Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeEightify for Safari
Findings · 3
LOW FINDINGS · 3
  1. 01YouTube video ID extracted from page URL and posted to frontend.eightify.app iframe for AI summarization (disclosed primary function).
  2. 02Auth token retrieved via native messaging from host Eightify.app and forwarded into iframe URL query string (?token=...), exposing the bearer token to URL-borne leak vectors (Referer headers, browser/server logs).
  3. 03Service worker fetches remote A/B-test configuration ('tests') from backend.eightify.app/event-all on every load with credentials:'include' and persists it to chrome.storage.local; remote-controlled JSON is stored locally without integrity check.
OTHER EXTENSIONS

Is Eightify for Safari safe?

Low risk

No summary available.

Rational Expressions, Incv1.0.7Chrome Web Store
20Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

Updated 30 May 2026app.eightify.Extension

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact