Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeFanFundU Extension
Findings · 3
+1 more finding locked
MEDIUM FINDINGS · 3
  1. 01Content script runs on every website (matches *://*/*) and observes URL/DOM on all browsing, sending merchant-match queries for any URL the user visits to the background service worker for local lookup against an affiliate merchant list of 80+ patterns.
  2. 02When the user lands on a merchant site recognised by FanFundU, the background fetches an affiliate redirect (linkout) URL from fanfundu.com/pccapi/extension/get/linkout/{merchantId} keyed by the user's auth token, allowing FanFundU to log every cashback-eligible store visit per-user.
  3. 03Extension subscribes to chrome.cookies.onChanged for ALL cookie events, then reacts only when a cookie on fanfundu.com named FFUsli changes (the user's auth token). All cookie change notifications globally are handed to the listener but only fanfundu.com cookies trigger user.update().
+1 more finding locked
OTHER EXTENSIONS

Is FanFundU Extension safe?

Low risk

No summary available.

FanFundU, LLCv1.0Chrome Web Store
20Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

+1 more finding not shown

Book a call to see all findingsScan your browser
Updated 30 May 2026com.fanfundu.FanFundU-Extension.Extension

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact