Is Findymail - Email & Phone Finder safe?

Low risk

Findymail checks postMessage sender origin with a substring match, then writes the message data into the LinkedIn page via innerHTML.

On LinkedIn Sales Navigator, search, and posts pages, Findymail listens for window postMessage events and checks the sender's origin with a substring test rather than an exact match, so an origin merely containing the expected auth domain passes. Messages that pass are stored and later inserted into Findymail's contact widget on the live linkedin.com page using innerHTML without sanitization, so a page able to satisfy that origin check can inject content into the widget.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

valentin.wallyn.suprajrv1.0.43Chrome Web Store
20Risk
Who publishes it

Peanuts SaaS Studio - no other listings under this identity

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
valentin.wallyn.suprajr
Declared legal entity
Peanuts SaaS Studio
Registered address
3 Ruelle des Carmélites, Capinghem 59160, FR
Registered contact
Valentin Wallyn

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

What it can do

Permissions this extension asks for, as declared in version 1.0.38. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to. The current listed version is 1.0.43, which we have not unpacked yet.

  • Read and change your data on findymail.com

    https://*.findymail.com/*

  • Read and change your data on localhost

    http://localhost/*

  • Store data in your browser

    storage

  • See the address and title of every tab you have open

    tabs

Updated 30 September 2026ichmnigkjinmjedillldopaolidofben