Is Eno® from Capital One® safe?

Low risk

Eno from Capital One scans page structure on all sites and sends URL, referrer, and session identifiers to Capital One analytics.

The extension runs content scripts on all HTTP and HTTPS pages. On pages where payment-related form elements are detected, it collects the page title, body text, and form field data, then transmits the current URL, referrer, and the user's profileReferenceId to Capital One's Snowplow analytics endpoint. A window.postMessage handler in the content script accepts tracking messages from any web origin and forwards them — along with the user's stored profileReferenceId — to the same analytics endpoint without validating the message origin.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

Capital Onev6.0.0Firefox Add-ons
20Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Data recipients

potomac-clickstream.capitalone.com
Updated 17 September 2026amo-941474