Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeBugHerd: Visual Feedback & Bug Tracking Tool
Findings · 3
HIGH FINDINGS · 3
  1. 01Content script postMessage proxy (PROXY_FETCH/PROXY_XHR) accepts messages from any origin on any page, allowing arbitrary pages to make credentialed requests through the extension
  2. 02Content script postMessage GET_LOCAL_STORAGE/SET_LOCAL_STORAGE handlers expose page localStorage read/write to any cross-origin sender
  3. 03Extension ID and BugHerd project API key injected into page window.BUGHERD_EXTENSION_CONFIG on project-matched sites, readable by all page scripts
OTHER EXTENSIONS

Is BugHerd: Visual Feedback & Bug Tracking Tool safe?

High risk

No summary available.

BugHerdv3.0.4950Chrome Web Store
75Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

Updated 30 May 2026popigpemobhbfkhnnkllkjgkaabedgpb

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact