Is Prospecta safe?

Low risk

Prospecta fingerprints the browser and combines it with the Chrome-signed-in email and IP location on every side-panel open.

On install and startup, Prospecta reads the Chrome-signed-in email and looks up the user's city and region from their IP address, storing both locally. A fingerprinting script injected into web.whatsapp.com hashes canvas, WebGL, audio, and font rendering into a persistent device ID. Every time the side panel is opened, the extension sends this email, location, and device ID together to its own backend at api.eminer.app, with no mention of this collection in its store listing or privacy policy.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

eMinerv5.0.4Chrome Web Store
20Risk
Who publishes it

eMiner - 2 other listings from the same operator, 1 of them carrying a finding

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
eMiner
Declared legal entity
eMiner

Same store account

2 other listings published from this account, 6k+ users between them. 1 of them carries a finding.

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Where it sends data

Destinations our analysis observed prospecta-%F0%9F%87%A7%F0%9F%87%B7 contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.

  • api.eminer.app

    prospecta-%F0%9F%87%A7%F0%9F%87%B7 sends data to api.eminer.app. No other extension we have analysed sends data here.

Updated 30 September 2026pkilehgkihmedmpnkdpdfhpchlgkkfjp