Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeFortiDLP Browser Extension
Findings · 3
+3 more findings locked
HIGH FINDINGS · 3
  1. 01New fetch_plain.js monkeypatches window.fetch to capture full outbound HTTP request bodies, URLs, and headers site-wide, forwarding them via native messaging to com.jazznetworks.browserextension
  2. 02New xhr_delay_before_abort.js monkeypatches XMLHttpRequest.open/send/setRequestHeader site-wide to capture XHR request bodies and headers, with a 1-second delay-then-abort blocking mechanism
  3. 03New ws_copilot.js monkeypatches WebSocket.prototype.send site-wide to intercept and optionally block outbound WebSocket messages, with capability to inject fake error frames to terminate WebSocket sessions
+3 more findings locked
OTHER EXTENSIONS

Is FortiDLP Browser Extension safe?

Medium risk

No summary available.

Next DLPv3.5.6Chrome Web Store
45Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

+3 more findings not shown

Book a call to see all findingsScan your browser
Updated 30 May 2026gbojkjpincgojijodbnliimgeggnomai

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact