Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeClockk Extension
Findings · 3
+2 more findings locked
HIGH FINDINGS · 3
  1. 01Content script on <all_urls> reports every visited page's URL + title + userAgent to the vendor backend as a 'url-artifact' fallback whenever the page does not match a known SaaS pattern; subject only to a server-fetched domain blacklist regex
  2. 02When a visited page matches a vendor-supplied 'webApp' pattern, the content script extracts page text via a server-supplied CSS selector and posts it (page innerText, app name, identifier, page title, URL, userAgent) to the vendor backend
  3. 03icon_url for every recognized web-app artifact is built as `https://icon.horse/icon/<visited-hostname>`, leaking the hostnames of monitored SaaS pages to a third-party favicon CDN
+2 more findings locked
OTHER EXTENSIONS

Is Clockk Extension safe?

High risk

No summary available.

Clockk.com Inc.v25.12.2Chrome Web Store
75Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

+2 more findings not shown

Book a call to see all findingsScan your browser
Updated 30 May 2026com.clockk.safari.Extension

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact