WebCull
Documentation Private Bookmark Manager
Private Bookmark Manager

JavaScript Bookmarks

Use bookmarklets for advanced page actions with separate personal and public Collection permissions.

What JavaScript Bookmarks Do

A JavaScript bookmark, often called a bookmarklet, stores a small JavaScript action instead of an ordinary web address. When you deliberately open it, the action runs in the page you are viewing. It can make useful changes such as simplifying a page, adjusting its presentation, copying structured details, or starting a trusted workflow.

That flexibility also gives the code access to the current page. Only save and run JavaScript you wrote, reviewed, or received from a source you fully trust. WebCull labels this feature Less secure and leaves it off by default.

How Browsers Treat Bookmarklets

Many desktop browsers support bookmarklets through their built-in bookmark managers. Instead of navigating to a normal https: address, activating a javascript: bookmark asks the browser to run its code in the current page. Exact support and restrictions vary by browser and website, and a website's Content Security Policy can block execution.

WebCull keeps this advanced behavior available without treating it like an ordinary link. JavaScript bookmarks are handled through explicit permission and confirmation steps before any code can run. The MDN guide to JavaScript URLs provides more detail about browser behavior.

WebCull Requires A Deliberate Choice

Off by default
Personal and public Collection permissions both start off. An ordinary bookmark workflow does not need JavaScript access.
Never automatic
WebCull never auto-opens a JavaScript bookmark. You must explicitly choose to open it.
run once
When a JavaScript bookmark is blocked, you can run that action once without leaving the broader permission enabled.
Separate trust boundaries
JavaScript you saved and JavaScript supplied through a public Collection have separate settings. Enabling one does not enable the other.

Choose The Narrowest Permission You Need

Open Settings, then Security, to find both controls.

JavaScript in my bookmarks
Allows JavaScript bookmarks you save or control to run when you explicitly open them. Keep this off if you do not use bookmarklets.
JavaScript from public Collections
Allows code supplied by a public Collection owner or collaborator to run when you explicitly open it. This is a separate and higher trust decision because someone else can change the saved code.

Treat The Code As Part Of The Current Page

Do not run bookmarklet code you cannot read or explain, especially on a sensitive signed-in page. Be careful with third-party bookmarklets even when the visible code looks simple: a bookmarklet can load remote code or send information from the current page to an external service, so the code you see may not be the whole behavior. A short name, a familiar Collection, or a recommendation from another person is not a security review. WebCull leaves JavaScript bookmarks off by default for a reason. Prefer Run once when you do not need continuing access, and enable JavaScript bookmarks only if you understand and accept the risk. Use this feature at your own risk.

Malicious or unsafe code can read or change information available to the page and may act with your signed-in access. This can resemble the impact of cross-site scripting even though a bookmarklet you deliberately run is not automatically an XSS vulnerability. Read Cross-Site Scripting: Bookmark Managers Have Critical Security Boundaries to Uphold for a plain-language explanation of that risk.

Next step Private Bookmark Manager Proxy Parsing And Media Embeds Control URL detail fetching, bookmark detail suggestions, extension capture, and playable third-party media embeds.