Is FoundersCard Chrome Extension safe?
FoundersCard Chrome Extension fetches a benefit list from founderscard.com and injects server-controlled HTML into every visited web page.
On each page load, the extension retrieves a benefit catalogue from founderscard.com and checks whether the current site matches any listed partner. When a match is found, it injects a popup overlay whose title and link URL are taken directly from the server response and written via innerHTML without HTML-encoding, meaning a malicious or compromised server response could execute arbitrary content in the context of the visited page. The extension also loads a font stylesheet from fonts.cdnfonts.com on every popup display, which exposes the page URL via the Referer header to that CDN.
Part of this rating comes from analysis signals we haven't published as detailed findings yet.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.