Is Octotree - GitHub code tree safe?

Clean risk

Octotree renders its account password field as plain text in its GitHub sidebar login form.

When you open Octotree's login panel on GitHub, the password field is built as a text input, so typed characters are visible instead of masked. Submitting that form sends the entered email and password to Octotree's login API at www.octotree.io/api/v1.0/login.

Ovityv8.2.4Chrome Web Store
0Risk
Who publishes it

Ovity - no other listings under this identity

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
Ovity

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

What it can do

Permissions this extension asks for, as declared in version 8.2.4. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Read and change your data on api.github.com

    https://api.github.com/*

  • Read and change your data on www.octotree.io

    https://www.octotree.io/*

  • Store data in your browser

    storage

  • Add items to the right-click menu

    contextMenus

  • Act on the current tab, but only after you click the extension

    activeTab

  • Run its own code inside the pages you visit

    scripting

Where it sends data

Destinations our analysis observed Octotree contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.

  • www.octotree.io

    Octotree sends data to www.octotree.io. No other extension we have analysed sends data here.

Updated 30 September 2026bkhaagjahfmjljalopjnoealnfndnagc