Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeBlockSite: Block Sites & Focus
Findings · 3
+4 more findings locked
HIGH FINDINGS · 3
  1. 01Every URL the user visits is sent from a content script on <all_urls> to BlockSite's vendor server (category.blocksite.co/category) for category-based blocking lookups, producing a full browsing-history feed.
  2. 02Affiliate attribution flow harvests the Impact Radius `irclickid` browser cookie via chrome.cookies and POSTs it (along with the user's email and a customer status) to user-state.blocksite.co/affiliate/installEvent.
  3. 03Mixpanel product analytics with hardcoded production project token (838c65c3e2afe9d50264505a75298594) sends extension-event telemetry tied to a per-install distinct_id and (when signed in) user_id to api.mixpanel.com / api-js.mixpanel.com.
+4 more findings locked
OTHER EXTENSIONS

Is BlockSite: Block Sites & Focus safe?

Medium risk

No summary available.

BlockSite LPv1.0.2Chrome Web Store
45Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

+4 more findings not shown

Book a call to see all findingsScan your browser
Updated 30 May 2026com.BlockSite-Safari.Extension

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact