Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeEvernote Web Clipper
Findings · 3
+2 more findings locked
MEDIUM FINDINGS · 3
  1. 01On google.com/search results pages, the content script reads the user's search-input value (input.gLFyf / textarea.gLFyf / #lst-ib) and the current URL, then forwards both to background which queries Evernote's getRelatedNotes/getBusinessRelatedNotes API for the signed-in account.
  2. 02Background script ships a hardcoded analytics shared-secret (DAAFA9ED-C15D-400C-BA38-D201F9BEBF5A and stage key A5470FAA-7BA9-464B-859F-8BC7E3E62E31) used as the HMAC key for X-Signature on every analytics POST to cec.svc.evernote.com/e — embedding the signing secret on the client makes the X-Signature header an integrity layer in name only.
  3. 03Vendor analytics POSTs to cec.svc.evernote.com/e with rich device fingerprint (deviceId, language, browser+version, OS+version, device make/model, screen resolution and devicePixelRatio, IANA timezone, userTier) plus authenticated_global_user_id when signed in.
+2 more findings locked
OTHER EXTENSIONS

Is Evernote Web Clipper safe?

Medium risk

No summary available.

Evernote Corporationv7.40.0Chrome Web Store
45Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

+2 more findings not shown

Book a call to see all findingsScan your browser
Updated 30 May 2026com.evernote.web.clipper.extension

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact