Is Spector.js safe?

Low risk

Spector.js injects a global variable and wraps canvas APIs on every page visited, including before the user activates it.

On every page load, Spector.js runs a content script in the MAIN world that writes a named property to the window object and replaces the native HTMLCanvasElement and OffscreenCanvas context methods with its own wrappers. This happens unconditionally on all http, https, and file URLs, regardless of whether the user has activated the extension for that tab. No user data is transmitted to external servers.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

babylon.jsv0.9.32Chrome Web Store
20Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Updated 17 September 2026denbgaamihkadbghdceggmchnflmhpmk