Downloads a .xpi file (0.00 MB). In Zotero, open Tools → Plugins and install it from the file.
StarsPeople who starred the repository on GitHub: a rough measure of interest.
15
DownloadsAll-time downloads of its release files from GitHub. Installs from elsewhere aren't counted.
104
ContributorsPeople who have committed code to the repository.
2
LicenceThe licence the code is published under, as GitHub reports it.
MIT
C
Atlas gradeNot recommended
A+ABCC
because any website you visit can make it act through its local server: it doesn't check where requests come from, and 1 more finding
Next rung: B, once nothing in the code is a serious concern.
Applies to v0.3.0, released 16 May 2026Code checked · tested installed in Zotero 9.0.6 on 27 Sep 2026
Doesn't work with the current Zotero (10)Works with Zotero 7, 8, 9.
What we found in the codeSets the gradeThe worst finding in these three areas sets the grade.
Code transparencyReadable code, uploaded by the project's automated GitHub buildThe release file was uploaded by the project's automated GitHub build. We haven't yet rebuilt it from the source to compare.LowLow concern: normal for plugins that do this job. Listed so you know.
Updates
Updates come from this project's GitHub repositoryThe update address offers this version
Where your data goesNo web requests foundLowLow concern: normal for plugins that do this job. Listed so you know.
No further detail for this area yet.
Powerful capabilitiesAny website you visit can make it act through its local server: it doesn't check where requests come from, and 2 moreHighHigh concern: a serious problem. One high finding makes the grade C.
Any website you visit can make it act through its local server: it doesn't check where requests come fromhighHigh concern: a serious problem.Runs code web pages send ithighHigh concern: a serious problem.Runs code it assembles while runninglowLow concern.
Where we found it
Any website you visit can make it act through its local server: it d…bootstrap.js · line 88
A website can make it run code the site sends
var fn = new Function("Zotero", "return (async () => { " + code + " })();");
Runs code web pages send itbootstrap.js · line 88
var fn = new Function("Zotero", "return (async () => { " + code + " })();");
Before you installShown, not gradedFacts to help you decide. They don't change the grade.
Works withZotero 7, 8, 9 · not 10, 11 betaDoesn't work with the current Zotero (10)MediumMedium concern: worth reading before you install. One medium finding makes the grade B.