Is Sourcegraph safe?

Low risk

Sourcegraph loads Google Fonts CSS when adding its interface to GitHub pages.

When the Sourcegraph extension mounts its buttons on GitHub or GitHub Enterprise pages, its content script imports Inter font CSS from Google Fonts. That request can expose routine request metadata such as your IP address and referrer to Google Fonts while the extension UI loads.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

Sourcegraphv24.3.8Chrome Web Store
20Risk
Who publishes it

Sourcegraph - no other listings under this identity

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
Sourcegraph
Declared legal entity
Sourcegraph
Registered address
981 Mission St, San Francisco, CA 94103, USA
Registered contact
Quinn Slack

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

What it can do

Permissions this extension asks for, as declared in version 24.3.2. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to. The current listed version is 24.3.8, which we have not unpacked yet.

  • Read and change your data on github.com

    https://github.com/*

  • Store data in your browser

    storage

  • Run its own code inside the pages you visit

    scripting

Where it sends data

Destinations our analysis observed Sourcegraph contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.

  • fonts.googleapis.comwidely used

    Sourcegraph sends data to fonts.googleapis.com. A widely used service: 123 other extensions we have analysed send data here.

Updated 30 September 2026dgjhfomjieaadpoljlnidmbgkdffpack