Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeGoogle Shopping Deals
Findings · 3
+5 more findings locked
HIGH FINDINGS · 3
  1. 01Background script logs every web navigation (URL, redirect chain, transition type, navigation type, full user agent, environment metadata) plus all browser cookies to https://collect-panelresearch.google.com via the Tritium LogEntry RPC.
  2. 02Background script subscribes to chrome.webRequest.onSendHeaders (urls=['<all_urls>'], requestHeaders) and chrome.webRequest.onHeadersReceived to capture sub-resource (intrapage) request URLs, request cookie headers, referer, and selected response headers, gated by remote-config-supplied URL pattern regexes (urlPatternRegexes, intrapageUrlPattern, requiredResponseHeaders, loggedResponseHeaders) and forwards each match to LogEntry as entryType='intrapageRequest'.
  3. 03Server-pushed declarativeNetRequest dynamic rules — the extension downloads JSON-encoded DNR rules from Google's tritium server and unconditionally applies them via chrome.declarativeNetRequest.updateDynamicRules, allowing post-install modification of network-request behavior on every site without code review.
+5 more findings locked
OTHER EXTENSIONS

Is Google Shopping Deals safe?

High risk

No summary available.

Googlev1.34.0Chrome Web Store
75Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

+5 more findings not shown

Book a call to see all findingsScan your browser
Updated 30 May 2026com.google.beam.SafariWebExtension

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact