What JavaScript Bookmarks Do
A JavaScript bookmark, often called a bookmarklet, stores a small JavaScript action instead of an ordinary web address. When you deliberately open it, the action runs in the page you are viewing. It can make useful changes such as simplifying a page, adjusting its presentation, copying structured details, or starting a trusted workflow.
That flexibility also gives the code access to the current page. Only save and run JavaScript you wrote, reviewed, or received from a source you fully trust. WebCull labels this feature Less secure and leaves it off by default.
How Browsers Treat Bookmarklets
Many desktop browsers support bookmarklets through their built-in bookmark managers. Instead of navigating to a normal https: address, activating a javascript: bookmark asks the browser to run its code in the current page. Exact support and restrictions vary by browser and website, and a website's Content Security Policy can block execution.
WebCull keeps this advanced behavior available without treating it like an ordinary link. JavaScript bookmarks are handled through explicit permission and confirmation steps before any code can run. The MDN guide to JavaScript URLs provides more detail about browser behavior.
WebCull Requires A Deliberate Choice
Choose The Narrowest Permission You Need
Open Settings, then Security, to find both controls.
Treat The Code As Part Of The Current Page
Do not run bookmarklet code you cannot read or explain, especially on a sensitive signed-in page. Be careful with third-party bookmarklets even when the visible code looks simple: a bookmarklet can load remote code or send information from the current page to an external service, so the code you see may not be the whole behavior. A short name, a familiar Collection, or a recommendation from another person is not a security review. WebCull leaves JavaScript bookmarks off by default for a reason. Prefer Run once when you do not need continuing access, and enable JavaScript bookmarks only if you understand and accept the risk. Use this feature at your own risk.
Malicious or unsafe code can read or change information available to the page and may act with your signed-in access. This can resemble the impact of cross-site scripting even though a bookmarklet you deliberately run is not automatically an XSS vulnerability. Read Cross-Site Scripting: Bookmark Managers Have Critical Security Boundaries to Uphold for a plain-language explanation of that risk.