# Feature request: Inform users when an Anki addon communicates with third parties

**URL:** <https://forums.ankiweb.net/t/feature-request-inform-users-when-an-anki-addon-communicates-with-third-parties/50096>\
**Category:** Suggestions\
**Created:** [September 29, 2024, 5:23pm UTC](https://forums.ankiweb.net/t/feature-request-inform-users-when-an-anki-addon-communicates-with-third-parties/50096 "2024-09-29T17:23:54Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![joshdavham](https://sea2.discourse-cdn.com/flex002/user_avatar/forums.ankiweb.net/joshdavham/32/23596_2.png) [@joshdavham](https://forums.ankiweb.net/u/joshdavham)\
**Post date:** [September 29, 2024, 5:23pm UTC](https://forums.ankiweb.net/t/feature-request-inform-users-when-an-anki-addon-communicates-with-third-parties/50096/1 "2024-09-29T17:23:54Z")

</div>

Anki addons are capable of communicating with third parties via api calls, etc, meaning that a user’s data could be shared inapropriately and without the user’s knowldege or consent.

Given this, I think it would be helpful if there could be a little info tag or something on an addon’s page that says something like ‘this addon communicates with third parties’ just to keep the user informed.

In order to create this feature, there would likely need to be something like a quick code scan of the addon to see if there’s something like an ‘import requests’, etc in the addon’s code.

Let me know what you think!

---

<div class="post-metadata">

**Author:** ![Shigeyuki](https://sea2.discourse-cdn.com/flex002/user_avatar/forums.ankiweb.net/shigeyuki/32/23878_2.png) [@Shigeyuki](https://forums.ankiweb.net/u/Shigeyuki)\
**Post date:** [September 30, 2024, 1:47am UTC](https://forums.ankiweb.net/t/feature-request-inform-users-when-an-anki-addon-communicates-with-third-parties/50096/2 "2024-09-30T01:47:03Z")

</div>

Maybe it is not possible to auto identify only communications with third parties.

E.g. I’m developing [Anki Leaderboard](https://ankiweb.net/shared/info/175794613) (fork), which auto sends user statistics to the server as data. To simplify this part of the code, it looks like this:

```auto
import requests
url = "server URL"
data = "statistics data" 
response = requests.post(url, data=data, timeout=15)

```

This function is almost the same as when accessing a URL to retrieve data, e.g. if I want to only receive data without sending it looks like this:

```auto
import requests
response = requests.get(url, timeout=15)

```

So if we were to identify a function that sends data add-ons that merely receive data would be mis-detected, e.g. getting a definition from a dictionary, getting an image from Google, IPA, translating via google or DeepL, audio, using AI, etc. This is a very common feature in Anki add-ons.

Other challenging tasks such as these:

- Developers can also use “urllib” instead of “requests”.

- Developers can rename the module when importing.

- Developers can incorporate different apps that are not easily readable, e.g. my add-ons:

- Some of the add-ons have extremely large source code, so I don’t think they can be auto parsed by AnkiWeb’s server. (maybe AnkiWeb does not have the ability to parse the source code.)

Another way would be to read the code of the add-on, many add-ons have simple source code and can be easily read. The most commonly used programming language in Anki is Python which is the easiest to learn and recently you can also use AI such as ChatGPT.

However even if we completely check them I don’t think it is completely safe to do so, e.g. add-ons can be auto updated so even if you read the source code completely there is a possibility that features will be added later.

So I think a practical solution is to check if the developer is trustworthy, e.g. Anking and Migaku are reliable because they are third party organizations they hire professional programmers, some well-known individual add-ons developers on Anki are Glutanimate, Abdo, ijgnd, Tatsumoto, Arthur Milchior, etc. they have been active on Anki for many years and are very reliable.

---

<div class="post-metadata">

**Author:** ![eroscard](https://sea2.discourse-cdn.com/flex002/user_avatar/forums.ankiweb.net/eroscard/32/22632_2.png) [@eroscard](https://forums.ankiweb.net/u/eroscard)\
**Post date:** [September 30, 2024, 4:53pm UTC](https://forums.ankiweb.net/t/feature-request-inform-users-when-an-anki-addon-communicates-with-third-parties/50096/3 "2024-09-30T16:53:12Z")

</div>

I imagine it would be difficult to identify malicious code within addons, but it would be cool to have an addon like this, as it would provide more security to users.

Shige, you are also part of the history and select group of great addon creators.

My knowledge of databases is almost zero at the moment, but I hope to one day create an addon that works like a DB, updating the necessary information automatically.

The idea would be for users to communicate with each other within Anki, either through messages or through competition.

For example: in a study competition to see who can make the same deck the fastest, it would be fun to study like this and see each other’s level.

---

<div class="post-metadata">

**Author:** ![joshdavham](https://sea2.discourse-cdn.com/flex002/user_avatar/forums.ankiweb.net/joshdavham/32/23596_2.png) [@joshdavham](https://forums.ankiweb.net/u/joshdavham)\
**Post date:** [September 30, 2024, 8:51pm UTC](https://forums.ankiweb.net/t/feature-request-inform-users-when-an-anki-addon-communicates-with-third-parties/50096/4 "2024-09-30T20:51:34Z")

</div>

Thanks for your thoughts!

To respond to a couple of your points:

- I don’t think that Anki should only look for when data is being sent to third parties. To simplify things: I’d suggest adding the ‘third party’ tag if an addon so much as retrieves data from third parties (e.g., calling a dictionary api)
- I understand that the ‘requests’ module isn’t the only python module to communicate with third parties and that this can be renamed, but I still think detection of importing these types of modules should be possible most of the time with good enough accuracy.
- You bring up a good point about updating addons. That would require a bit of work, for example if an addon were to previously make calls to a locally installed dictionary, then later switch to a third party dicitonary.
- When it comes to checking with the trustworthiness of the developers, I wouldn’t be so generous (even if they are organizations with professional programmers). I won’t name names, but I strongly distrust one of the names you mentioned.

Overall, while I don’t think adding this tag would make addons safe in itself, I do think it would encourage users to exercise more caution within the anki ecosystem and keep them more informed as well.

---

<div class="post-metadata">

**Author:** ![addons\_zz](https://sea2.discourse-cdn.com/flex002/user_avatar/forums.ankiweb.net/addons_zz/32/43_2.png) [@addons\_zz](https://forums.ankiweb.net/u/addons_zz)\
**Post date:** [October 2, 2024, 1:18am UTC](https://forums.ankiweb.net/t/feature-request-inform-users-when-an-anki-addon-communicates-with-third-parties/50096/5 "2024-10-02T01:18:53Z")

</div>

For Sublime Text packages (add-ons), a public repository is reviewed before a new package is added: [Pull requests · wbond/package\_control\_channel · GitHub](https://github.com/wbond/package_control_channel/pulls)

Adding a community-driven review process for add-ons before submitting them could be a start. However, that does not help if the add-on developer later adds such third-party communication (i.e., after the add-on is accepted and published). This happened with one famous Sublime text addon with about 3 million downloads. The community spotted the ‘intrusive’ code in one update and removed the add-on some days later from the public channel. Later, the ‘intrusive’ code was removed, and the add-on was re-accepted for new downloads again.

A reliable solution could be an AI that analyzes each add-on update (code) before publishing and studies its code to look for bad actors. However, the AI should be prone to error; someone would have to supervise it and instruct it/correct its behavior when it goes wrong, not to mention the costs of running this AI for each add-on submission.

Given the current situation, someone looking for a trustworthy add-on should read its evaluations, who the author is, and, if possible, look into its source code (if they can understand it).

---

<div class="post-metadata">

**Author:** ![joshdavham](https://sea2.discourse-cdn.com/flex002/user_avatar/forums.ankiweb.net/joshdavham/32/23596_2.png) [@joshdavham](https://forums.ankiweb.net/u/joshdavham)\
**Post date:** [October 2, 2024, 4:18am UTC](https://forums.ankiweb.net/t/feature-request-inform-users-when-an-anki-addon-communicates-with-third-parties/50096/6 "2024-10-02T04:18:05Z")

</div>

> Given the current situation, someone looking for a trustworthy add-on should read its evaluations, who the author is, and, if possible, look into its source code (if they can understand it).

Agreed.

> Adding a community-driven review process for add-ons before submitting them could be a start.

What could such a community-driven review process look like? I’ve personally never heard of anything like that.

---

<div class="post-metadata">

**Author:** ![sorata](https://sea2.discourse-cdn.com/flex002/user_avatar/forums.ankiweb.net/sorata/32/34115_2.png) [@sorata](https://forums.ankiweb.net/u/sorata)\
**Post date:** [October 2, 2024, 4:48am UTC](https://forums.ankiweb.net/t/feature-request-inform-users-when-an-anki-addon-communicates-with-third-parties/50096/7 "2024-10-02T04:48:48Z")

</div>

> [@addons\_zz](#):
>
> A reliable solution could be an AI that analyzes each add-on update (code) before publishing and studies its code to look for bad actors.

It can probably be used alongside with community review. In Wikipedia, we have tools that rate contributions on whether they are damaging or not or whether they were made in good faith, etc. It helps those who are patrolling. I imagine it would be helpful if particular parts of the code can be flagged in a similar way.

---

<div class="post-metadata">

**Author:** ![addons\_zz](https://sea2.discourse-cdn.com/flex002/user_avatar/forums.ankiweb.net/addons_zz/32/43_2.png) [@addons\_zz](https://forums.ankiweb.net/u/addons_zz)\
**Post date:** [October 3, 2024, 12:39am UTC](https://forums.ankiweb.net/t/feature-request-inform-users-when-an-anki-addon-communicates-with-third-parties/50096/8 "2024-10-03T00:39:41Z")

</div>

> [@joshdavham](#):
>
> What could such a community-driven review process look like?

A more restricted code review could be a GitHub repository; all addons would have to open a pull-request committing their code. Selected community members will review this pull request and, if approved, merge it. After the code is merged, Anki will be able to download this addon. This is entirely restricted, as any add-on update would have to submit a new pull request to be reviewed and approved again before being released to Anki users.

This is also the safest option for any Anki user, as it would significantly reduce the probability of malicious code being installed. However, it would perhaps burden the community, which would have to review pull requests and merge them constantly.

> [@sorata](#):
>
> I imagine it would be helpful if particular parts of the code can be flagged in a similar way.

It seems like a good idea. A GitHub bot with AI capabilities could review these pull requests and pre-approve or reprove them, and later, some community members could merge or close them.

---

<div class="post-metadata">

**Author:** ![joshdavham](https://sea2.discourse-cdn.com/flex002/user_avatar/forums.ankiweb.net/joshdavham/32/23596_2.png) [@joshdavham](https://forums.ankiweb.net/u/joshdavham)\
**Post date:** [October 3, 2024, 4:01pm UTC](https://forums.ankiweb.net/t/feature-request-inform-users-when-an-anki-addon-communicates-with-third-parties/50096/9 "2024-10-03T16:01:52Z")

</div>

A community review sounds ideal in many ways, but, as you said, it would likely burden the community. Not only would it be a lot of work for good open source devs to maintain, but I think it would also discourage more anki addon development.

Personally, I’m more in favor of some sort of an automated code scan - be it AI or otherwise, just to look for high risk code.

More generally however, it’s not like I think addons communicating with third parties is bad in any way, I just think that there is currently a dangerous level of trust (naivety?) in the Anki ecosystem. People actually do store sensitive information in their decks and they do put too much trust into the addons and decks they download (which aren’t vetted). Fundamentally, I was just thinking that the ‘communicates with third parties’ could work to make users just a bit more thoughtful(/paranoid) about what they download and thus a bit more safe.

---

<div class="post-metadata">

**Author:** ![Shigeyuki](https://sea2.discourse-cdn.com/flex002/user_avatar/forums.ankiweb.net/shigeyuki/32/23878_2.png) [@Shigeyuki](https://forums.ankiweb.net/u/Shigeyuki)\
**Post date:** [October 5, 2024, 3:05pm UTC](https://forums.ankiweb.net/t/feature-request-inform-users-when-an-anki-addon-communicates-with-third-parties/50096/10 "2024-10-05T15:05:05Z")

</div>

I think that malicious programs that work offline are also highly dangerous, e.g. malware built in from the start, corrupting the PC irretrievably, corrupting the deck schedule. So I think if we base it on sends and receives, there may be a possibility to miss something like that.

Basically decks do not contain any info about money or privacy, so even if the add-on is collecting and submitting data about Anki and decks there is little risk to the user (such data is usually collected for research and improvement purposes). If the add-on is trying to access data that has nothing to do with Anki it becomes suspicious.

Other, I think of reliability like this:

1. Does author develop a lot of volunteer work?

2. Is author a professional programmer or not?

3. Author is not anonymous?

4. Is author really the person?

5. Is add-on original or not?

6. Are there many contributors?

7. Are there lots of users?

8. Is the code written for easy reading?

9. Is the add-on code simple and short?

10. Does the author list the license correctly?

11. Is the add-on publicly available on Github?

12. Does author actively interact with users?

* * *

So in my opinion third parties and well known developers are very reliable, they fulfill many of these checkpoints, are develop for free in huge quantities and their code is very serious, so it is clear from the developer’s view that they are not interested in profit or mischief at all.

These developers’ activities are difficult for the average user to understand, e.g. the hard work of the developers does not change anything on the surface thus from average users’ views the developers seem to be doing nothing.(thus for the average users, third parties and monetizing authors look like scammers)

* * *

However as already explained even if all of these are checked they are not completely safe.

E.g. These are the risks:

1. Embedding maulware when updating an add-on.
2. Embedding malicious code in a sophisticated way that is not known to the average developer.
3. Using different code on AnkiWeb than what is publicly available on GitHub.
4. The account is real but has been hacked.
5. Photos and biographies are AI generated.
6. Author appears friendly but is actually a scammer.
7. Removing malicious code in some way after execution.

In short add-ons can be developed for anything so any malicious workaround can be developed, so if users want to be as safe as possible it is safest to use native Anki without add-ons, Anki for desktop is checked by official Anki and is read by many developers, so it is the most reliable. (Basically to develop add-ons developers need to read Anki’s code.)

* * *

So in my case measures are like this:

1. Make sure that if my PC is broken or infected with malware, it doesn’t matter.

2. Toggle off suspicious add-ons and examine the code before running them.

* * *

However I think it is extremely unlikely that add-ons actually contain any kind of malicious malware, according to AnkiForums maybe there has been only one suspicious case so far. (Though it is possible that it was quickly removed by the official Anki, or possibly undetected.)

I guess the reason for this is that the number of users of add-ons is extremely small, e.g. according to the author’s page of my add-ons releases, the number of downloads of the usual add-ons (not so popular but still useful) is in the tens to hundreds, even the leaderboard of popular add-ons currently has only about 1700 active users.

This means that even if a malicious developer develops add-ons only tens or hundreds of them will be downloaded. So if the malware is for profit there is no benefit to developing add-ons at all, it would be easier and more reasonable to develop a Chrome extension with a large number of users instead or to send a lot of spam emails.

* * *

So I check the security of these as well just to be sure, but in reality I’m mainly trying to prevent errors and bugs in add-ons, like this:

1. Install and update add-ons one by one.

2. Wait a week or so to update add-ons.

3. See AnkiWeb page before updating.

4. Toggle off add-ons that are only used occasionally.

If measures like this are taken for errors maybe it will help a little bit for security measures. (e.g. by delaying the update someone might discover the malicious code first and the add-on will be removed.)

---

<div class="post-metadata">

**Author:** ![ambushfall](https://sea2.discourse-cdn.com/flex002/user_avatar/forums.ankiweb.net/ambushfall/32/33794_2.png) [@ambushfall](https://forums.ankiweb.net/u/ambushfall)\
**Post date:** [May 14, 2026, 6:33am UTC](https://forums.ankiweb.net/t/feature-request-inform-users-when-an-anki-addon-communicates-with-third-parties/50096/11 "2026-05-14T06:33:39Z")

</div>

Your answer isn’t really ideal,

There is a solution to malware code, the addons would execute in an isolated environment from the userspace, having only certain endpoints available, and those being other addons, think virtual HDD space, or for network requests chrome extensions with CORS or (Preflight requests and hooks).

Is this overkill? No, it’s security, is it worth to the owners of Anki?  
No, profit and less cost is the way to go, anki wouldn’t care if your pc is bricked, or if you got ransomed, not that it would happen either (regardless).

Literally, it’s that hard, and simple at the same time. Cheers

---

<div class="post-metadata">

**Author:** ![Danika\_Dakika](https://sea2.discourse-cdn.com/flex002/user_avatar/forums.ankiweb.net/danika_dakika/32/17815_2.png) [@Danika\_Dakika](https://forums.ankiweb.net/u/Danika_Dakika)\
**Post date:** [May 14, 2026, 8:28am UTC](https://forums.ankiweb.net/t/feature-request-inform-users-when-an-anki-addon-communicates-with-third-parties/50096/12 "2026-05-14T08:28:20Z")

</div>

If you have specific concerns about security in Anki, I hope you’ll share them with the team privately – [Getting Help - Anki Manual](https://docs.ankiweb.net/getting-help.html#private-questions) .

---

<div class="post-metadata">

**Author:** ![Shigeyuki](https://sea2.discourse-cdn.com/flex002/user_avatar/forums.ankiweb.net/shigeyuki/32/23878_2.png) [@Shigeyuki](https://forums.ankiweb.net/u/Shigeyuki)\
**Post date:** [May 14, 2026, 12:03pm UTC](https://forums.ankiweb.net/t/feature-request-inform-users-when-an-anki-addon-communicates-with-third-parties/50096/13 "2026-05-14T12:03:14Z")

</div>

> [@ambushfall](#):
>
> or for network requests chrome extensions with CORS or (Preflight requests and hooks).

The current version of Anki uses PyQt and Ot uses Chromium for its browser, so it’s almost identical to Chrome, so it might be possible to create add-ons using JavaScript and load them using a mechanism very similar to that of Chrome extensions, I think this would be a safer approach. (but this limits development flexibility and makes it incompatible with existing add-ons.)
