Am I Being Pwned? logoAm I Being Pwned?
Book a demo
Homecherry pick maximize cred
Findings · 3
+2 more findings locked
HIGH FINDINGS · 3
  1. 01Content script extracts full page text, URL, and title from checkout/payment pages and exfiltrates to developer's Supabase backend for LLM card-recommendation processing
  2. 02User email address collected via Google OAuth / Supabase auth and persisted to chrome.storage.local; subsequently included in all card-sync and rank-cards API calls to developer's backend
  3. 03User's saved credit card list and card preferences exfiltrated to developer's Supabase backend on every popup open and checkout page detection
+2 more findings locked
OTHER EXTENSIONS

Is cherry pick maximize cred safe?

High risk

No summary available.

v1.35Chrome Web Store
75Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

+2 more findings not shown

Book a call to see all findingsScan your browser
Updated 30 May 2026ebankejienamjhfeecfcloemnggddgbf

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact