Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeGrammarly: AI Writing App
Findings · 3
+2 more findings locked
HIGH FINDINGS · 3
  1. 01When the user focuses an editable element (textarea, contenteditable, or input of type text/email/tel/url/etc.) on any non-excluded site, the content script captures the field's text and streams it over a long-lived WebSocket to wss://capi.grammarly.com/freews for grammar/style checking
  2. 02Content script Grammarly-check.js is injected on <all_urls> (minus a ~50-site explicit exclusion list) at document_idle in all frames, including about:blank — the script reads document.location.href on every page and queries the background for an isUrlAllowlisted decision before activating the gButton/text-check UI
  3. 03Performance/usage telemetry events emitted from the content script attach the page hostname (n.domain) to gButton/inline-alert/text-check metrics, so Grammarly's analytics pipeline receives the domain of every site where Grammarly activates plus how much text was checked, alert counts, and latency
+2 more findings locked
OTHER EXTENSIONS

Is Grammarly: AI Writing App safe?

Low risk

No summary available.

Grammarly, Incv9.96Chrome Web Store
20Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

+2 more findings not shown

Book a call to see all findingsScan your browser
Updated 30 May 2026com.grammarly.safari.extension.web

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact