Am I Being Pwned? logoAm I Being Pwned?by Bay Area Labs
Contact usScan my org
HomeFrankerFaceZ
Findings · 3
+1 more finding locked
MEDIUM FINDINGS · 3
  1. 01Twitch username sent to FFZ WebSocket servers on page load; current Twitch channel name sent per-navigation, revealing which channels the user watches
  2. 02URLs of links appearing in Twitch chat are sent to the FFZ link-service on hover/render for rich content preview resolution
  3. 03Content script writes chrome.runtime.id to document.body.dataset.ffzExtension on all twitch.tv pages, making the extension ID readable by any page-level JavaScript
+1 more finding locked
OTHER EXTENSIONS

Is FrankerFaceZ safe?

Low risk

No summary available.

FrankerFaceZv4.79.3.0Chrome Web Store
20Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

+1 more finding not shown

Book a call to see all findingsScan your browser
Updated 30 May 2026fadndhdgpmmaapbmfcknlfgcflmmmieb

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogFree Org ScanHow it worksSecurityFor VendorsFAQThreat Intel FeedAPI DocsPrivacy PolicyTerms of ServiceContact