Is GrabzIt Web Monitor safe?

Low risk

GrabzIt Web Monitor accepts any page's postMessage with no origin check, letting it arm the monitor setup with an attacker-chosen API key.

The extension's injected content script listens for window postMessage events without checking the sender's origin, so any script running on the same page can send a message that supplies its own applicationKey and opens the monitor-setup panel. If the user then completes the setup wizard, the monitor is created on GrabzIt's servers under that attacker-supplied key rather than the user's own account key. Separately, whenever an error is logged the extension also sends the user's real GrabzIt account key to its analytics vendor, PostHog, as the tracking identifier for that event.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

GrabzIt Limitedv1.1.1Chrome Web Store
20Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Data recipients

api.grabz.iteu.i.posthog.com (PostHog)
Updated 20 September 2026opicjhpjnaggghfoiklghbnmehlnglgm