Is Scribbr Citation Generator safe?

Medium risk

Scribbr is medium risk. Each popup open, Scribbr Citation Generator sends the tab URL and a persistent device ID to Amplitude; Sentry gets crash/session data separately. Neither is disclosed. The persistent ID lets Amplitude profile you across sessions.

Scribbrv43.22Chrome Web Store
45Risk
Who publishes it

QuillBot (Course Hero), LLC - 1 other listing from the same operator, 1 of them carrying a finding

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
Scribbr
Declared legal entity
QuillBot (Course Hero), LLC
Registered address
303 East Wacker Drive, Suite 2101, Chicago, IL 60601-5223, US
Registered contact
Learneo Inc.

Same operator - 1 listing

Published under a different store account, but sharing the registered address, contact or declared legal entity this one gave the store.

Shared hosts - 1 hostname

Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.

scribbr.com
Also called by 4 other listings, including WikiTree Sourcer

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

SeverityMEDIUM
ClassUNWANTED
TypeUnexpected
CWECWE-200
SourceAI SANDBOX

Tab URL and device ID sent to Amplitude and Sentry on every popup open

Each popup open, Scribbr Citation Generator sends the tab URL and a persistent device ID to Amplitude; Sentry gets crash/session data separately.

Neither is disclosed.

The persistent ID lets Amplitude profile you across sessions.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You open the Scribbr Citation Generator popup on any webpage.

No special action is required, opening the popup on any tab is sufficient.

The extension did this

The extension immediately POSTs the current page URL and your persistent device ID to Amplitude's analytics API.

A secondary Sentry session beacon is also dispatched, linking the session to the same device context.

02EvidenceFIELD TABLE
Fields transmitted in the Amplitude 'Extension Opened' event
FieldValueWhy it matters
Current page URL
https://www.nature.com/articles/s41586-024-07487-wThe full URL of the tab you had open when you clicked the extension icon.
Device ID
a6gX2zAGCJCwz-sr3zQmPYA stable random identifier generated once and stored permanently. Ties every Amplitude event across sessions back to your device.
Citation style
apaThe citation format selected (e.g. APA, MLA). Used alongside the URL to profile which research pages you visit.
Extension version
43.22Version string of the installed extension, sent on install, update, and each 'Opened' event.
03EvidenceNETWORK CAPTURE
Captured request
POSThttps://api.amplitude.com/2/httpapi
HTTP 200, event accepted by Amplitude ingestion endpoint.
Headers
Content-Typeapplication/json
Body
{
  "api_key": "6ae9ad7168028f5affbce98a196acc26",
  "events": [
    {
      "event_type": "Citation Generator Browser Extension Opened",
      "device_id": "a6gX2zAGCJCwz-sr3zQmPY",
      "user_id": null,
      "event_properties": {
        "extension_language": "en-US",
        "citation_language": "en-US",
        "citation_style": "apa",
        "url": "https://www.nature.com/articles/s41586-024-07487-w"
      }
    }
  ]
}
04EvidenceSTORAGE DUMP
What's stored on your device

Written on first run and never cleared, so it's a permanent cross-session fingerprint included in every Amplitude event payload.

Locationchrome.storage.local key 'amplitudeDeviceId'
Contents (JSON)
{
  "amplitudeDeviceId": "a6gX2zAGCJCwz-sr3zQmPY"
}
05EvidenceCODE COMPARE
The code that does this

Amplitude device ID persistence and event dispatch (background.js)

What it actually does
// Amplitude client init (locale: 'com', env: 'production')
const amplitudeClient = new AmplitudeClient('browser-extension', 'production', 'com');

// Persist device ID across sessions
chrome.storage.local.get('amplitudeDeviceId', ({ amplitudeDeviceId }) => {
  if (amplitudeDeviceId) {
    amplitudeClient.setDeviceId(amplitudeDeviceId); // reuse existing
  } else {
    const newId = amplitudeClient.getDeviceId(); // auto-generated UUID
    if (newId) chrome.storage.local.set({ amplitudeDeviceId: newId }); // persist forever
  }
});

// On popup open: send URL + device ID to Amplitude
rt.logEvent({
  name: 'Citation Generator Browser Extension Opened',
  data: {
    extension_language: 'en-US',
    citation_language: 'en-US',
    citation_style: t.citationStyle[0],
    url: r.url  // current tab URL
  }
});
06EvidenceTHIRD PARTY LIST
External endpoints receiving data from this extension
  • api.amplitude.com

    Amplitude Analytics (Amplitude Inc., San Francisco). Receives 'Extension Opened', 'Installed', 'Updated', 'Source Cited', and other events with tab URL and persistent device ID.

  • o84835.ingest.sentry.io

    Sentry error/session tracking (Functional Software Inc.). Receives session envelopes and crash reports via navigator.sendBeacon. DSN: o84835.ingest.sentry.io/6153303.

What it can do

Permissions this extension asks for, as declared in version 43.22. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Read and change your data on every secure site you visit

    https://*/*

  • Read and change your data on every site you visit

    http://*/*

  • Run its own code inside the pages you visit

    scripting

  • See the address and title of every tab you have open

    tabs

  • Store data in your browser

    storage

  • Sign you in with your Google account

    identity

Updated 30 September 2026epbobagokhieoonfplomdklollconnkl