Is Similarweb Sales Extension: Contact Finder & AI Email Writer safe?
Similarweb Sales is medium risk. Using the extension's sidebar or email-agent controls makes the content script post interaction events to the Similarweb iframe: current page URL, event category, action, event name, and optional custom data describing what you clicked.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
Interaction events include the current page URL
Using the extension's sidebar or email-agent controls makes the content script post interaction events to the Similarweb iframe: current page URL, event category, action, event name, and optional custom data describing what you clicked.
- Severity
- Medium unwanted
- Type
- Unexpected
- CWE
- CWE-200
- Source
- Dynamic sandbox
You use a visible extension feature such as the sidebar, meeting brief, badge, or email assistant.
The content script sends an interaction event that includes the current page URL to the Similarweb iframe.
- Current page URLhttps://mail.google.com/mail/u/0/#inbox
Shows which page was open when you used the extension feature.
- Event categorycraft email agent
Groups the feature area where the click happened.
- Event action and nameclick / generate email
Describes the specific control or action you used.
- Custom interaction data{"email_mode":"compose new","target":"email-agent"}
Adds details about the mode or target for the feature you used.
The tracking helper adds window.location.href before posting to the iframe
Readable tracking helper
deobfuscated/dist/frame.jsvar Ns = () => { let t; return { init: r => { t = r }, trackEvent: (r, o, s, i) => { if (!t) { console.warn("TrackingService: trackEvent called before init()"); return } t.sendMessage({ message: "track event", category: r, action: o, eventName: s, url: window.location.href, custom_data: i }) } }},re = Ns();Readable email-agent click handler
deobfuscated/dist/frame.jss.addEventListener("click", i => { i.stopPropagation(); let a = r ? "gmail toolbar icon/load gmail assistant/with recipient" : "gmail toolbar icon/load gmail assistant/no recipient", c = r ? "reply" : "compose new"; re.trackEvent("craft email agent", "click", a, { email_mode: c, target: "email-agent" }), re.trackEvent("craft email agent", "click", "generate email", { email_mode: c, target: "email-agent" }), window.open(Ur, "_blank")})- pro.similarweb.com
Hosts the Similarweb sales-extension iframe that receives interaction event messages from the content script.
Dynamic analysis did not capture a live request to pro.similarweb.com because the authenticated extension UI did not render in that session. The confirmed evidence here is the shipped code path that posts current-page interaction events to the iframe.