Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeDenote: Save Ads TK & FB Ad Library
Findings · 3
+4 more findings locked
HIGH FINDINGS · 3
  1. 01Extension intercepts Facebook GraphQL API requests via webRequest.onBeforeRequest and onBeforeSendHeaders, capturing form data and headers from facebook.com/api/graphql/ requests
  2. 02Extension fetches remote configuration from denote.net that controls XHR interception behavior, header filtering rules, and Facebook API doc_id parameters
  3. 03Injected page-level script hijacks XMLHttpRequest to intercept all Facebook ad library API responses including auth tokens (X-FB-LSD, X-ASBD-ID, fb_dtsg) and full ad data
+4 more findings locked
OTHER EXTENSIONS

Is Denote: Save Ads TK & FB Ad Library safe?

High risk

No summary available.

Denotev1.0.27.8Chrome Web Store
75Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

+4 more findings not shown

Book a call to see all findingsScan your browser
Updated 30 May 2026okieokifcnnigcgceookjighhplbhcip

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact