Is Perplexity Exporter - Extract chat convos easily safe?

Low risk

Perplexity Exporter accepts account updates from any extension with no sender check, letting one forge its cached subscription data.

The extension listens for external messages from any other installed extension and, without checking who sent them, writes whatever account_info object it receives straight into its local storage cache. That cached record normally holds subscription and customer details fetched from the extension's own backend, but the code treats any cached copy as fresh for the next 10 seconds, so another extension can keep resending updates to make the popup and options page permanently display attacker-chosen plan, customer ID, or email details. No user data leaves the browser through this handler; it only lets another installed extension feed the extension false account data.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

20Risk
Who publishes it

Mark - 5 other listings from the same operator, 5 of them carrying a finding

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
Mark

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

What it can do

Permissions this extension asks for, as declared in version 1.0.0. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Read and change your data on pplxexporter.com

    https://*.pplxexporter.com/

  • Store data in your browser

    storage

Updated 30 September 2026ldhnhcmaklgfgakhjjclehidfcehfcjm