Is MozBar safe?

Clean risk

MozBar transmits visited URLs and search result links to api.moz.com when the user is signed in.

When the user is authenticated, MozBar sends the URL of each page visited (without query parameters) to api.moz.com via JSON-RPC on every tab activation and page load. On Google, Bing, and Yahoo search pages, it also collects and transmits the URLs of all organic search results to the same endpoint when the SERP overlay is active. Responses are cached locally for 24 hours.

0Risk
Who publishes it

Moz - no other listings under this identity

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
Moz
Declared legal entity
Moz
Registered address
1100 2nd Ave, Suite 500, Seattle, WA 98101, USA

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

What it can do

Permissions this extension asks for, as declared in version 4.1.1. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to. The current listed version is 5.0.17, which we have not unpacked yet.

  • Read and change your data on every site you visit

    <all_urls>

  • See the address and title of every tab you have open

    tabs

  • Act on the current tab, but only after you click the extension

    activeTab

  • Store data in your browser

    storage

  • Read and change cookies, including the ones that keep you signed in

    cookies

  • Watch every request your browser makes

    webRequest

Where it sends data

Destinations our analysis observed MozBar contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.

  • api.moz.com

    MozBar sends data to api.moz.com. No other extension we have analysed sends data here.

Updated 30 September 2026eakacpaijcpapndcfffdgphdiccmpknp