Is FoundersCard Chrome Extension safe?

Low risk

FoundersCard Chrome Extension fetches a benefit list from founderscard.com and injects server-controlled HTML into every visited web page.

On each page load, the extension retrieves a benefit catalogue from founderscard.com and checks whether the current site matches any listed partner. When a match is found, it injects a popup overlay whose title and link URL are taken directly from the server response and written via innerHTML without HTML-encoding, meaning a malicious or compromised server response could execute arbitrary content in the context of the visited page. The extension also loads a font stylesheet from fonts.cdnfonts.com on every popup display, which exposes the page URL via the Referer header to that CDN.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

FoundersCardv1.3.5Chrome Web Store
20Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Data recipients

founderscard.comfonts.cdnfonts.com
Updated 17 September 2026kamiaabbnpncbobdiblhfogafnoefkae