
("extension_usage" !== t || await a("extension_usage")) &&
fetch("https://us.i.posthog.com/capture", {
method: "POST",
headers: { "Content-Type": "application/json" },
body: JSON.stringify({
api_key: "phc_yObZ9Y7kcPWkhvNtSflXm0gdkDuRBvOFsps03KXgxRH",
distinct_id: n["a"].getters["user/id"] || await o(),
event: t,
properties: {
$process_person_profile: !!n["a"].getters["user/id"],
...r, // spreads device_id, user_id, email from call site
platform: "extension",
$browser: getBrowserInfo().browser,
$browser_language: navigator.language,
$os: getBrowserInfo().os,
$raw_user_agent: navigator.userAgent,
environment: "production",
version: chrome.runtime.getManifest().version
}
})
}).catch(err => console.error("Failed to send PostHog event", err));
}// After Supabase confirms active subscription and loads user profile:
if (store.getters["user/isPRO"]) {
analytics.sendEvent(
"extension_usage",
{
device_id: await getDeviceId(),
user_id: user.id,
email: user.email // account email included explicitly
},
true // force=true: bypass analytics_enabled opt-out
);
}The extension_usage event fires at most once per calendar day. A date-keyed record in chrome.storage.local under the key 'analysis_events_sent' tracks the last transmission date per event type; if the stored date matches the current UTC date the event is skipped.
- us.i.posthog.com
PostHog analytics, US region. Receives account email, user ID, device UUID, browser, OS, and user agent via /capture under a hardcoded project key.
Where it sends data
Destinations our analysis observed Mobile simulator - responsive testing tool contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.
- us.i.posthog.com
Mobile simulator - responsive testing tool sends data to us.i.posthog.com. 24 other extensions we have analysed send data here.
- mobile-first-admin.herokuapp.com
Mobile simulator - responsive testing tool sends data to mobile-first-admin.herokuapp.com. No other extension we have analysed sends data here.