Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeThe Donation Reminder
Findings · 3
+2 more findings locked
MEDIUM FINDINGS · 3
  1. 01Background analytics SDK POSTs the current page URL (window.location.href) along with installationId/userId/sessionId on every analytic event to api-v3.easyfundraising.org.uk/analytics/event; the personal-data redaction routine that blanks searchQuery/url/redirectUrl/urlHostname is gated by browserCode===firefox and never runs on the Safari build.
  2. 02On Google and Bing search-result pages the SERP content script reads the user's search query from the URL and includes it (`searchQuery`) in the payload of `displayedSerpAlert` and `clickedSerpAlert` analytic events POSTed to api-v3.easyfundraising.org.uk/analytics/event.
  3. 03On retailer order-confirmation pages the background extracts the order ID (from the URL query string) and the order total (regex-matched against page innerText) and POSTs them with the basket URL and retailer identity to api-v3.easyfundraising.org.uk/analytics/event/iterable.
+2 more findings locked
OTHER EXTENSIONS

Is The Donation Reminder safe?

Medium risk

No summary available.

easyfundraisingv6.23.0Chrome Web Store
45Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

+2 more findings not shown

Book a call to see all findingsScan your browser
Updated 30 May 2026uk.org.easyfundraising.easyfundraisingDonationReminder.Extension

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact