Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeConnectlift Mate - Your AI Job Hunt Assistant
Findings · 3
+2 more findings locked
MEDIUM FINDINGS · 3
  1. 01Extension fetches remote configuration from a GitHub Pages endpoint and injects the response message into the popup DOM, allowing the developer to dynamically change displayed content.
  2. 02LinkedIn profile data (name, headline, about, current role) of third-party users is scraped from the active tab and sent to the Groq LLM API for message generation.
  3. 03User's Groq API key is stored in chrome.storage.local (unencrypted) and transmitted in Authorization headers to api.groq.com; the Google OAuth access token is also stored in plaintext in chrome.storage.local.
+2 more findings locked
OTHER EXTENSIONS

Is Connectlift Mate - Your AI Job Hunt Assistant safe?

Medium risk

No summary available.

Connectlift mate v3.0.0Chrome Web Store
45Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

+2 more findings not shown

Book a call to see all findingsScan your browser
Updated 30 May 2026kbagmgoojogjfmcmnhlihjmkfcadambe

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact