Plugins

Nutstore

by Arthur-Lucifer · github.com/Arthur-Lucifer/zotero-plugin-nutstore

Nutstore sso plugin for Zotero

View source
Downloads a .xpi file (0.2 MB). In Zotero, open Tools → Plugins and install it from the file.
StarsPeople who starred the repository on GitHub: a rough measure of interest.
0
DownloadsAll-time downloads of its release files from GitHub. Installs from elsewhere aren't counted.
1
ContributorsPeople who have committed code to the repository.
5
LicenceThe licence the code is published under, as GitHub reports it.
AGPL-3.0
C
Atlas gradeNot recommended
because its code is obfuscated in a bundled package (@nutstore/sso-js), not in the plugin's own code
Applies to v2.0.3, released 4 Feb 2026Code checked · not yet tested in a live Zotero
Doesn't work with the current Zotero (10)Works with Zotero 7, 8.
Fork of nutstore/zotero-plugin-nutstoreA copy of another listed plugin, changed by someone else.
Another plugin uses the same IDOne other plugin shares this add-on ID. Zotero can only install one of them.
What we found in the codeSets the gradeThe worst finding in these three areas sets the grade.
Code transparencyObfuscated code in a bundled package (@nutstore/sso-js), not in the plugin's own codeThe release file was uploaded by the project's automated GitHub build. The code is obfuscated, so it can't be compared with the source. We haven't yet checked whether this file matches the public source code.HighHigh concern: a serious problem. One high finding makes the grade C.
Updates
Updates come from this project's GitHub repositoryThe update address offers this version
Where your data goesWe couldn't fully check where it sends data: the code is obfuscated2 addresses in 1 group.UnknownWe couldn't check this yet.
Apps you connect (2)
dav-demo.jianguoyun.comdav.jianguoyun.com
Where we found it
dav-demo.jianguoyun.comcontent/scripts/zotero-plugin-nutstore.js · line 4551
Zotero.Prefs.set("sync.storage.url", getNutstoreWebdavUrl());
dav.jianguoyun.comcontent/scripts/zotero-plugin-nutstore.js · line 4551
Zotero.Prefs.set("sync.storage.url", getNutstoreWebdavUrl());
Powerful capabilitiesChanges Zotero settings that aren't its own, and 5 moreMediumMedium concern: worth reading before you install. One medium finding makes the grade B.
Changes Zotero settings that aren't its ownmediumMedium concern: worth reading before you install.A zotero:// link (a web page can open one) can make it install add-ons without asking you (from zotero-plugin-toolkit)mediumMedium concern: worth reading before you install.A zotero:// link can make it run code if you approve a prompt (from zotero-plugin-toolkit)mediumMedium concern: worth reading before you install.Stores API keys or passwordslowLow concern.Works with files on your computerlowLow concern.Uses Zotero's password managerlowLow concern.
Where we found it
Changes Zotero settings that aren't its owncontent/scripts/zotero-plugin-nutstore.js · line 4535

Changes where Zotero syncs your library or files, at startup, without asking

Zotero.Prefs.set("sync.storage.username", "");
A zotero:// link (a web page can open one) can make it install add-o…content/scripts/zotero-plugin-nutstore.js · line 129

zotero://plugin

Services.io.getProtocolHandler("zotero").wrappedJSObject._extensions["zotero://plugin"] = pluginBridgeExtension;
A zotero:// link can make it run code if you approve a promptcontent/scripts/zotero-plugin-nutstore.js · line 85

zotero://ztoolkit-debug

Services.io.getProtocolHandler("zotero").wrappedJSObject._extensions["zotero://ztoolkit-debug"] = debugBridgeExtension;
Before you installShown, not gradedFacts to help you decide. They don't change the grade.
Works withZotero 7, 8 · not 9, 10, 11 betaDoesn't work with the current Zotero (10)MediumMedium concern: worth reading before you install. One medium finding makes the grade B.
Zotero 7 ✓ worksZotero 8 ✓ worksZotero 9 ✗ doesn't workZotero 10 ✗ doesn't workZotero 11 beta ✗ doesn't work
What you'll needZotero 7, 8Detected automatically from its code
No further detail for this area yet.
MaintenanceActive · last release 4 Feb 20265 contributors
No further detail for this area yet.
LanguagesDocumentation in EnglishInterface: English and Chinese
No further detail for this area yet.
We report what we found in the code. Open any area for the evidence.How we gradeReport a problem

What it does

Description coming soon. We haven't written a summary yet. The line above is the developer's own description; the developer's README is linked above.

What you'll need

Detected automatically
  • Zotero 7, 8Not working with Zotero 10

Where your data goes

We found: we couldn't fully check where it sends data: the code is obfuscated. 2 addresses in 1 group.

Apps you connect (2)
dav-demo.jianguoyun.comdav.jianguoyun.com
Evidence · file and line
dav-demo.jianguoyun.comcontent/scripts/zotero-plugin-nutstore.js · line 4551
Zotero.Prefs.set("sync.storage.url", getNutstoreWebdavUrl());
dav.jianguoyun.comcontent/scripts/zotero-plugin-nutstore.js · line 4551
Zotero.Prefs.set("sync.storage.url", getNutstoreWebdavUrl());

Forks and alternatives

Fork of nutstore/zotero-plugin-nutstore.

1 other plugin uses the same ID as this one. Every Zotero plugin carries an ID, a name tag Zotero uses to tell plugins apart. These 2 plugins carry the same one, because people copied Nutstore to make their own versions and kept its ID.Show what this means
  • You can only have one. Zotero sees them as the same plugin.
  • Installing another replaces it. If you install one of the others, it takes this one's place.
  • Check what you install. Several share this plugin's name, so make sure the file comes from the one you meant.
Nutstore · this pluginArthur-Lucifer/zotero-plugin-nutstoreCNot recommended14 Feb 2026
NutstoreThe most used · nutstore/zotero-plugin-nutstoreCNot recommended144,73624 Aug 2026
See all 2 and how they differ →

No forks listed.

The developer's response

The developer hasn't responded. Developers can reply here, and their reply sits next to our findings.I'm the developer
Install Nutstore
CNot recommended
We don't recommend itIts code is obfuscated in a bundled package (@nutstore/sso-js), not in the plugin's own code.
Better-graded plugins for the same job
We don't know one yet.
Read what we found