Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeEno from Capital One
Findings · 3
+2 more findings locked
MEDIUM FINDINGS · 3
  1. 01The background script registers a webRequestBlocking listener on response headers for supported merchant payment URLs and strips x-frame-options and content-security-policy from the responses so the merchant's payment page can be iframed inside the Eno content-script overlay.
  2. 02Content scripts on all https/http pages discover credit-card-shaped form fields and ship the page URL, referrer, and a fingerprint of detected input metadata to Capital One's Snowplow collector (potomac-clickstream.capitalone.com) whenever a CC field is matched.
  3. 03When the Eno virtual-card banner is displayed on a supported merchant site, the content script reports the visited hostname and origin+pathname of the page to Capital One's Snowplow collector as a Banner_Displayed (or CC_Swap_Pop_Banner_Displayed) event.
+2 more findings locked
OTHER EXTENSIONS

Is Eno from Capital One safe?

Clean risk

No summary available.

Capital Onev5.4.1Chrome Web Store
0Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

+2 more findings not shown

Book a call to see all findingsScan your browser
Updated 30 May 2026com.capitalone.ewa.extension

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact