Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeEditor for Docs, Sheets & Slides
Findings · 3
MEDIUM FINDINGS · 3
  1. 01Content script intercepts Google Docs/Sheets/Slides/Drive link clicks across all websites and routes them through developer-controlled google-edit.com, exposing document URLs
  2. 02Google Docs URLs are transmitted to developer-controlled server over HTTP (not HTTPS), enabling passive interception of document identifiers
  3. 03Popup.js contains hardcoded references to google-edit.com endpoints for document creation and Drive access, suggesting server-side tracking of user document-creation actions
OTHER EXTENSIONS

Is Editor for Docs, Sheets & Slides safe?

Medium risk

No summary available.

konimatoanv1.1.10Chrome Web Store
45Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

Updated 30 May 2026oepjogknopbbibcjcojmedaepolkghpb

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact