<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://consumerrights.wiki/index.php?action=history&amp;feed=atom&amp;title=WhatRuns</id>
	<title>WhatRuns - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://consumerrights.wiki/index.php?action=history&amp;feed=atom&amp;title=WhatRuns"/>
	<link rel="alternate" type="text/html" href="https://consumerrights.wiki/index.php?title=WhatRuns&amp;action=history"/>
	<updated>2026-05-30T00:46:09Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.44.0</generator>
	<entry>
		<id>https://consumerrights.wiki/index.php?title=WhatRuns&amp;diff=55151&amp;oldid=prev</id>
		<title>Louis: new product article on the whatruns chrome extension. covers the 2017 hacker news launch, the may 2026 arnott disclosure that it exfiltrates urls and ai-chat content with no obfuscation, the owned it ltd companies house record (formerly braggnow ltd), and the broader prompt poaching pattern.</title>
		<link rel="alternate" type="text/html" href="https://consumerrights.wiki/index.php?title=WhatRuns&amp;diff=55151&amp;oldid=prev"/>
		<updated>2026-05-29T21:00:58Z</updated>

		<summary type="html">&lt;p&gt;new product article on the whatruns chrome extension. covers the 2017 hacker news launch, the may 2026 arnott disclosure that it exfiltrates urls and ai-chat content with no obfuscation, the owned it ltd companies house record (formerly braggnow ltd), and the broader prompt poaching pattern.&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;{{ProductCargo&lt;br /&gt;
| ArticleType = Product&lt;br /&gt;
| Category = Browser extension&lt;br /&gt;
| Company = Owned it Ltd&lt;br /&gt;
| Description = Chrome and Edge extension that identifies website technologies; in May 2026 observed exfiltrating full URLs &amp;amp; AI chat content without disclosure.&lt;br /&gt;
| InProduction = Yes&lt;br /&gt;
| ReleaseYear = 2017&lt;br /&gt;
| Website = https://www.whatruns.com/&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;WhatRuns&amp;#039;&amp;#039;&amp;#039; is a Chrome and Edge browser extension, published by UK company [[Owned it Ltd]], that identifies the frameworks, fonts, content management systems, plugins, and analytics tools running on any website the user opens. On May 11, 2026, security researcher James Arnott of Am I Being Pwned? reported that WhatRuns also transmits every URL its roughly 400,000 users visit, along with the content of those users&amp;#039; conversations with hosted AI chatbots, back to Owned it Ltd&amp;#039;s servers, with no obfuscation of the request payloads &amp;amp; no disclosure of this collection in either the extension&amp;#039;s privacy policy or its Chrome Web Store data-safety declaration.&amp;lt;ref name=&amp;quot;aibp&amp;quot;&amp;gt;{{Cite web |last=Arnott |first=James |date=2026-05-11 |title=The AI Chat Scraping Extension Wall of Shame |url=https://amibeingpwned.com/blog/ai-chat-scraper-wall-of-shame/ |website=Am I Being Pwned? |access-date=May 29, 2026}}&amp;lt;/ref&amp;gt;&amp;lt;ref name=&amp;quot;cws&amp;quot;&amp;gt;{{Cite web |date=2026-04-27 |title=WhatRuns |url=https://chromewebstore.google.com/detail/whatruns/cmkdbmfndkfgebldhnkbfhlneefdaaip |website=Chrome Web Store |publisher=Google |access-date=May 29, 2026}}&amp;lt;/ref&amp;gt; As of May 29, 2026, the extension is still listed on the Chrome Web Store with both the &amp;#039;&amp;#039;Featured&amp;#039;&amp;#039; &amp;amp; &amp;#039;&amp;#039;Established Publisher&amp;#039;&amp;#039; badges in place.&amp;lt;ref name=&amp;quot;cws&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Background ==&lt;br /&gt;
&lt;br /&gt;
WhatRuns launched on Hacker News on August 25, 2017, marketed as a competitor to website-technology profilers such as Wappalyzer &amp;amp; BuiltWith.&amp;lt;ref name=&amp;quot;hn&amp;quot;&amp;gt;{{Cite web |date=2017-08-25 |title=Whatruns: Identify technologies used on any website |url=https://news.ycombinator.com/item?id=15098028 |website=Hacker News |access-date=May 29, 2026}}&amp;lt;/ref&amp;gt; The extension&amp;#039;s stated function is to read a page the user is already viewing, fingerprint the technologies in use, &amp;amp; display a sidebar that names them. A typical user installs WhatRuns because they want a one-click way to answer the question of what a site is built with, for example whether a blog runs WordPress, what fonts a competitor&amp;#039;s homepage uses, or which analytics package an e-commerce site has loaded.&amp;lt;ref name=&amp;quot;cws&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The Chrome Web Store listing positions WhatRuns directly against four named competitors. The product description on the listing reads in part that WhatRuns identifies technologies running on any site &amp;amp; frames itself as an alternative to Wappalyzer, BuiltWith, Datanyze, and Ghostery.&amp;lt;ref name=&amp;quot;cws&amp;quot; /&amp;gt; The listing categorizes the extension under Developer Tools.&lt;br /&gt;
&lt;br /&gt;
The extension&amp;#039;s own privacy policy, last updated August 2025, tells users that the only data leaving their browser is technical fingerprinting material. The policy states that the extension may collect &amp;#039;&amp;#039;&amp;quot;Source code snippets and public resources (e.g., scripts, metadata, or stylesheets) solely to identify technologies&amp;quot;&amp;#039;&amp;#039; along with &amp;#039;&amp;#039;&amp;quot;Timestamps and diagnostic information for debugging and performance tuning&amp;quot;&amp;#039;&amp;#039; &amp;amp; &amp;#039;&amp;#039;&amp;quot;A randomly generated identifier to differentiate anonymous extension sessions.&amp;quot;&amp;#039;&amp;#039;&amp;lt;ref name=&amp;quot;policy&amp;quot;&amp;gt;{{Cite web |date=August 2025 |title=Privacy Policy |url=https://www.whatruns.com/privacy |website=WhatRuns |access-date=May 29, 2026}}&amp;lt;/ref&amp;gt; The same policy states that &amp;#039;&amp;#039;&amp;quot;All collected data is anonymised and aggregated before any analysis or sharing&amp;quot;&amp;#039;&amp;#039; &amp;amp; that &amp;#039;&amp;#039;&amp;quot;We do not engage in cross-site tracking or behavioural profiling.&amp;quot;&amp;#039;&amp;#039;&amp;lt;ref name=&amp;quot;policy&amp;quot; /&amp;gt; Neither URLs nor AI chat content appear anywhere in the policy.&lt;br /&gt;
&lt;br /&gt;
== The May 2026 disclosure ==&lt;br /&gt;
&lt;br /&gt;
On May 11, 2026, James Arnott published an entry on the Am I Being Pwned? &amp;#039;&amp;#039;&amp;quot;AI Chat Scraping Extension Wall of Shame&amp;quot;&amp;#039;&amp;#039; naming WhatRuns as confirmed entry #6 in the table, with 400,000 users, the &amp;#039;&amp;#039;Featured &amp;amp; Verified&amp;#039;&amp;#039; badges, and an obfuscation status of &amp;#039;&amp;#039;None&amp;#039;&amp;#039;.&amp;lt;ref name=&amp;quot;aibp&amp;quot; /&amp;gt; Arnott&amp;#039;s &amp;#039;&amp;#039;&amp;quot;Confirmed&amp;quot;&amp;#039;&amp;#039; classification carries a specific operational meaning on the page. He writes that &amp;#039;&amp;#039;&amp;quot;Confirmed means I observed chat content leaving the browser in network traffic during manual testing.&amp;quot;&amp;#039;&amp;#039;&amp;lt;ref name=&amp;quot;aibp&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In a short note above the WhatRuns table row, Arnott discloses that he had personally used the extension before testing it:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;blockquote&amp;gt;&amp;#039;&amp;#039;WhatRuns shows users &amp;quot;what runs&amp;quot; on the sites they visit, for example if you visit a site that runs WordPress, it&amp;#039;ll tell you it runs WordPress. It&amp;#039;s actually pretty useful. I (James) previously had it installed, this one hits close to home.&amp;#039;&amp;#039;&amp;lt;/blockquote&amp;gt;&amp;lt;ref name=&amp;quot;aibp&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Arnott then states the observed behavior in one sentence:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;blockquote&amp;gt;&amp;#039;&amp;#039;WhatRuns exfiltrates every URL you visit, alongside AI chats. No exceptions here, they don&amp;#039;t even bother to obfuscate the requests which is nice to see, although there&amp;#039;s no indication to the user this exfiltration is happening.&amp;#039;&amp;#039;&amp;lt;/blockquote&amp;gt;&amp;lt;ref name=&amp;quot;aibp&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Arnott documents his methodology in a separate section of the same post, describing it as &amp;#039;&amp;#039;&amp;quot;the AIBP analysis pipeline (dynamic and static analysis in a sandbox), then manually verified by me, James, watching the AI chat exfiltration happen in my own (sandboxed) browser with my own eyes, inspecting outbound network requests.&amp;quot;&amp;#039;&amp;#039;&amp;lt;ref name=&amp;quot;aibp&amp;quot; /&amp;gt; A companion video on the amibeingpwned YouTube channel, titled &amp;#039;&amp;#039;WhatRuns caught scraping AI chats&amp;#039;&amp;#039;, shows the network capture from Arnott&amp;#039;s sandbox.&amp;lt;ref name=&amp;quot;yt&amp;quot;&amp;gt;{{Cite web |last=Arnott |first=James |title=WhatRuns caught scraping AI chats |url=https://www.youtube.com/watch?v=UYwUmaVohQk |website=YouTube |publisher=amibeingpwned |access-date=May 29, 2026}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
As of May 29, 2026, no other named security researcher has independently published a corroborating analysis of WhatRuns. The disclosure rests on Arnott&amp;#039;s single-researcher observation.&lt;br /&gt;
&lt;br /&gt;
== Data exfiltration mechanics ==&lt;br /&gt;
&lt;br /&gt;
Arnott&amp;#039;s finding is that two streams of data leave the browser of every WhatRuns user &amp;amp; arrive at Owned it Ltd&amp;#039;s servers. The first stream is the full URL of every page the user opens, not only the pages where the user clicks the WhatRuns icon. The second stream is the content of conversations the user has with hosted AI chatbots while the extension is installed.&amp;lt;ref name=&amp;quot;aibp&amp;quot; /&amp;gt; Neither stream is mentioned in the extension&amp;#039;s privacy policy or its Chrome Web Store data-safety declaration.&amp;lt;ref name=&amp;quot;policy&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;cws&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The technical detail that matters here is Arnott&amp;#039;s &amp;#039;&amp;#039;&amp;quot;no obfuscation&amp;quot;&amp;#039;&amp;#039; finding. In the Wall of Shame table, the &amp;#039;&amp;#039;Obfuscation&amp;#039;&amp;#039; column for WhatRuns reads &amp;#039;&amp;#039;None&amp;#039;&amp;#039;, the same value Arnott assigns to Similarweb &amp;amp; a less invasive value than the &amp;#039;&amp;#039;Extensive&amp;#039;&amp;#039; he assigns to the Stylish extension.&amp;lt;ref name=&amp;quot;aibp&amp;quot; /&amp;gt; Several other extensions in the same table wrap their exfiltrated payloads in LZ-String compression, base64, or character-mapping schemes that make the captured data harder to read at a glance during a network inspection.&amp;lt;ref name=&amp;quot;aibp&amp;quot; /&amp;gt; WhatRuns does not. The URL &amp;amp; chat-content payloads travel from the browser to Owned it Ltd in cleartext form within the TLS connection to the server, which means anyone with network-trace access to a WhatRuns user&amp;#039;s machine, such as a corporate IT team running endpoint inspection, can read the captured data directly without decoding it. Arnott characterizes the absence of obfuscation as &amp;#039;&amp;#039;&amp;quot;nice to see&amp;quot;&amp;#039;&amp;#039; from a researcher&amp;#039;s perspective, because it makes the behavior immediately visible in a network trace, while noting that &amp;#039;&amp;#039;&amp;quot;there&amp;#039;s no indication to the user this exfiltration is happening.&amp;quot;&amp;#039;&amp;#039;&amp;lt;ref name=&amp;quot;aibp&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Owned it Ltd ==&lt;br /&gt;
&lt;br /&gt;
The extension&amp;#039;s publisher is registered with the UK Companies House as OWNED IT LTD, company number 07755519.&amp;lt;ref name=&amp;quot;ch&amp;quot;&amp;gt;{{Cite web |title=OWNED IT LTD overview |url=https://find-and-update.company-information.service.gov.uk/company/07755519 |website=Companies House |publisher=UK Government |access-date=May 29, 2026}}&amp;lt;/ref&amp;gt; The company was incorporated on August 30, 2011 under the original name BRAGGNOW LTD; its name was changed to OWNED IT LTD on December 2, 2011, roughly three months after incorporation &amp;amp; nearly six years before the WhatRuns extension launched on Hacker News.&amp;lt;ref name=&amp;quot;ch&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;hn&amp;quot; /&amp;gt; The registered office is 11 Brindley Place, Brunswick Square, Birmingham, England, B1 2LP.&amp;lt;ref name=&amp;quot;ch&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Companies House lists the company&amp;#039;s SIC code as 63990, &amp;#039;&amp;#039;&amp;quot;Other information service activities not elsewhere classified,&amp;quot;&amp;#039;&amp;#039; &amp;amp; its status as Active. Last accounts were made up to March 31, 2025.&amp;lt;ref name=&amp;quot;ch&amp;quot; /&amp;gt; The address on the Companies House record matches the developer address Owned it Ltd publishes on its Chrome Web Store listing, which gives the developer as &amp;#039;&amp;#039;Ownedit Ltd&amp;#039;&amp;#039; at the same Birmingham B1 2LP location.&amp;lt;ref name=&amp;quot;cws&amp;quot; /&amp;gt; The Chrome Web Store renders the publisher name as the compressed string &amp;#039;&amp;#039;Ownedit Ltd&amp;#039;&amp;#039;; the UK registry name is &amp;#039;&amp;#039;OWNED IT LTD&amp;#039;&amp;#039;.&lt;br /&gt;
&lt;br /&gt;
== Other extensions in Arnott&amp;#039;s Wall of Shame ==&lt;br /&gt;
&lt;br /&gt;
WhatRuns is one of seven Chrome extensions Arnott catalogs on the AIBP Wall of Shame as either &amp;#039;&amp;#039;Confirmed&amp;#039;&amp;#039; or &amp;#039;&amp;#039;Capability&amp;#039;&amp;#039; for AI chat exfiltration in May 2026, alongside Stylish, Poper Blocker, Similarweb, StayFocusd, CrxMouse, StayFree, and UrbanVPN.&amp;lt;ref name=&amp;quot;aibp&amp;quot; /&amp;gt; The broader category was named in December 2025 by John Tuckner of Secure Annex, who coined the term &amp;#039;&amp;#039;Prompt Poaching&amp;#039;&amp;#039; for the practice of browser extensions capturing user conversations with AI chatbots &amp;amp; transmitting them to the extension publisher for use as training, analytics, or commercial intelligence material.&amp;lt;ref name=&amp;quot;sa&amp;quot;&amp;gt;{{Cite web |last=Tuckner |first=John |date=2025-12-28 |title=Prompt poaching runs rampant in extensions |url=https://secureannex.com/blog/prompt-poaching/ |website=Secure Annex |access-date=May 29, 2026}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Tuckner&amp;#039;s December 2025 post identifies Similarweb &amp;amp; StayFocusd as the two extensions his analysis examined in detail; it does not name WhatRuns.&amp;lt;ref name=&amp;quot;sa&amp;quot; /&amp;gt; Tuckner&amp;#039;s contribution to the WhatRuns story is the category, not the identification. Arnott&amp;#039;s May 2026 post is the first published security analysis to place WhatRuns inside the Prompt Poaching pattern. For the cross-extension pattern as a whole, see [[Browser extension AI chat exfiltration]].&lt;br /&gt;
&lt;br /&gt;
== Chrome Web Store status ==&lt;br /&gt;
&lt;br /&gt;
The Chrome Web Store listing for WhatRuns as of May 29, 2026, eighteen days after Arnott&amp;#039;s disclosure, shows version 1.10.0, last updated April 27, 2026, with a download size of 1.9 MiB.&amp;lt;ref name=&amp;quot;cws&amp;quot; /&amp;gt; The listing reports 400,000 users &amp;amp; a rating of 4.2 out of 5 from 813 user ratings.&amp;lt;ref name=&amp;quot;cws&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Two Google badges sit on the listing. The first is the &amp;#039;&amp;#039;Featured&amp;#039;&amp;#039; badge, which Google describes as &amp;#039;&amp;#039;&amp;quot;assigned to extensions that follow our technical best practices and meet a high standard of user experience and design&amp;quot;&amp;#039;&amp;#039; &amp;amp; which Google says is awarded after manual evaluation by Chrome team members, paying attention to &amp;#039;&amp;#039;&amp;quot;providing an enjoyable and intuitive experience, using the latest platform APIs and respecting the privacy of end-users.&amp;quot;&amp;#039;&amp;#039;&amp;lt;ref name=&amp;quot;badge&amp;quot;&amp;gt;{{Cite web |last=Kim |first=Debbie |date=2022-04-20 |title=Find great extensions with new Chrome Web Store badges |url=https://blog.google/products/chrome/find-great-extensions-new-chrome-web-store-badges/ |website=The Keyword |publisher=Google |access-date=May 29, 2026}}&amp;lt;/ref&amp;gt; The second is the &amp;#039;&amp;#039;Established Publisher&amp;#039;&amp;#039; badge, which Google describes as showcasing publishers who have &amp;#039;&amp;#039;&amp;quot;verified their identity and demonstrated compliance with the developer program policies.&amp;quot;&amp;#039;&amp;#039;&amp;lt;ref name=&amp;quot;badge&amp;quot; /&amp;gt; Google states that &amp;#039;&amp;#039;&amp;quot;publishers cannot pay to receive either badge.&amp;quot;&amp;#039;&amp;#039;&amp;lt;ref name=&amp;quot;badge&amp;quot; /&amp;gt; The WhatRuns listing displays the Established Publisher tooltip text &amp;#039;&amp;#039;&amp;quot;The publisher has a good record with no history of violations.&amp;quot;&amp;#039;&amp;#039;&amp;lt;ref name=&amp;quot;cws&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The listing also carries Google&amp;#039;s standard data-safety section, in which Owned it Ltd declares to users that data handled by WhatRuns is &amp;#039;&amp;#039;&amp;quot;Not being sold to third parties, outside of the approved use cases&amp;quot;&amp;#039;&amp;#039; &amp;amp; &amp;#039;&amp;#039;&amp;quot;Not being used or transferred for purposes that are unrelated to the item&amp;#039;s core functionality.&amp;quot;&amp;#039;&amp;#039;&amp;lt;ref name=&amp;quot;cws&amp;quot; /&amp;gt; The same listing notifies EU consumers that &amp;#039;&amp;#039;&amp;quot;This developer has not identified itself as a trader. For consumers in the European Union, please note that consumer rights do not apply to contracts between you and this developer.&amp;quot;&amp;#039;&amp;#039;&amp;lt;ref name=&amp;quot;cws&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
As of May 29, 2026, no public evidence indicates that Google has revoked either badge, removed the listing, or issued a public statement in response to Arnott&amp;#039;s report.&lt;br /&gt;
&lt;br /&gt;
== Consumer guidance ==&lt;br /&gt;
&lt;br /&gt;
A user installing WhatRuns to identify the technologies behind a website does not need an extension that runs in the background on every page the user opens. The technology-profiler feature requires only that the extension read the page the user has explicitly asked it to read. Per Arnott&amp;#039;s observation, WhatRuns transmits the URL of every page the user visits whether or not the user has interacted with the extension on that page, &amp;amp; transmits the content of conversations the user has with hosted AI chatbots.&amp;lt;ref name=&amp;quot;aibp&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Users who installed WhatRuns specifically for the technology-detection feature can uninstall it &amp;amp; use a server-side alternative that does not require browser-resident access to the user&amp;#039;s full browsing history or AI chat sessions, such as a website-technology lookup performed from a separate browser tab against a URL the user types in directly. Users who keep WhatRuns or any similar extension installed should review the extension&amp;#039;s host permissions in the Chrome &amp;#039;&amp;#039;chrome://extensions&amp;#039;&amp;#039; page; the access scope an extension declares there is the upper bound on what it can read from the browser.&lt;br /&gt;
&lt;br /&gt;
== See also ==&lt;br /&gt;
&lt;br /&gt;
* [[Browser extension AI chat exfiltration]]&lt;br /&gt;
* [[Owned it Ltd]]&lt;br /&gt;
* [[SimilarWeb]]&lt;br /&gt;
* [[Chrome Web Store]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
{{reflist}}&lt;br /&gt;
&lt;br /&gt;
[[Category:Browser extensions]]&lt;br /&gt;
[[Category:Products]]&lt;br /&gt;
[[Category:Privacy incidents]]&lt;/div&gt;</summary>
		<author><name>Louis</name></author>
	</entry>
</feed>