Is Portline Auto Import safe?
Portline Auto Import fetches the dealer's Copart password in cleartext and auto-submits it to log them into Copart.com.
On every page load, a MAIN-world content script asks Portline's backend (cpt-api.liontrans.com) for the account's Copart username and password, which come back as plaintext JSON and are stored in Copart's own localStorage; the script then POSTs those credentials to Copart's processLogin endpoint to sign the dealer in automatically. The background worker also polls for an attached debugger every second: if DevTools is opened on Copart's own service worker, it logs the user out, closes all tabs, and disables itself, and it force-closes any Copart tab where a debugger is attached.
Part of this rating comes from analysis signals we haven't published as detailed findings yet.
Who publishes itnikametr3 - no other listings under this identity, 10 shared hostnames
nikametr3 - no other listings under this identity, 10 shared hostnames
What this publisher told the store about itself, and the other listings that told it the same thing.
Shared hosts - 10 hostnames
Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Where it sends data
Destinations our analysis observed Portline Auto Import contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.
- cpt-api.liontrans.com
Portline Auto Import sends data to cpt-api.liontrans.com. No other extension we have analysed sends data here.
- www.copart.com
Portline Auto Import sends data to www.copart.com. No other extension we have analysed sends data here.