Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeActioner AI - Career Automation
Findings · 3
+7 more findings locked
HIGH FINDINGS · 3
  1. 01externally_connectable grants message-sending privileges to any Replit subdomain, enabling untrusted third-party Replit projects to send commands to the extension
  2. 02AUTH_STATUS handler exposes user email, userId, token expiration, and auth state to any externally_connectable origin without additional access control
  3. 03Comprehensive user PII including name, email, phone, address, work history, education, salary, demographics (EEO data), and disability status is sent to a server-controlled backend URL
+7 more findings locked
OTHER EXTENSIONS

Is Actioner AI - Career Automation safe?

High risk

No summary available.

v2.2.14Chrome Web Store
75Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

+7 more findings not shown

Book a call to see all findingsScan your browser
Updated 30 May 2026dldanbehhdlfbkmkfnmhemkkibpoaheg

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact