Is Scribbr Citation Generator safe?
Scribbr is medium risk. Each popup open, Scribbr Citation Generator sends the tab URL and a persistent device ID to Amplitude; Sentry gets crash/session data separately. Neither is disclosed. The persistent ID lets Amplitude profile you across sessions.
Who publishes itQuillBot (Course Hero), LLC - 1 other listing from the same operator, 1 of them carrying a finding
QuillBot (Course Hero), LLC - 1 other listing from the same operator, 1 of them carrying a finding
What this publisher told the store about itself, and the other listings that told it the same thing.
Same operator - 1 listing
Published under a different store account, but sharing the registered address, contact or declared legal entity this one gave the store.
Shared hosts - 1 hostname
Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
Tab URL and device ID sent to Amplitude and Sentry on every popup open
Each popup open, Scribbr Citation Generator sends the tab URL and a persistent device ID to Amplitude; Sentry gets crash/session data separately.
Neither is disclosed.
The persistent ID lets Amplitude profile you across sessions.
You open the Scribbr Citation Generator popup on any webpage.
No special action is required, opening the popup on any tab is sufficient.
The extension immediately POSTs the current page URL and your persistent device ID to Amplitude's analytics API.
A secondary Sentry session beacon is also dispatched, linking the session to the same device context.
| Field | Value | Why it matters | |
|---|---|---|---|
Current page URL | https://www.nature.com/articles/s41586-024-07487-w | The full URL of the tab you had open when you clicked the extension icon. | |
Device ID | a6gX2zAGCJCwz-sr3zQmPY | A stable random identifier generated once and stored permanently. Ties every Amplitude event across sessions back to your device. | |
Citation style | apa | The citation format selected (e.g. APA, MLA). Used alongside the URL to profile which research pages you visit. | |
Extension version | 43.22 | Version string of the installed extension, sent on install, update, and each 'Opened' event. |
| Content-Type | application/json |
{
"api_key": "6ae9ad7168028f5affbce98a196acc26",
"events": [
{
"event_type": "Citation Generator Browser Extension Opened",
"device_id": "a6gX2zAGCJCwz-sr3zQmPY",
"user_id": null,
"event_properties": {
"extension_language": "en-US",
"citation_language": "en-US",
"citation_style": "apa",
"url": "https://www.nature.com/articles/s41586-024-07487-w"
}
}
]
}Written on first run and never cleared, so it's a permanent cross-session fingerprint included in every Amplitude event payload.
chrome.storage.local key 'amplitudeDeviceId'{
"amplitudeDeviceId": "a6gX2zAGCJCwz-sr3zQmPY"
}Amplitude device ID persistence and event dispatch (background.js)
// Amplitude client init (locale: 'com', env: 'production')
const amplitudeClient = new AmplitudeClient('browser-extension', 'production', 'com');
// Persist device ID across sessions
chrome.storage.local.get('amplitudeDeviceId', ({ amplitudeDeviceId }) => {
if (amplitudeDeviceId) {
amplitudeClient.setDeviceId(amplitudeDeviceId); // reuse existing
} else {
const newId = amplitudeClient.getDeviceId(); // auto-generated UUID
if (newId) chrome.storage.local.set({ amplitudeDeviceId: newId }); // persist forever
}
});
// On popup open: send URL + device ID to Amplitude
rt.logEvent({
name: 'Citation Generator Browser Extension Opened',
data: {
extension_language: 'en-US',
citation_language: 'en-US',
citation_style: t.citationStyle[0],
url: r.url // current tab URL
}
});- api.amplitude.com
Amplitude Analytics (Amplitude Inc., San Francisco). Receives 'Extension Opened', 'Installed', 'Updated', 'Source Cited', and other events with tab URL and persistent device ID.
- o84835.ingest.sentry.io
Sentry error/session tracking (Functional Software Inc.). Receives session envelopes and crash reports via navigator.sendBeacon. DSN: o84835.ingest.sentry.io/6153303.
What it can do
Permissions this extension asks for, as declared in version 43.22. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Read and change your data on every secure site you visit
https://*/*
Read and change your data on every site you visit
http://*/*
Run its own code inside the pages you visit
scripting
See the address and title of every tab you have open
tabs
Store data in your browser
storage
Sign you in with your Google account
identity