Is Mobile simulator - responsive testing tool safe?

Medium risk

Mobile simulator - responsive testing tool sends paid subscribers' email and account identifiers to PostHog analytics, bypassing the analytics opt-out setting.

Once per day, the extension verifies a paid subscriber's account and then POSTs usage analytics to PostHog including the user's email address, user ID, device ID, browser, OS, and user-agent string. A force flag in the analytics call overrides the user-facing analytics opt-out preference, meaning paid subscribers cannot prevent this transmission. The data is sent to us.i.posthog.com using a hardcoded API key.

François Dupratv4.21.2Chrome Web Store
45Risk
Who publishes it

Mobile FIRST - 5 other listings from the same operator, none carrying a finding

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
François Duprat
Declared legal entity
Mobile FIRST
Registered address
93 Bd Voltaire, Paris 75011, FR
Registered contact
Duprat

Same operator - 5 listings

Published under a different store account, but sharing the registered address, contact or declared legal entity this one gave the store.

Shared hosts - 1 hostname

Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.

webmobilefirst.com
Also called by 3 other listings, including Mobile simulator - responsive testing tool

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

SeverityMEDIUM
ClassUNWANTED
TypeUnexpected
CWECWE-359
SourceAI SANDBOX

Paid subscriber email transmitted to PostHog, bypassing analytics opt-out

Dynamic analysis captured a POST from the background worker to us.i.posthog.com/capture with the subscriber's email, user ID, and device ID, fired right after subscription confirmed.

Bypasses the opt-out via force=true, at most once/day.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You log in with a paid subscription account and the extension verifies your subscription.

The background service worker calls Supabase to confirm your subscription is active and loads your profile, including your registered email address.

The extension did this

The extension posts your account email address to PostHog analytics, regardless of your analytics setting.

sendEvent is invoked with force=true, which bypasses the analytics_enabled preference gate. Your email, user ID, and a persistent device UUID are included in the request body.

02EvidenceNETWORK CAPTURE
Captured request
POSThttps://us.i.posthog.com/capture
HTTP 200 {"status": "Ok"}, PostHog confirmed receipt.
Headers
Content-Typeapplication/json
Body
{
  "api_key": "phc_yObZ9Y7kcPWkhvNtSflXm0gdkDuRBvOFsps03KXgxRH",
  "distinct_id": "a8f2e91b-3c47-4d2e-b9f1-2e5c8d4a6b13",
  "event": "extension_usage",
  "properties": {
    "$process_person_profile": true,
    "device_id": "550e8400-e29b-41d4-a716-446655440000",
    "user_id": "a8f2e91b-3c47-4d2e-b9f1-2e5c8d4a6b13",
    "email": "alice@example.com",
    "platform": "extension",
    "$browser": "Chrome",
    "$browser_language": "en-US",
    "$os": "Linux",
    "$raw_user_agent": "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36",
    "environment": "production",
    "version": "4.18.0"
  }
}
03EvidenceFIELD TABLE
Fields transmitted to PostHog in the extension_usage event
FieldValueWhy it matters
Account email
alice@example.comYour registered email address for webmobilefirst.com, sent explicitly in the request body. It directly identifies your account to PostHog.
Account user ID
a8f2e91b-3c47-4d2e-b9f1-2e5c8d4a6b13Your unique account identifier from the extension's backend, which links all PostHog events back to your profile.
Device ID
550e8400-e29b-41d4-a716-446655440000A persistent UUID stored in the extension's local storage and sent with every analytics event to track your device across sessions.
Browser and OS
Chrome / LinuxYour browser name and operating system, included as environment context with every event.
Raw user agent
Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36The full browser user agent string, which can be used to fingerprint your specific browser configuration.
04EvidenceCODE COMPARE
The code that does this

The analytics gate and call site, shipped vs deobfuscated

What it actually does
Analytics function with force bypass and PostHog POST (deobfuscated)
async function s(t, r, s) {
  // s = force argument; when true, bypasses analytics_enabled check
  (n["a"].getters["settings/analytics_enabled"] || s) &&
  ("extension_usage" !== t || await a("extension_usage")) &&
  fetch("https://us.i.posthog.com/capture", {
    method: "POST",
    headers: { "Content-Type": "application/json" },
    body: JSON.stringify({
      api_key: "phc_yObZ9Y7kcPWkhvNtSflXm0gdkDuRBvOFsps03KXgxRH",
      distinct_id: n["a"].getters["user/id"] || await o(),
      event: t,
      properties: {
        $process_person_profile: !!n["a"].getters["user/id"],
        ...r,            // spreads device_id, user_id, email from call site
        platform: "extension",
        $browser: getBrowserInfo().browser,
        $browser_language: navigator.language,
        $os: getBrowserInfo().os,
        $raw_user_agent: navigator.userAgent,
        environment: "production",
        version: chrome.runtime.getManifest().version
      }
    })
  }).catch(err => console.error("Failed to send PostHog event", err));
}
Call site: fires after PRO subscription confirmed (deobfuscated)
// After Supabase confirms active subscription and loads user profile:
if (store.getters["user/isPRO"]) {
  analytics.sendEvent(
    "extension_usage",
    {
      device_id: await getDeviceId(),
      user_id:   user.id,
      email:     user.email   // account email included explicitly
    },
    true   // force=true: bypass analytics_enabled opt-out
  );
}
05EvidenceTEMPORAL PATTERN
When this fires
Every 1 day

The extension_usage event fires at most once per calendar day. A date-keyed record in chrome.storage.local under the key 'analysis_events_sent' tracks the last transmission date per event type; if the stored date matches the current UTC date the event is skipped.

06EvidenceTHIRD PARTY LIST
Where the account email is sent
  • us.i.posthog.com

    PostHog analytics, US region. Receives account email, user ID, device UUID, browser, OS, and user agent via /capture under a hardcoded project key.

Where it sends data

Destinations our analysis observed Mobile simulator - responsive testing tool contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.

  • us.i.posthog.com

    Mobile simulator - responsive testing tool sends data to us.i.posthog.com. 24 other extensions we have analysed send data here.

  • mobile-first-admin.herokuapp.com

    Mobile simulator - responsive testing tool sends data to mobile-first-admin.herokuapp.com. No other extension we have analysed sends data here.

Updated 30 September 2026ckejmhbmlajgoklhgbapkiccekfoccmk