Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeRSS Feed Reader
Findings · 3
+2 more findings locked
MEDIUM FINDINGS · 3
  1. 01On unhandled background service worker errors, extension transmits error details including service worker storage state (auth tokens, web push credentials) to errors.feeder.co
  2. 02The debug endpoint in the Feeder reader UI transmits the full chrome.storage.local contents (including auth token, email, user ID, web push credentials, and all cached data) to errors.feeder.co/debug/ whenever a user navigates to the debug section
  3. 03Extension strips Content-Security-Policy, X-Frame-Options, and several request headers (sec-fetch-dest, sec-fetch-site, referer) from responses on feeder.co tabs using declarativeNetRequest session rules
+2 more findings locked
OTHER EXTENSIONS

Is RSS Feed Reader safe?

Clean risk

No summary available.

Feederv8.0.28Chrome Web Store
0Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

+2 more findings not shown

Book a call to see all findingsScan your browser
Updated 30 May 2026pnjaodmkngahhkoihejjehlcdlnohgmp

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact