WPSNIFFER

WPSNIFFER

ID: kihhefcbenhkjgjhchanjfhhflaojldn

Supported Languages

🇺🇸US English

Extension Info & Metadata

Status
Active
Version
2.23
Size
0.07 MB
Rating
3.7/5
Reviews
84
Users
10,000
Type
Extension
Updated
Jul 19, 2026
Category
Developer tools
Price
Free
Featured
No
Visibility
Listed
Mature
No
By Google
No
Trusted
Yes

Publisher Contextual Analysis

Trusted
Author
andyforsberg.comView Profile
Website
Visit
Total Extensions
1
Active
1
Obsolete
0
Listed
1
Unlisted
0
Total Users
10,000
Screenshot 1

Detects the WordPress theme, plugins, version, and host used on any WordPress site.

Detects active WordPress theme being used on current WordPress website and links to the theme, if not found then returns a Google search for "{theme's name} wordpress theme".

Item
Type
Severity
Description
Contextual Risk Factors
Risk Factor
High
The following context increases the overall risk:• 15% increase: Older manifest version lacks modern security controls
storage
Permission
Medium
This permission allows storing data locally in the browser. Rated Medium because it can persist sensitive user data, track user activities over time, and potentially store malicious payloads.
tabs
Permission
Medium
This permission enables tab management and monitoring. Rated Medium because it can track open tabs, access tab metadata, and monitor user browsing patterns.
Older Manifest Version
Risk Factor
Medium
This extension uses Manifest Version 2
http://*/*
Permission
Unknown
No classification available for this permission.
https://*/*
Permission
Unknown
No classification available for this permission.

The extension initializes Parse.com (a third-party BaaS) with hardcoded API credentials and accumulates the domain of every WordPress site the user visits in local storage, then batch-uploads the full list to Parse.com every 10 minutes via DataAccess.flush(). The uploaded payload contains the stripped domain (browsing history) of visited sites. This data flows to a third-party server unrelated to the publisher domain (andyforsberg.com), is never disclosed in the CWS listing, and the TODO comment on line 8 confirms the developer knew it was not production-ready but shipped it anyway.

data.js (Line 1)
var WPSNIFFER_RESULTS = "WPSNIFFER_RESULTS";var APP_ID = "L1AlvBHhdJr2L79q7h382XT5hiWoZMo9czWfOqI3";var APP_KEY = "vKHvkIHXtMDhZJlkzr4cHPnhOCuy4pEIHueLXf9n";Parse.initialize(APP_ID, APP_KEY);var ThemeResult = Parse.Object.extend("TestObject"); // TODO change in productionfunction DataAccess() {};DataAccess.prototype.add = function(result) {    var self = this;    if (!result || !result.domain || !result.theme) {      return;    }    try {      result.theme = result.theme.split("-")[0];      result.domain = result.domain.replace(/http[s]?:\/\//, '');

The flush() method retrieves the accumulated list of visited WordPress domains from local storage and uploads them all to Parse.com via Parse.Object.saveAll(). This is called on extension startup and then on a 10-minute interval (background.js line 109). The 'TODO remove in production' comment on line 60 is further evidence that the developer deliberately left data-exfiltration code active in a published extension, not by accident.

data.js (Line 48)
DataAccess.prototype.flush = function() {  var self = this;  try {    chrome.storage.local.get({      WPSNIFFER_RESULTS: []    }, function(o) {      if (chrome.runtime.lastError) {        return;      }      var results = o[WPSNIFFER_RESULTS] || [];      if (results.length) {        var collection = results.map(function(result) {          result.name = result.domain; // TODO remove in production          return new ThemeResult(result);        });        Parse.Object.saveAll(collection, {          success: function() {            chrome.storage.local.set({              WPSNIFFER_RESULTS: []            }, function() {});          },          error: function() {}        });      }    });  } catch (ex) {}};

The background page starts an exfiltration loop immediately on load and repeats every 10 minutes. The comment 'start upload to parse.com loop' is explicit about the intent. Combined with the domain collection in data.js, this creates a persistent covert telemetry channel that operates entirely in the background without user awareness or consent.

background.js (Line 6)
var UPLOAD_INTERVAL = 10 * 60 * 1000; // 10 minutes...// start upload to parse.com loopdataAccess.flush();setInterval(function() {  dataAccess.flush();}, UPLOAD_INTERVAL);

By severity

Critical2
High1
Medium0
Low0

Versions scanned

Showing 1 of 2 scanned versions with more than one unique finding. Counts are unique findings that include each version.

Extension VersionCode Review Findings
2.233

Files with findings

2 distinct paths — top paths by unique finding count:

  • data.js2
  • background.js1
S.No.
Category
Severity
File
Summary
Found in Version
1Data Exfiltration
critical
data.js (line 48)The flush() method retrieves the accumulated list of visited WordPress domains from local storage and uploads them all to Parse.com via Parse.Object.saveAll(). This is called on extension startup and then on a 10-minu…
2Unauthorized Data Collection
critical
data.js (line 1)The extension initializes Parse.com (a third-party BaaS) with hardcoded API credentials and accumulates the domain of every WordPress site the user visits in local storage, then batch-uploads the full list to Parse.co…
3Tracking
high
background.js (line 6)The background page starts an exfiltration loop immediately on load and repeats every 10 minutes. The comment 'start upload to parse.com loop' is explicit about the intent. Combined with the domain collection in data.…
URLs
28
IPv4
0
IPv6
0

URLs

View the external URLs this extension communicates with to understand its network activity and data interactions.

Gain full insight into all external connections.

Upgrade for full visibility.

getbootstrap.com-http://getbootstrap.com
github.com/twbs/bootstrap/blob/master/LICENSEhttps://github.com/twbs/bootstrap/blob/master/LICENSE
fontawesome.io-http://fontawesome.io
fontawesome.io/licensehttp://fontawesome.io/license
fonts.gstatic.com/s/opensans/v10/K88pR3goAWT7BTt32Z01m5Bw1xU1rKptJj_0jans920.woff2http://fonts.gstatic.com/s/opensans/v10/K88pR3goAWT7BTt32Z01m5Bw1xU1rKptJj_0jans920.woff2
fonts.gstatic.com/s/opensans/v10/RjgO7rYTmqiVp7vzi-Q5UZBw1xU1rKptJj_0jans920.woff2http://fonts.gstatic.com/s/opensans/v10/RjgO7rYTmqiVp7vzi-Q5UZBw1xU1rKptJj_0jans920.woff2
fonts.gstatic.com/s/opensans/v10/ttwNtsRpgsxVmgGGmiUOEpBw1xU1rKptJj_0jans920.woff2http://fonts.gstatic.com/s/opensans/v10/ttwNtsRpgsxVmgGGmiUOEpBw1xU1rKptJj_0jans920.woff2
fonts.gstatic.com/s/opensans/v10/LWCjsQkB6EMdfHrEVqA1KZBw1xU1rKptJj_0jans920.woff2http://fonts.gstatic.com/s/opensans/v10/LWCjsQkB6EMdfHrEVqA1KZBw1xU1rKptJj_0jans920.woff2
fonts.gstatic.com/s/opensans/v10/xozscpT2726on7jbcb_pApBw1xU1rKptJj_0jans920.woff2http://fonts.gstatic.com/s/opensans/v10/xozscpT2726on7jbcb_pApBw1xU1rKptJj_0jans920.woff2
fonts.gstatic.com/s/opensans/v10/59ZRklaO5bWGqF5A9baEEZBw1xU1rKptJj_0jans920.woff2http://fonts.gstatic.com/s/opensans/v10/59ZRklaO5bWGqF5A9baEEZBw1xU1rKptJj_0jans920.woff2
Showing 1 to 10 of 30 rows
Rows per page:

Gain full insight into all external connections.

Upgrade for full visibility.

No IP addresses found
Version
Size
Is Malicious
Findings
Permhash
4.0
Latest
0.07 MB
Malicious
2.23
0.33 MB
Malicious
3
Showing 1 to 2 of 10 rows
Rows per page:

Code Diff

Compare extension code between any two versions.

0 changed files (scanned top 25 shared text files)

No comparable text files found between these versions.

Browse and explore files within this extension package

Gain full insight into all external connections.

Upgrade for full visibility.