Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeDraftback
Findings · 3
MEDIUM FINDINGS · 3
  1. 01OAuth tokens and Google email extracted from Google Docs page context and transmitted to draftback.com
  2. 02User email and persistent UUID transmitted to accounts.draftback.com for subscription verification
  3. 03v0.0.28 adds a debug logging subsystem with four new service-worker message cases (set-debug-enabled, debug-log, get-debug-logs, clear-debug-logs). The handler has no sender-origin check. Any web page can enable debug mode, then retrieve debug logs from chrome.storage.local — logs that include the user's Google email address once the sign-in flow has run.
OTHER EXTENSIONS

Is Draftback safe?

Low risk

No summary available.

jsomersv0.0.27Chrome Web Store
20Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

Updated 30 May 2026nnajoiemfpldioamchanognpjmocgkbg

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact