Is Eno® from Capital One® safe?
Eno from Capital One scans page structure on all sites and sends URL, referrer, and session identifiers to Capital One analytics.
The extension runs content scripts on all HTTP and HTTPS pages. On pages where payment-related form elements are detected, it collects the page title, body text, and form field data, then transmits the current URL, referrer, and the user's profileReferenceId to Capital One's Snowplow analytics endpoint. A window.postMessage handler in the content script accepts tracking messages from any web origin and forwards them — along with the user's stored profileReferenceId — to the same analytics endpoint without validating the message origin.
Part of this rating comes from analysis signals we haven't published as detailed findings yet.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.