Is Xpath Ninja safe?

Clean risk

Xpath Ninja captures clicked element attributes and text from every webpage and sends them to a local HTTP server at 127.0.0.1:8000.

On every mousedown event across all websites and frames, the extension collects the target element's tag, class, id, aria-label, and visible text content. This data is assembled into an XPath descriptor and forwarded from the content script to the background page, which POSTs it as JSON to http://127.0.0.1:8000/my-api/. The local server appears to be a companion test-automation tool; page text from any site visited—including forms and buttons—flows to that endpoint on every click.

xpathninjaextensionv2.0.2Chrome Web Store
0Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

What it can do

Permissions this extension asks for, as declared in version 2.0.2. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Write to your clipboard

    clipboardWrite

  • Store data in your browser

    storage

  • Show a panel beside the page

    sidePanel

Where it sends data

Destinations our analysis observed Xpath Ninja contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.

  • 127.0.0.1:8000

    Xpath Ninja sends data to 127.0.0.1:8000. No other extension we have analysed sends data here.

Updated 30 September 2026lmichhbmhiejfedjilpaphhdcbidehgh