Is Perplexity Exporter - Extract chat convos easily safe?
Perplexity Exporter accepts account updates from any extension with no sender check, letting one forge its cached subscription data.
The extension listens for external messages from any other installed extension and, without checking who sent them, writes whatever account_info object it receives straight into its local storage cache. That cached record normally holds subscription and customer details fetched from the extension's own backend, but the code treats any cached copy as fresh for the next 10 seconds, so another extension can keep resending updates to make the popup and options page permanently display attacker-chosen plan, customer ID, or email details. No user data leaves the browser through this handler; it only lets another installed extension feed the extension false account data.
Part of this rating comes from analysis signals we haven't published as detailed findings yet.
Who publishes itMark - 5 other listings from the same operator, 5 of them carrying a finding
Mark - 5 other listings from the same operator, 5 of them carrying a finding
What this publisher told the store about itself, and the other listings that told it the same thing.
Same store account
5 other listings published from this account, 216k+ users between them. 5 of them carry a finding.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
What it can do
Permissions this extension asks for, as declared in version 1.0.0. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Read and change your data on pplxexporter.com
https://*.pplxexporter.com/
Store data in your browser
storage