Is Sidebarr - Bookmarks, Apps and more safe?
Sidebarr is medium risk. After Sidebarr is installed, the background script posts extension metadata and the stored UUID to sidebarr.org/api/config/. Dynamic analysis observed the request; the code merges every server JSON key into the extension config.…
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
Remote Configuration Is Applied After Install
After Sidebarr is installed, the background script posts extension metadata and the stored UUID to sidebarr.org/api/config/.
Dynamic analysis observed the request; the code merges every server JSON key into the extension config.
You install or start the extension.
The background script requests remote configuration and applies returned settings to local behavior.
| Content-Type | application/x-www-form-urlencoded |
| Field | Value | Why it matters | |
|---|---|---|---|
Extension ID | afdfpkhbdpioonfeknablodaejkklbdn | Tells sidebarr.org which Chrome extension is asking for configuration. | |
Extension version | 2.1.4 | Lets the server return settings for the installed release. | |
Stored browser ID | 2fb6e4ea-dcf5-2e5f-a456-f7ee6d15254b | Lets the server associate configuration checks with the same browser profile over time. | |
Request time | 2026-07-13T12:08:30.515Z | Shows when this browser profile asked for new configuration. |
The code that posts configuration data and applies the response
key: "updateConfig",
value: function() {
var e = this;
fetch(this.configUrl, {
method: "POST",
headers: {
"Content-Type": "application/x-www-form-urlencoded"
},
body: "filters=" + encodeURIComponent(btoa(JSON.stringify({
id: chrome.runtime.id,
version: this.version,
timestamp: Date.now(),
uid: this.config.uid
})))
}).then((function(e) {
return e.json()
})).then((function(t) {
if (t) {
for (var r in t) e.config[r] = t[r];
e.saveConfig(e.config)
}
})).finally((function() {
if (e.config.configUpTime && e.config.configUpTime > 0) {
var t = function(e) {
return e / 6e4
};
chrome.alarms.clear("updateTimer"), chrome.alarms.create("updateTimer", {
delayInMinutes: t(e.config.configUpTime),
periodInMinutes: t(e.config.configUpTime)
})
}
}))
}- sidebarr.org
Returns JSON configuration values that the extension stores and uses for future scheduling.
AI Chat Prompts Are Posted With a Persistent UUID
Code analysis shows a Sidebarr AI chat prompt goes from the background script to chat.sidebarr.net/api/generate with model, prompt, a streaming flag, and the stored UUID in an X-Client-UUID header.
Confirmed from code, not captured traffic.
You submit a prompt in the extension's AI chat feature.
The extension posts your prompt to Sidebarr's chat server with a persistent UUID header.
| Field | Value | Why it matters | |
|---|---|---|---|
Your chat prompt | Summarize this page for me | The text you type into the AI chat box is sent to the chat service. | |
Persistent browser ID | 2fb6e4ea-dcf5-2e5f-a456-f7ee6d15254b | Lets the chat service associate prompts from the same browser profile. | |
Model name | gpt-oss:20b | Tells the service which AI model the extension selected for the response. | |
Streaming flag | true | Tells the service to send the answer back in streamed chunks. |
The content script forwards the prompt and UUID to the background script
var H = function() {
var e = Yn(Gn().mark((function e(n, r) {
var t, o, i, a, s, l, c, f;
return Gn().wrap((function(e) {
for (;;) switch (e.prev = e.next) {
case 0:
return n.preventDefault(), y(!0), t = {
type: "user",
text: r
}, T((function(e) {
return [].concat(Xn(e), [t])
})), E(""), o = [].concat(Xn(A), [t]), i = sr(o), e.next = 9, or("uuid");
case 9:
a = e.sent, s = a.uuid, l = ar(), T((function(e) {
return [].concat(Xn(e), [{
type: "bot",
text: ""
}])
})), c = chrome.runtime.connect({
name: "sidebarr"
}), f = !1, c.onMessage.addListener((function(e) {
if (e.requestId === l)
if ("delta" === e.type) T((function(n) {
var r = Xn(n),
t = r[r.length - 1];
return r[r.length - 1] = {
type: "bot",
text: ((null == t ? void 0 : t.text) || "") + e.text
}, r
}));
else if ("error" === e.type) T((function(n) {
var r = Xn(n);
return r[r.length - 1] = {
type: "bot",
text: e.message
}, r
}));
else if ("done" === e.type) {
f = !0, y(!1);
try {
c.disconnect()
} catch (e) {}
}
})), c.postMessage({
type: "generate",
requestId: l,
uuid: s || "",
model: "gpt-oss:20b",
prompt: i
}), c.onDisconnect.addListener((function() {
f || y(!1)
}));
case 18:
case "end":
return e.stop()
}
}), e)
})));
return function(n, r) {
return e.apply(this, arguments)
}
}()The background script posts the prompt to chat.sidebarr.net
fetch("https://chat.sidebarr.net/api/generate", {
method: "POST",
headers: {
"Content-Type": "application/json",
"X-Client-UUID": r.uuid || ""
},
body: JSON.stringify({
model: r.model,
prompt: r.prompt,
stream: !0
}),
signal: o.signal
})- chat.sidebarr.net
Receives AI chat prompts, selected model names, stream flags, and the X-Client-UUID header.
Install Telemetry Sends a Persistent UUID
When Sidebarr starts after installation, it creates a persistent UUID, saves it, and sends install telemetry to sidebarr.org.
Dynamic analysis decoded the query value to an install event with uid 2fb6e4ea-dcf5-2e5f-a456-f7ee6d15254b.
You install the extension.
The extension creates a persistent UUID and sends it with an install telemetry event.
| Field | Value | Why it matters | |
|---|---|---|---|
Persistent browser ID | 2fb6e4ea-dcf5-2e5f-a456-f7ee6d15254b | Lets sidebarr.org recognize the same browser profile across extension sessions. | |
Extension ID | afdfpkhbdpioonfeknablodaejkklbdn | Identifies which Chrome extension installation is reporting the event. | |
Extension version | 2.1.4 | Tells the server which release of the extension is installed. | |
Lifecycle action | install | Tells the server that this browser profile just installed or updated the extension. | |
Event time | 2026-07-13T12:08:30.515Z | Records when the lifecycle event happened in the browser. |
The code that creates the UUID and sends the lifecycle event
key: "processQueue",
value: function() {
for (; this.queue.length > 0;) {
var e = this.queue.shift();
if (!e.type || "action" != e.type) return !0;
var t = "p=" + encodeURIComponent(btoa(JSON.stringify({
id: chrome.runtime.id,
v: this.version,
action: e.action,
uid: this.uid,
t: Date.now()
})));
fetch(this.actionUrl + "?" + t).then((function(e) {
return e.json()
})).then((function(e) {
e.url && chrome.tabs.create({
url: e.url
})
}))
}
}key: "generateUID",
value: function() {
return "xxxxxxxx-xxxx-2xxx-yxxx-xxxxxxxxxxxx".replace(/[xy]/g, (function(e) {
var t = 16 * Math.random() | 0;
return ("x" == e ? t : 3 & t | 8).toString(16)
}))
}- sidebarr.org
Receives extension lifecycle telemetry with the persistent UUID and extension metadata.
What it can do
Permissions this extension asks for, as declared in version 2.1.4. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Read and change your data on every site you visit
<all_urls>
Store data in your browser
storage
Read and change your bookmarks
bookmarks
Run its own code inside the pages you visit
scripting
Store an unlimited amount of data in your browser
unlimitedStorage
Block and redirect the requests your browser makes
declarativeNetRequest
See the address and title of every tab you have open
tabs
Schedule its own background tasks
alarms