Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeHandy Screenshot for Safari
Findings · 2
LOW FINDINGS · 2
  1. 01Content script runs on every page (Info.plist SFSafariWebsiteAccess Level=All, manifest.json content_scripts.matches=<all_urls>) and reports window.location.href to the host app over safari.extension.dispatchMessage; this is the screenshot tool's normal capture mechanism.
  2. 02Editor/settings/capture pages load the Ant Design icon font from Alibaba CDN (at.alicdn.com), leaking the user's IP/User-Agent to a third party each time those pages render.
OTHER EXTENSIONS

Is Handy Screenshot for Safari safe?

Low risk

No summary available.

泰宁 陆v1.1Chrome Web Store
20Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

Updated 30 May 2026lu.taining.HandyScreenshot.SafariExtension

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact