Is Não Seguidores safe?
Não Seguidores is medium risk. Code analysis shows on an authenticated Instagram page, Nao Seguidores' content script reads session values from the page into API request headers. Unauthenticated, it showed "Login no Instagram nao detectado" with no API request.
Who publishes itinvertexto.com - 6 other listings from the same operator, 1 of them carrying a finding
invertexto.com - 6 other listings from the same operator, 1 of them carrying a finding
What this publisher told the store about itself, and the other listings that told it the same thing.
Same store account
6 other listings published from this account, 199k+ users between them. 1 of them carries a finding.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
Instagram session values read for API requests
Code analysis shows on an authenticated Instagram page, Nao Seguidores' content script reads session values from the page into API request headers.
Unauthenticated, it showed "Login no Instagram nao detectado" with no API request.
You run the extension while already signed in to Instagram.
The background script opens Instagram and injects the content script after the page finishes loading.
The extension reads Instagram page and session values and prepares them as API request headers.
Without an authenticated Instagram page, the extension reports that no Instagram login was detected.
| Field | Value | Why it matters | |
|---|---|---|---|
Your Instagram account ID | 23816413978342712 (illustrative) | This identifies which Instagram account the extension is acting on. | |
Your CSRF token | 9kR3Yb0p7cH2Lq8Nf6QaV4Bm1Sd0 (illustrative) | This helps authorize state-changing requests from your logged-in Instagram session. | |
Instagram app identifier | 936619743392459 (illustrative) | This tells Instagram which web app client the request is using. | |
Instagram rollout marker | 1019693628 (illustrative) | This adds version context for Instagram's web API requests. | |
Instagram web claim | hmac.AR2xYdHjWpVbQmS7nK4rTz (illustrative) | This session value can tie API requests back to your active Instagram browser session. |
| X-Csrftoken | 9kR3Yb0p7cH2Lq8Nf6QaV4Bm1Sd0 (illustrative) |
| X-Ig-App-Id | 936619743392459 (illustrative) |
| X-Asbd-Id | 129477 |
| X-Csrftoken | 9kR3Yb0p7cH2Lq8Nf6QaV4Bm1Sd0 (illustrative) |
| X-Ig-App-Id | 936619743392459 (illustrative) |
| Content-Type | application/x-www-form-urlencoded |
| X-Instagram-Ajax | 1019693628 (illustrative) |
| X-Requested-With | XMLHttpRequest |
The content script parses Instagram session values and copies them into headers
const m = document.body.innerHTML,
n = m.match(/\?"viewerId\?":\?"(\w+)\?"/i),
o = m.match(/\?"appScopedIdentity\?":\?"(\w+)\?"/i),
p = m.match(/(?<="csrf_token":").+?(?=")/i),
q = m.match(/(?<="X-IG-App-ID":").+?(?=")/i),
r = m.match(/(?<="rollout_hash":").+?(?=")/i);
let s = n ? n[1] : null;
s || (s = o ? o[1] : null);
const t = {},
u = {
"Content-Type": "application/x-www-form-urlencoded",
"X-Requested-With": "XMLHttpRequest",
"X-Asbd-Id": 129477,
};
sessionStorage.getItem("www-claim-v2") &&
(u["X-Ig-Www-Claim"] = sessionStorage.getItem("www-claim-v2"));
p && ((t["X-Csrftoken"] = p[0]), (u["X-Csrftoken"] = p[0]));
q && ((t["X-Ig-App-Id"] = q[0]), (u["X-Ig-App-Id"] = q[0]));
r && (u["X-Instagram-Ajax"] = r[0]);- www.instagram.com
Receives GraphQL follower-list requests with X-Csrftoken and X-Ig-App-Id headers.
- i.instagram.com
Receives friendship unfollow POST requests with CSRF, app, web-claim, and rollout headers.
What it can do
Permissions this extension asks for, as declared in version 1.3.15. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to. The current listed version is 1.4.5, which we have not unpacked yet.
Read and change your data on instagram.com
https://*.instagram.com/*
Run its own code inside the pages you visit
scripting