Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeAkeyless Password Manager 2.0
Findings · 3
LOW FINDINGS · 3
  1. 01Content script registered on <all_urls> with all_frames:true reads form fields, password inputs, labels and DOM context on every page and frame to support credential autofill
  2. 02Background service worker sends the visited site's hostname to the user's authenticated Akeyless vault on every page navigation to look up matching credentials
  3. 03Background injects a passkey/WebAuthn shim into world:'MAIN' on every navigated tab, replacing navigator.credentials so the extension can intercept create()/get() calls
OTHER EXTENSIONS

Is Akeyless Password Manager 2.0 safe?

Clean risk

No summary available.

Akeyless Securityv1.26.21Chrome Web Store
0Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

Updated 30 May 2026com.akeyless.password-manager.extension

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact