Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeCapacities Web Extension
Findings · 2
LOW FINDINGS · 2
  1. 01Manifest declares cleartext HTTP host_permissions for a hardcoded EC2 IP (http://18.192.220.44:8000/) and http://localhost:3333/ — leftover development endpoints granted to a production Safari extension.
  2. 02On user action (popup open + 'Save'), the extension reads the active tab's URL and title via chrome.tabs.query and POSTs them to https://portal.capacities.io/resources/weblinks alongside the user's auth cookie — bookmark-style exfil, but only of the page the user explicitly chose to save.
OTHER EXTENSIONS

Is Capacities Web Extension safe?

Low risk

No summary available.

Capacities Labs GmbHv1.5.6Chrome Web Store
20Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

Updated 30 May 2026io.capacities.webextension.Extension

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact